<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Github-Actions on it-learn.io | IT, Networking &amp; Cybersecurity Blog</title><link>https://blog.it-learn.io/tags/github-actions/</link><description>Recent content in Github-Actions on it-learn.io | IT, Networking &amp; Cybersecurity Blog</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 25 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://blog.it-learn.io/tags/github-actions/index.xml" rel="self" type="application/rss+xml"/><item><title>Megalodon Supply-Chain Attack Poisons 5,500+ GitHub Repos — Ghost CMS Zero-Day and TrapDoor Campaign</title><link>https://blog.it-learn.io/posts/2026-05-25-megalodon-supply-chain-attack-poisons-5-500-github-repos-gho/</link><pubDate>Mon, 25 May 2026 00:00:00 +0000</pubDate><guid>https://blog.it-learn.io/posts/2026-05-25-megalodon-supply-chain-attack-poisons-5-500-github-repos-gho/</guid><description>Three supply-chain attacks in a single day: Megalodon injects credential-stealing workflows into 5,500+ GitHub repos, CVE-2026-26980 turns 700+ Ghost CMS sites into phishing infrastructure, and TrapDoor plants 34 malicious packages across npm, PyPI, and Crates.io. Plus Lazarus deploys a fileless RAT against crypto firms.</description></item></channel></rss>