CRITICALAdvisoryOct 10, 2026
Action required
Immediately audit GitHub Actions workflows in your repositories and CI/CD pipelines for suspicious audit or security check jobs. Block outbound connections to 185.220.101.45 and scan logs for any exfiltration. Review GitHub Actions audit logs for unexpected workflow modifications and revoke any exposed API keys or tokens.
Affected products
GitHub ActionspyxelathenadriverDevOpsGPT
Linked articles