Attention, colleagues: GitHub Actions runners are being used to attack cPanel and WHM

Colleagues, I’d like to draw your attention to a cybersecurity incident.
Researchers have reported a campaign in which compromised GitHub repositories were turned into attack infrastructure.
Through malicious GitHub Actions workflows, a Linux payload is downloaded onto GitHub-hosted runners and used to scan for vulnerable cPanel and WHM servers, including those affected by CVE-2026-41940.
The attackers then try to bypass authentication and collect credentials, configs, SSH data, GitHub/GitLab tokens, and cloud keys.
Why it matters: they are not abusing developers’ systems, but the CI/CD infrastructure itself, turning it into a tool for finding victims.
Are you reviewing your GitHub Actions policies across your projects?
#cybersecurity #GitHubActions #DevSecOps #SupplyChain


Latest comments
No comments yet.