logo

Hackers Abuse GitHub Actions to Exploit cPanel and WHM Servers and Steal Cloud Credentials

ID: 30d0592b-81e6-5a1a-8142-5536a85aa7c0

STIX ID: report--30d0592b-81e6-5a1a-8142-5536a85aa7c0

Feed Name: cybersecurityNews.com

Threat Score
80/100

Date Published: 2026-07-23

Date Updated: 2026-07-23

Author: Tushar Subhra Dutta

...
...

A widespread campaign has been discovered where attackers plant malicious GitHub Actions workflow files in compromised repositories to spin up ephemeral Ubuntu runners that download a Linux payload, scan the internet for cPanel/WHM targets, attempt exploitation of CVE-2026-41940, and exfiltrate credentials and tokens; analysts observed thousands of matching workflows, multiple compromised Packagist packages from a maintainer account, and provided IoCs and mitigation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.