VMTech
Discuss a project

Attention, colleagues: GitHub Actions runners are being used to attack cPanel and WHM

Attention, colleagues: GitHub Actions runners are being used to attack cPanel and WHM

Colleagues, I’d like to draw your attention to a cybersecurity incident.

Researchers have reported a campaign in which compromised GitHub repositories were turned into attack infrastructure.

Through malicious GitHub Actions workflows, a Linux payload is downloaded onto GitHub-hosted runners and used to scan for vulnerable cPanel and WHM servers, including those affected by CVE-2026-41940.

The attackers then try to bypass authentication and collect credentials, configs, SSH data, GitHub/GitLab tokens, and cloud keys.

Why it matters: they are not abusing developers’ systems, but the CI/CD infrastructure itself, turning it into a tool for finding victims.

Are you reviewing your GitHub Actions policies across your projects?
#cybersecurity #GitHubActions #DevSecOps #SupplyChain

Open analytics
On the site 1 views
min read 1 23.07.2026
On Instagram 3 views
On Instagram 1 reach
Instagram

Attention, colleagues: GitHub Actions runners are being used to attack cPanel and WHM

Open the post on Instagram ↗