As cited
Copy frozen at (site build).
threat intel
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
Researchers discovered a large-scale campaign weaponizing compromised GitHub repositories and Actions runners as attack infrastructure against cPanel and WebHost Manager instances. The campaign involved malicious Packagist development versions across 10 packages associated with a legitimate PHP and DevOps developer between July 12 and 13.
Why it matters: Hosting providers and developers using cPanel, WHM, or Packagist dependencies face direct exploitation risk from this active supply-chain attack; practitioners should review GitHub Actions configurations and audit Packagist package versions deployed in production.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
threat intel
Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers
Researchers discovered a large-scale campaign weaponizing compromised GitHub repositories and Actions runners as attack infrastructure against cPanel and WebHost Manager instances. The campaign involved malicious Packagist development versions across 10 packages associated with a legitimate PHP and DevOps developer between July 12 and 13.
Why it matters: Hosting providers and developers using cPanel, WHM, or Packagist dependencies face direct exploitation risk from this active supply-chain attack; practitioners should review GitHub Actions configurations and audit Packagist package versions deployed in production.
- Source published
- First seen by Cybersecurity Tracker