<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 23:53:51 +0000</lastBuildDate>
    <item>
      <title>EUVD-2026-275878</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-275878</link>
      <description>EUVD-2026-275878</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-275878</guid>
    </item>
    <item>
      <title>fkie_cve-2026-31976</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-31976</link>
      <description>&lt;p&gt;xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credentials created a series of pull requests (#46, #47, #48) injecting obfuscated shell code into action.yml. The PRs were blocked by branch protection rules and never merged into the main branch. However, the attacker used the compromised GitHub App credentials to move the mutable v5 tag to point at the malicious commit (4bf1d4e19ad81a3e8d4063755ae0f482dd3baf12) from one of the unmerged PRs. This commit remained in the repository&amp;#39;s git object store, and any workflow referencing @v5 would fetch and execute it. This is a supply chain compromise via tag poisoning. Any GitHub Actions workflow referencing xygeni/xygeni-action@v5 during the affected window (approximately March 3–10, 2026) executed a C2 implant that granted the attacker arbitrary command execution on the CI runner for up to 180 seconds per workflow run.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;xygeni-action is the GitHub Action for Xygeni Scanner. On March 3, 2026, an attacker with access to compromised credentials created a series of pull requests (#46, #47, #48) injecting obfuscated shell code into action.yml. The PRs were blocked by branch protection rules and never merged into the main branch. However, the attacker used the compromised GitHub App credentials to move the mutable v5 tag to point at the malicious commit (4bf1d4e19ad81a3e8d4063755ae0f482dd3baf12) from one of the unmerged PRs. This commit remained in the repository&amp;#39;s git object store, and any workflow referencing @v5 would fetch and execute it. This is a supply chain compromise via tag poisoning. Any GitHub Actions workflow referencing xygeni/xygeni-action@v5 during the affected window (approximately March 3–10, 2026) executed a C2 implant that granted the attacker arbitrary command execution on the CI runner for up to 180 seconds per workflow run.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-31976</guid>
    </item>
    <item>
      <title>GHSA-f8q5-h5qh-33mh — xygeni-action v5 tag poisoned with C2 backdoor</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-f8q5-h5qh-33mh</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; GitHub Actions: xygeni/xygeni-action&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;On March 3, 2026, an attacker with access to compromised credentials created a series of pull requests (#46, #47, #48) injecting obfuscated shell code into `action.yml`. The PRs were blocked by branch protection rules and never merged into the main branch.&lt;/p&gt;
&lt;p&gt;However, the attacker used the compromised GitHub App credentials to move the mutable `v5` tag to point at the malicious commit (`4bf1d4e19ad81a3e8d4063755ae0f482dd3baf12`) from one of the unmerged PRs. This commit remained in the repository&amp;#39;s git object store, and any workflow referencing `@v5` would fetch and execute it.&lt;/p&gt;
&lt;p&gt;The malicious code, disguised as a &amp;#34;scanner version telemetry&amp;#34; step, operates as follows:&lt;/p&gt;
&lt;p&gt;1. Registers the CI runner with a C2 server at `91.214.78.178` (via `security-verify.91.214.78.178.nip.io`), transmitting hostname, username, and OS version.
2. Polls the C2 server every 2–7 seconds for 180 seconds, receiving and executing arbitrary shell commands via `eval`.
3. Compresses and base64-encodes command output before exfiltrating it back to the C2 server.&lt;/p&gt;
&lt;p&gt;The implant runs silently in the background alongside the legitimate scan, suppresses all errors, skips TLS certificate verification, and uses randomized polling intervals to evade detection.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This is a supply chain compromise via tag poisoning. Any GitHub Actions workflow referencing `xygeni/xygeni-action@v5` during the affected window (approximately March 3–10, 2026) executed a C2 implant that granted the attacker arb…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; GitHub Actions: xygeni/xygeni-action&lt;/p&gt;
&lt;p&gt;### Description&lt;/p&gt;
&lt;p&gt;On March 3, 2026, an attacker with access to compromised credentials created a series of pull requests (#46, #47, #48) injecting obfuscated shell code into `action.yml`. The PRs were blocked by branch protection rules and never merged into the main branch.&lt;/p&gt;
&lt;p&gt;However, the attacker used the compromised GitHub App credentials to move the mutable `v5` tag to point at the malicious commit (`4bf1d4e19ad81a3e8d4063755ae0f482dd3baf12`) from one of the unmerged PRs. This commit remained in the repository&amp;#39;s git object store, and any workflow referencing `@v5` would fetch and execute it.&lt;/p&gt;
&lt;p&gt;The malicious code, disguised as a &amp;#34;scanner version telemetry&amp;#34; step, operates as follows:&lt;/p&gt;
&lt;p&gt;1. Registers the CI runner with a C2 server at `91.214.78.178` (via `security-verify.91.214.78.178.nip.io`), transmitting hostname, username, and OS version.
2. Polls the C2 server every 2–7 seconds for 180 seconds, receiving and executing arbitrary shell commands via `eval`.
3. Compresses and base64-encodes command output before exfiltrating it back to the C2 server.&lt;/p&gt;
&lt;p&gt;The implant runs silently in the background alongside the legitimate scan, suppresses all errors, skips TLS certificate verification, and uses randomized polling intervals to evade detection.&lt;/p&gt;
&lt;p&gt;### Impact&lt;/p&gt;
&lt;p&gt;This is a supply chain compromise via tag poisoning. Any GitHub Actions workflow referencing `xygeni/xygeni-action@v5` during the affected window (approximately March 3–10, 2026) executed a C2 implant that granted the attacker arb…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-f8q5-h5qh-33mh</guid>
    </item>
  </channel>
</rss>
