A Malware Campaign Is Using GitHub Actions to Hunt Unpatched cPanel Servers

Three months after cPanel shipped an emergency fix for CVE-2026-41940, the critical authentication bypass has found a second delivery system, and this time it runs on GitHub’s own machines. On July 22, the security firm Socket reported that a malware operation has been abusing GitHub Actions, the automation service built into code repositories, to turn … Continue reading A Malware Campaign Is Using GitHub Actions to Hunt Unpatched cPanel Servers