GitHub Actions Abuse Exploits cPanel CVE-2026-41940 to Steal Server Credentials
ID: 55cf9ce9-8b5b-5d13-9dc1-6850cf6389ea
STIX ID: report--55cf9ce9-8b5b-5d13-9dc1-6850cf6389ea
Feed Name: Cyber Press
Threat Score
A widespread campaign abused compromised GitHub accounts and Packagist-synchronized development branches to inject hundreds of malicious GitHub Actions workflows (and ~6,100 related workflow files) that spin up Ubuntu runners, download payloads from a C2, and scan/exploit internet-facing hosts — notably targeting a cPanel authentication bypass (CVE-2026-41940) to steal server credentials, secrets, keys, and other high-value data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
