Morning Review in IT Security — July 23, 2026
The threat landscape continues to evolve with significant developments across multiple attack vectors. Today's review covers a sophisticated supply chain compromise leveraging GitHub Actions infrastructure, critical kernel vulnerabilities affecting Linux systems, major data breaches impacting millions of users, and privilege escalation flaws in widely deployed software.
Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign
A comprehensive investigation has uncovered a widespread campaign exploiting compromised GitHub repositories to conduct internet-scale scanning and credential harvesting operations. Between July 12 and 13, 2026, threat actors pushed malicious GitHub Actions workflow files to ten PHP packages maintained by developer dinushchathurya on Packagist, with each affected development version containing between 55 and 62 malicious YAML automation files totaling 583 files across all packages. Source: Large-Scale GitHub Actions Abuse Powers a Distributed cPanel and WHM Exploitation Campaign
The malicious workflows were designed to execute on GitHub-hosted Ubuntu runners following repository pushes or manual execution, downloading architecture-specific Linux payloads from threat actor-controlled infrastructure at 43.228.157.68. These payloads targeted internet-facing cPanel and WHM systems through CVE-2026-41940, an authentication bypass vulnerability, while simultaneously harvesting credentials including AWS keys, GitHub and GitLab tokens, OpenAI and Google credentials, Stripe keys, database information, SSH material, and configuration files. The campaign implemented a resilient command-and-control pipeline with continuous heartbeat callbacks every 30 seconds and chunked HTTP POST exfiltration of up to 5,000 lines of collected data.
The scope of this operation extends far beyond a single compromised maintainer. GitHub Code Search identified approximately 6,100 matching workflow files using the campaign's unique DNSHook identifier, with broader searches across C2 addresses, scanner commands, and exfiltration logic returning roughly 15,000 to 16,000 matching files across unrelated repositories. The distinctive code reuse across established projects with recorded Actions runs confirms this represents an ongoing broad campaign rather than an isolated incident. The affected parties span repository owners facing account restrictions and resource consumption, GitHub-hosted runners repurposed as disposable attack infrastructure, cPanel and WHM operators subject to direct exploitation, and hosting customers with exposed websites, databases, and application secrets.
RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS
The Qualys Threat Research Unit has disclosed CVE-2026-64600, a critical race condition in the Linux kernel's XFS filesystem copy-on-write path that permits local privilege escalation to root. An attacker with ordinary local account access can exploit this vulnerability to overwrite protected files on disk and gain complete host root privileges, including on systems running SELinux in Enforcing mode. Source: RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600)
This vulnerability represents a significant risk to Linux deployments utilizing XFS filesystems, as the attack requires no special privileges or system modifications and can bypass security frameworks designed to protect kernel integrity.
Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts
Two separate data breaches have exposed sensitive information from tens of millions of user accounts across the Suno and Paidwork platforms. The compromised data includes names, email addresses, phone numbers, passwords, and financial information, with hackers publicly releasing the stolen records. Source: Suno, Paidwork Data Breaches Affect Tens of Millions of Accounts
These breaches underscore the ongoing risks associated with inadequate data protection measures and the continued exposure of financial records through platform compromises.
Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
Cybersecurity researchers have disclosed CVE-2026-8933, a high-severity local privilege escalation vulnerability in snap-confine with a CVSS score of 7.8. An unprivileged user can trigger this race condition to obtain root access and achieve complete control of affected systems running default installations of Ubuntu Desktop 24.04, 25.10, and 26.04. Source: Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs
This vulnerability poses a significant risk to the widespread Ubuntu Desktop user base, as exploitation requires no special permissions and affects default system configurations used by millions of users globally.
The convergence of these threats—from sophisticated supply chain attacks to kernel-level vulnerabilities and widespread data breaches—demonstrates the multifaceted nature of the current threat environment. Organizations must prioritize patching critical kernel vulnerabilities, securing CI/CD infrastructure against GitHub Actions abuse, and implementing robust credential rotation following data breach disclosures.