[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fH2Agz26arNPTxV7dRMBObd49b4jYriIUVVn1Lgdawq8":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"420d1ee0-4484-4ed5-bb24-a73e9019e270","malicious-php-packages-weaponize-github-actions-to-exploit-cpanel-servers","61d6fb0c-6860-49e7-9def-307d665744d2","Malicious PHP Packages Weaponize GitHub Actions to Exploit cPanel Servers","Attackers injected malicious GitHub Actions workflows into 10 compromised PHP packages on Packagist, effectively turning GitHub's own hosted runners into a distributed attack platform targeting cPanel servers via CVE-2026-41940, an authentication bypass vulnerability. This attack is a compound supply chain threat: it exploits developer trust in open-source package registries, abuses legitimate CI\u002FCD infrastructure to obscure malicious activity, and capitalizes on unpatched server software to harvest credentials. The scale — over 6,100 malicious workflow files identified — demonstrates how CI\u002FCD pipelines have become high-value attack vectors that organizations rarely scrutinize as rigorously as production environments. This matters because any developer or organization pulling these packages inherits weaponized build pipelines that can silently exfiltrate secrets and credentials without ever touching their own infrastructure directly.","**Immediate actions:**\n- Audit all third-party Packagist dependencies for unexpected or modified GitHub Actions workflow files before the next build cycle.\n- Patch cPanel and WHM servers to a version that remediates CVE-2026-41940 and enforce multi-factor authentication on all control panel interfaces.\n- Rotate any credentials or secrets that may have been exposed through GitHub Actions environment variables or repository secrets.\n\n**Detection measures:**\n- Enable GitHub Advanced Security or equivalent tooling to scan workflow files for unauthorized outbound network calls or payload download patterns.\n- Monitor CI\u002FCD job logs for anomalous external HTTP requests, credential access events, or unexpected runner behaviors.\n- Subscribe to Packagist and GitHub security advisories to receive timely alerts on compromised packages or maintainer account takeovers.\n\n**Long-term improvements:**\n- Implement a software supply chain vetting process that pins dependency versions and verifies package integrity via checksums or signed releases before adoption.\n- Apply the principle of least privilege to GitHub Actions workflows by restricting runner permissions and using ephemeral, self-hosted runners isolated from production secrets.\n- Establish a formal vulnerability management program that prioritizes patching of internet-facing control panels and enforces SLA-based remediation timelines.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 2 – Inventory and Control of Software Assets","CIS Control 7 – Continuous Vulnerability Management","CIS Control 16 – Application Software Security","NIST SP 800-161 – Supply Chain Risk Management","NIST CSF ID.SC-4 – Supplier Risk Assessment","NIST SP 800-53 SA-12 – Supply Chain Protection","NIST SP 800-53 SI-2 – Flaw Remediation","NIST SP 800-53 CM-7 – Least Functionality","SLSA Framework – Supply Chain Levels for Software Artifacts","GDPR Article 32 – Security of Processing (credential exposure risk)","published","2026-07-23T14:21:25.891773+00:00","2026-07-23T14:21:25.589+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fthehackernews.com\u002F2026\u002F07\u002Fattackers-weaponize-github-actions.html","attackers-weaponize-github-actions-runners-to-target-cpanel-and-whm-servers-2f8c8b","Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"05757c8d-6b93-4194-b35d-7359e7d33b0e","Vulnerability Management","vulnerability-management","Missing scans, no risk prioritization","#fb923c",{"id":37,"name":38,"slug":39,"description":40,"color":41},"859cf0ad-a7e9-42bb-a75d-bac6511fa5d5","Configuration Management","configuration-management","Misconfigs, default credentials, exposed services","#eab308",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f0c2a0af-58aa-4128-87c9-6acd30f2dc48","Supply Chain","supply-chain","Third-party risk, compromised dependencies","#8b5cf6",[]]