重置
网络安全
GitHub Actions 被滥用用于扫描 cPanel/WHM:10 个 PHP 包被入侵,CVE-2026-41940 大规模利用
GitHub Actions 被滥用用于扫描 cPanel/WHM:10 个 PHP 包被入侵,CVE-2026-41940 大规模利用

Socket.dev 记录了一场网络攻击活动,其中 583 个 GitHub Actions 工作流被嵌入 10 个 PHP 包中,用于扫描互联网上存在 CVE-2026-41940 漏洞(cPanel/WHM 认证绕过漏洞)的实例,以窃取几乎所有可用的凭据。约 6,100 个工作流在 GitHub 上带有该活动的签名。

Jul 23, 2026 18 3

LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
主题
浏览
信息