Vulnerabilities · 53 days ago

GitHub Actions Turned into cPanel Attack Infrastructure

Compromised developer repos are now part of the attack surface. The campaign is using GitHub-hosted runners as disposable infrastructure, so the scans look like normal CI jobs instead of direct attacker traffic, which makes both attribution and perimeter filtering weaker.

Investigators tied the activity to 583 malicious workflows across 10 compromised Packagist packages tied to a legitimate developer. Those workflows trigger on repo pushes or manual runs, launch GitHub-hosted runners, and target cPanel and WHM instances vulnerable to CVE-2026-41940; cPanel/WHM 11.40 fixes the flaw.

The broader risk is that abused CI can scale exploitation without a stable attack host, and the compromised packages create a second supply-chain path beyond the control panel itself. Once trusted automation is repurposed this way, detection has to account for legitimate cloud infrastructure doing hostile work.

CVE-2026-41940

NVD KEV

Known exploited · CISA KEV

CVSS 9.8 CRITICAL: cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows… EPSS 99% (100th percentile).

CISA federal remediation date May 3 · date passed

Timeline

Sources

2 sources covering this story

Entities

Part of the PlainSec briefing for 2026-07-24

Editions

Related stories