socket-dev · Crawled Jul 22, 2026
Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign
3 IoCs
Read original article ↗
AI Summary
A large-scale campaign has abused GitHub Actions by compromising repositories to exploit CVE-2026-41940, a cPanel and WHM authentication bypass vulnerability. Malicious workflow files were pushed to compromised repositories, triggering execution on GitHub-hosted runners that downloaded and ran a Linux-based scanner to target vulnerable servers. The payload scanned for exposed credentials, configuration files, and secrets, exfiltrating them to attacker-controlled infrastructure. This campaign extended beyond a single developer, leveraging distributed infrastructure for scanning, exploitation, and credential harvesting at scale.
AI-extracted · verify before operational use