# Hackerbot-Claw Grows, Xygeni Tag Poisoning, GitHub Search HA, Windows SID Failures, and AI Skills Supply Chain Page: https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/hackerbot-claw-grows-xygeni-tag-poisoning-github-search-ha-windows-sid-failures-and-ai-skills-supply-chain Text version: https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/hackerbot-claw-grows-xygeni-tag-poisoning-github-search-ha-windows-sid-failures-and-ai-skills-supply-chain.md Podcast: [Ship It Weekly - DevOps, SRE, Platform and Cloud Engineering News](https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275) Published: 2026-03-27T05:05:25+00:00 Episode link: https://rss.com/podcasts/ship-it-weekly/2665471 Audio file: https://content.rss.com/episodes/356364/2665471/ship-it-weekly/2026_03_27_04_55_11_7a117890-6b2e-48da-8c23-9395ef5e1ec5.mp3 Processing state: not_requested JSON: https://stenobird.com/v1/public/podcasts/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/episodes/hackerbot-claw-grows-xygeni-tag-poisoning-github-search-ha-windows-sid-failures-and-ai-skills-supply-chain Duration seconds: 925 ## Resource This episode of Ship It Weekly is about the places where convenience quietly turns into trust. Brian revisits the Trivy story by zooming out to the bigger hackerbot-claw GitHub Actions campaign, then gets into the Xygeni tag-poisoning compromise, GitHub’s search high availability rebuild for GitHub Enterprise Server, Windows Server 2025 surfacing duplicate SID problems in cloned images, and the agent-skills ecosystem replaying package supply chain history. Plus: a quick lightning round on GitHub pausing self-hosted runner minimum-version enforcement and March secret scanning updates. Links OpenSSF advisory on active GitHub Actions exploitation https://seclists.org/oss-sec/2026/q1/246 Xygeni action compromise via tag poisoning https://www.stepsecurity.io/blog/xygeni-action-compromised-c2-reverse-shell-backdoor-injected-via-tag-poisoning GitHub Enterprise Server search high availability rebuild https://github.blog/engineering/architecture-optimization/how-we-rebuilt-the-search-architecture-for-high-availability-in-github-enterprise-server/ Microsoft on duplicate SIDs and nongeneralized Windows Server 2025 images https://learn.microsoft.com/en-us/troubleshoot/exchange/administration/exchange-server-issues-on-incorrect-windows-server-image Socket on supply chain security for skills.sh https://socket.dev/blog/socket-brings-supply-chain-security-to-skills Snyk ToxicSkills research https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/ GitHub self-hosted runner minimum version enforcement paused https://github.blog/changelog/2026-03-13-self-hosted-runner-minimum-version-enforcement-paused/ GitHub secret scanning pattern updates, March 2026 https://github.blog/changelog/2026-03-10-secret-scanning-pattern-updates-march-2026/ More episodes and show notes at https://… ## Actions - request_transcript: `POST https://stenobird.com/v1/public/podcasts/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/episodes/hackerbot-claw-grows-xygeni-tag-poisoning-github-search-ha-windows-sid-failures-and-ai-skills-supply-chain/transcription-requests` — Idempotently request low-priority transcript generation for this episode. - read_markdown: `GET https://stenobird.com/podcast/ship-it-weekly-devops-sre-platform-and-cloud-engineering-news-7591275/hackerbot-claw-grows-xygeni-tag-poisoning-github-search-ha-windows-sid-failures-and-ai-skills-supply-chain.md` — Read the agent-friendly Markdown representation of this episode resource. A page view does not enqueue transcription. Agents should invoke `request_transcript` explicitly when they need this episode processed. ## Transcript Full transcripts are not published on public pages unless there is a clear rights basis.