CVE Tools

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

The Hacker NewsBy The Hacker News

Reported exploitedGitHub ActionsPackagist packages

Our summary

Researchers uncovered a large-scale cyber campaign where attackers leveraged compromised GitHub repositories to deploy malicious workflows targeting cPanel and WebHost Manager (WHM) servers. Between July 12 and 13, 2026, ten Packagist packages linked to a legitimate PHP developer were used to distribute malicious GitHub Actions workflows. These workflows trigger GitHub-hosted runners that download payloads exploiting CVE-2026-41940, an authentication bypass flaw in cPanel and WHM. The attacks aim to steal credentials, configuration files, and sensitive data from vulnerable systems. This incident highlights how supply chain vulnerabilities can be weaponized at scale.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store