Back Feeds.4Sysops Compromised GitHub repositories weaponized to attack cPanel and WHM servers
Attackers have compromised numerous GitHub repositories to deploy malicious GitHub Actions workflows that function as a distributed attack platform. These automated workflows trigger GitHub-hosted runners to download Linux payloads from a centralized command-and-control server. The primary objective of this infrastructure is to scan the internet for cPanel and WHM installations vulnerable to the authentication-bypass flaw CVE-2026-41940. Source
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
