Reset
Cybersecurity
GitHub Actions hijacked to scan cPanel/WHM: 10 PHP packages compromised and CVE-2026-41940 exploited at scale
GitHub Actions hijacked to scan cPanel/WHM: 10 PHP packages compromised and CVE-2026-41940 exploited at scale

Socket.dev documented a campaign where 583 GitHub Actions workflows slipped into 10 PHP packages scan the Internet for cPanel/WHM instances vulnerable to the CVE-2026-41940 authentication bypass - to steal almost all available credentials. Approximately 6,100 workflows bear the campaign's signature on GitHub.

Jul 23, 2026 18 3

Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

Get early access
Cybersecurity
Hugging Face breach: when an autonomous AI agent serves as a swarm-scale intrusion tool
Hugging Face breach: when an autonomous AI agent serves as a swarm-scale intrusion tool

On July 20, 2026, Hugging Face revealed a breach in its production infrastructure. The entry was made through a malicious dataset, but the most disturbing aspect is elsewhere: the post-intrusion operations were carried out by an "autonomous agent framework" executing thousands of actions across a swarm of ephemeral sandboxes.

Jul 20, 2026 23 3

LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information