Megalodon pushed 5,718 malicious commits to 5,561 GitHub repositories in a six-hour window. That’s faster than most teams can convene a Slack huddle, let alone trigger an incident response page. The economics of cybersecurity flipped this month, and they didn’t flip your way. Attack tooling got cheaper, faster, and more autonomous, while defensive cycles kept pretending we still live in a world where a human reviews every alert.
If you anchor your defensive posture to patch Tuesday, CVE assignment, or even an analyst’s morning triage, you’ve already lost the race. The stories worth stitching together this week aren’t about any single APT. They’re about a price collapse on offense that every security leader needs to internalize before next quarter’s budget review.
Megalodon Showed Your Six-Hour Response SLA Is Fiction
The Megalodon operators didn’t bother with elegance. They spun up throwaway GitHub accounts with names like build-bot, auto-ci, ci-bot, and pipeline-bot. They forged author identities. They committed base64-encoded bash payloads inside GitHub Actions workflows. Then they walked away with whatever CI secrets the runners coughed up.
The campaign hit 5,561 repos before anyone wrote a blog post about it. Six hours, end to end.
Think about what that means operationally. Your detection engineering team takes longer than that to tune a single SIEM rule. Your code review SLA assumes a human will eyeball changes within a business day. Your dependency scanner runs nightly, if you’re lucky. Megalodon is over and the loot is exfiltrated before the cron job even fires.
The mechanism is not novel. CI/CD pipeline abuse has been on every threat model for two years. What’s new is the speed and the fan-out. One operator, one script, thousands of victims. Defense-in-depth strategies that assume the attacker has to work for each target are now provably wrong.

A Zero-Day Now Costs Less Than Lunch
While Megalodon was busy with breadth, researchers at TrendAI and CHT Security were demonstrating depth. At Ekoparty Miami, they unveiled a pipeline built in three days that pairs AI-driven static analysis with automated Docker provisioning and dynamic verification through Chrome DevTools MCP. The output: working WordPress plugin zero-days for roughly $20 in compute each.
$20 per zero-day. That’s the going rate for AI-pipelined WordPress plugin flaws, and the price is dropping.
Twenty dollars. That’s the cost-per-bug ceiling now, against the most-deployed CMS plugin ecosystem on the planet. The vulnerability researcher community has been arguing for a year about whether agentic AI finds real bugs or generates noise. The TrendAI demonstration is one credible answer, and the answer is “real bugs, at scale, for the price of a sandwich.”
Pair this with the Iranian APT Screening Serpens campaign Unit 42 documented, AppDomainManager hijacking and new RAT variants aimed at tech and defense. Or with the two former US executives who pleaded guilty this week to running cover for a worldwide tech support fraud ring. The common thread isn’t sophistication. It’s industrialization. Every layer of the offensive stack, from nation-state espionage to consumer-grade scam ops to automated bug discovery, is now cheaper and more parallelizable than the corresponding defensive layer.
Verizon’s 2026 DBIR underlined the same shift from the victim side. Healthcare is fending off rising social engineering volume, vendor breaches keep recurring, and the median time to remediate a known-exploited vuln still measures in weeks. Your patch velocity is not the bottleneck anymore. Attacker throughput is.
Stop Optimizing the Wrong Cycle
If attackers can move in hours and you respond in days, no amount of tooling closes the gap. The fix isn’t more dashboards. It’s redesigning the parts of your program that still assume a human-in-the-loop pace.
Concrete, vendor-neutral moves to make this quarter:
- Pin and verify CI/CD workflows. Require signed commits on protected branches. Reject any GitHub Actions workflow change that wasn’t reviewed by a human owner. Disable workflow runs from forks by default. Audit your repos for
build-bot,auto-ci, and similar identities you didn’t create. - Treat CI runner secrets as already-leaked. Move every long-lived token to short-lived OIDC federation with cloud providers. If a token can survive a single workflow run, it will eventually leak. Inventory what each token can touch, and shrink that scope.
- Egress filter your build infrastructure. Runners should reach a known set of registries and package mirrors, nothing else. Base64-decoded bash phoning home to a fresh domain is detectable if you’re watching, and invisible if you’re not.
- Behavioral baselines, not signature lists. A new author identity making its first commit at 3 AM to a workflow file is the signal. Tools that wait for a CVE or an IOC will miss six-hour campaigns by design.
- Patch by exposure, not by severity. WordPress plugin zero-days at $20 means the universe of exploitable bugs in your stack just expanded. Rank patching by what’s reachable from the internet and what handles untrusted input first. CVSS is a hint, not a queue.
- Rehearse a sub-24-hour IR scenario. Tabletop the exact Megalodon shape: thousands of small commits across hundreds of repos, exfiltrated secrets, no obvious blast radius. If your runbook starts with “convene a war room,” rewrite it.
None of these require new vendors. They require a willingness to admit that the defensive playbook was built around an attacker who needed weeks. That attacker is no longer the median.
The Megalodon operator and the $20 zero-day pipeline aren’t outliers. They’re the floor. The teams that survive the next six-hour campaign will be the ones who already assumed it was coming, and who built workflows that don’t require a human to be awake when it arrives.
Sources
- Megalodon GitHub Attack Targets 5,561 Repos with Malicious CI/CD Workflows
- $20 per zero-day is already the WordPress plugin reality
- Tracking Iranian APT Screening Serpens’ 2026 Espionage Campaigns
- Former US execs plead guilty to aiding tech support scammers
- Verizon DBIR: Healthcare Fends Off Increased Social Engineering Attacks
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
