platform-engineering Your Platform Team Needs an Agent Policy — Yesterday On March 3rd, an attacker compromised the Xygeni GitHub Action by poisoning a mutable tag. Every CI runner referencing xygeni/xygeni-action@v5 quietly started executing a reverse shell to a C2… Michael Tuszynski Mar 15, 2026 5 min read