Feeds.4Sysops
GitHub Actions Exploited to Attack cPanel and WHM Servers
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
A large-scale cyber campaign has compromised multiple GitHub repositories to deploy malicious workflows targeting cPanel and WHM servers. Attackers are using GitHub Actions to automate the scanning of the internet for vulnerable installations, specifically exploiting the authentication-bypass flaw CVE-2026-41940. The malicious workflows leverage GitHub's compute resources to run scans and potentially steal cloud credentials. This operation has turned trusted open-source projects into tools for widespread attacks, affecting numerous web hosting environments. The campaign has been linked to the discovery of malicious development versions across multiple Packagist PHP packages. As of now, the exploitation of this vulnerability is active, and organizations using cPanel and WHM are at significant risk.
Key Points: • Attackers are leveraging compromised GitHub repositories to exploit cPanel and WHM servers. • The campaign utilizes CVE-2026-41940, an authentication-bypass vulnerability, for attacks. • Malicious GitHub Actions workflows are being used to scan for vulnerable systems globally.