language
Detectat automat

Am preselectat Română și Romanian Leu (lei) pentru tine.

Autentificare
softwarebay.de
softwarebay.de
Cyberattacks via GitHub Actions Target cPanel Servers
News Cybersecurity Cyberattacks via GitHub Actions Target cPanel Serv...
Cybersecurity

Cyberattacks via GitHub Actions Target cPanel Servers

Cyberattacks via GitHub Actions Target cPanel Servers

Cybersecurity researchers have uncovered an extensive campaign that utilizes compromised GitHub repositories as a distributed attack framework to target cPanel and WebHost Manager (WHM) instances. These activities were detected between July 12 and 13, 2026, and involve several malicious development versions of 10 packages associated with the legitimate PHP and DevOps developer dinushchathurya. The attackers have specifically employed GitHub Actions Runners to orchestrate their attacks.

This technique allows for the use of automated processes in software development to execute malicious code. Researchers identified that the attacks on cPanel and WHM servers were facilitated by the manipulation of packages in the affected repositories. The compromised packages were considered trustworthy within the PHP developer community, increasing the likelihood that users would download and utilize them. The use of GitHub as a platform for distributing malware poses a significant risk to the security of web hosting services, as many companies rely on this software. Security researchers have found that the attackers are not only targeting cPanel and WHM servers but are also attempting to gain access to sensitive data.

The attacks could jeopardize personal information of users and businesses. Researchers advise regularly checking the integrity of the packages used and promptly installing security updates. The campaign has already affected a multitude of servers, with the exact number of compromised systems still being determined. Security analyses indicate that the attackers are capable of rapidly scaling their infrastructure, complicating defensive measures. Researchers warn that similar attacks may increase in the future if appropriate protective measures are not implemented.

The vulnerability exploited by these attacks could also affect other software projects hosted on GitHub. Developers are urged to monitor their repositories for suspicious activities and ensure that their dependencies come from trusted sources. The use of security tools to verify code and dependencies is strongly recommended. The incidents have already led to heightened awareness within the developer community. Many users have begun to reassess their security practices and implement additional protective measures.

The response to these attacks could have long-term implications for the use of GitHub Actions and similar automation tools. Security researchers have documented the affected packages and their versions to enable a targeted response to the threat. Users of cPanel and WHM should stay informed about the latest developments and update their systems as necessary. The exact list of affected packages will be published in the coming days. The security situation remains tense as the attackers continue to refine their methods.

Researchers are working to gather more information about the attackers and their infrastructure. The discovery of these attacks could lead to increased collaboration between security researchers and software developers to enhance the security of open-source projects. According to researchers, the vulnerability affects a variety of servers worldwide, with the exact number of impacted systems still being assessed. Researchers emphasize the need to review and, if necessary, adjust security policies to prevent future attacks.

Tags: Cybersecurity GitHub cPanel WHM Malware Attacks Software Development IT Security

💬 Comentarii (0)

Scrie un comentariu

info Va fi publicat dupa moderare
chat_bubble_outline

Inca nu exista comentarii. Fii primul!

Live support available
Sarah E.
Sarah E.
check_circle Bucharest
Hello! I am Sarah. Do you have questions about our products or need help?
chat_bubble