← Back

Wire · technology

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Published

23 July 2026

Topic

technology

Sectors

CybersecurityDeveloper ToolsCloud Infrastructure

Source

Read at thehackernews.com

Verified

Fusion42 · 23 July 2026 · Fusion42 review

Attackers compromised ten PHP packages on Packagist by injecting malicious GitHub Actions workflows that turn GitHub runners into distributed attack infrastructure targeting cPanel and WHM servers via CVE-2026-41940, harvesting credentials and secrets at scale.

This Wire brief sits within Fusion42's coverage of Cybersecurity, Developer Tools and Cloud Infrastructure.

◆ The Wire takeaway

If you ship code that pulls dependencies from Packagist or runs GitHub Actions workflows, your build pipeline just became an attack vector that doesn't belong to you. Audit your action permissions this week and lock down secrets rotation—GitHub runners now need to be treated as untrusted compute.

Coverage

1 source · 23 Jul 2026

Related on Wire

Topics

CybersecurityDeveloper ToolsCloud Infrastructuresupply-chain-attackgithub-actions-abusecpanel-whmci-cd-securitypackagist-compromise