<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[my job?]]></title><description><![CDATA[<p>my job? wasting an absolutely ungodly amount of GitHub's free compute</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/364/675/865/815/886/original/00328b7740067cdb.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/topic/8bd8d26b-9da4-4932-8458-f6cc761ab464/my-job</link><generator>RSS for Node</generator><lastBuildDate>Fri, 17 Apr 2026 12:00:39 GMT</lastBuildDate><atom:link href="https://board.circlewithadot.net/topic/8bd8d26b-9da4-4932-8458-f6cc761ab464.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 07 Apr 2026 17:47:34 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to my job? on Tue, 07 Apr 2026 18:22:14 GMT]]></title><description><![CDATA[<p><span><a href="/user/caspicat%40infosec.exchange">@<span>caspicat</span></a></span> I actually hadn't seen this, but I'm not sure how it makes GH's own runners untrustworthy? it's definitely a (bad) operational error, but AFAICT it doesn't change the platform's security posture significantly</p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/yossarian/statuses/116364812880651568</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/yossarian/statuses/116364812880651568</guid><dc:creator><![CDATA[yossarian@infosec.exchange]]></dc:creator><pubDate>Tue, 07 Apr 2026 18:22:14 GMT</pubDate></item><item><title><![CDATA[Reply to my job? on Tue, 07 Apr 2026 17:58:10 GMT]]></title><description><![CDATA[<p><span><a href="/user/yossarian%40infosec.exchange">@<span>yossarian</span></a></span> btw have you seen this? Old news, but not sure if this was widely discussed. TL;DR You can't trust GitHub runner images</p><p><div class="card col-md-9 col-lg-6 position-relative link-preview p-0">



<a href="https://www.stepsecurity.io/blog/how-stepsecurity-harden-runner-detected-unexpected-microsoft-defender-installation-on-github-hosted-ubuntu-runners" title="How StepSecurity Harden Runner Detected Unexpected Microsoft Defender Installation on GitHub-hosted Ubuntu Runners  - StepSecurity">
<img src="https://cdn.prod.website-files.com/673b71f0790aabf30bd30bf8/68b6f871d01b97c5bb490604_image%20(23).png" class="card-img-top not-responsive" style="max-height: 15rem;" alt="Link Preview Image" />
</a>



<div class="card-body">
<h5 class="card-title">
<a href="https://www.stepsecurity.io/blog/how-stepsecurity-harden-runner-detected-unexpected-microsoft-defender-installation-on-github-hosted-ubuntu-runners">
How StepSecurity Harden Runner Detected Unexpected Microsoft Defender Installation on GitHub-hosted Ubuntu Runners  - StepSecurity
</a>
</h5>
<p class="card-text line-clamp-3">Microsoft Defender was unexpectedly installed on multiple workflow runs from mid-July through mid-August, causing abnormal network traffic. StepSecurity Harden Runner detected this infrastructure anomaly within hours, and GitHub Support has since resolved the issue</p>
</div>
<a href="https://www.stepsecurity.io/blog/how-stepsecurity-harden-runner-detected-unexpected-microsoft-defender-installation-on-github-hosted-ubuntu-runners" class="card-footer text-body-secondary small d-flex gap-2 align-items-center lh-2">



<img src="https://cdn.prod.website-files.com/673b71f0790aabf30bd30bc5/675212a565f0987a0779a91f_stesecurity-favicon.png" alt="favicon" class="not-responsive overflow-hiddden" style="max-width: 21px; max-height: 21px;" />





<p class="d-inline-block text-truncate mb-0"> <span class="text-secondary">(www.stepsecurity.io)</span></p>
</a>
</div></p><p>No SBOMs released for affected images during that window<br /><a href="https://github.com/actions/runner-images/releases" rel="nofollow noopener"><span>https://</span><span>github.com/actions/runner-imag</span><span>es/releases</span></a></p>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/caspicat/statuses/116364718275140204</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/caspicat/statuses/116364718275140204</guid><dc:creator><![CDATA[caspicat@infosec.exchange]]></dc:creator><pubDate>Tue, 07 Apr 2026 17:58:10 GMT</pubDate></item><item><title><![CDATA[Reply to my job? on Tue, 07 Apr 2026 17:48:24 GMT]]></title><description><![CDATA[<p>my list got cut off</p>

<div class="row mt-3"><div class="col-12 mt-3"><img class="img-thumbnail" src="https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/364/679/746/755/740/original/a1a12c518356cfd1.png" alt="Link Preview Image" /></div></div>]]></description><link>https://board.circlewithadot.net/post/https://infosec.exchange/users/yossarian/statuses/116364679903974123</link><guid isPermaLink="true">https://board.circlewithadot.net/post/https://infosec.exchange/users/yossarian/statuses/116364679903974123</guid><dc:creator><![CDATA[yossarian@infosec.exchange]]></dc:creator><pubDate>Tue, 07 Apr 2026 17:48:24 GMT</pubDate></item></channel></rss>