Skip to content
Compromised GitHub repositories weaponized to attack cPanel and WHM servers

Compromised GitHub repositories weaponized to attack cPanel and WHM servers

Feeds.4Sysops IT News July 23, 2026

Attackers have compromised numerous GitHub repositories to deploy malicious GitHub Actions workflows that function as a distributed attack platform. These automated workflows trigger GitHub-hosted runners to download Linux payloads from a centralized command-and-control server. The primary objective of this infrastructure is to scan the internet for cPanel and WHM installations vulnerable to the authentication-bypass flaw CVE-2026-41940. Source

Extracted Entities