GitHub Actions hijacked to scan cPanel/WHM: 10 PHP packages compromised and CVE-2026-41940 exploited at scale
Socket.dev documented a campaign where 583 GitHub Actions workflows slipped into 10 PHP packages scan the Internet for cPanel/WHM instances vulnerable to the CVE-2026-41940 authentication bypass - to steal almost all available credentials. Approximately 6,100 workflows bear the campaign's signature on GitHub.
1 h ago 18 3





