Cybersecurity experts are sounding the alarm after discovering that attackers have exploited GitHub Actions Runners, a popular automation tool, to compromise cPanel and WHM servers on a massive scale. The attack vector leverages a critical vulnerability in the way these tools interact with each other, highlighting the need for increased vigilance in protecting server infrastructure.
GitHub Actions Runners are used by developers to automate tasks and workflows on their GitHub repositories. However, as it turns out, attackers have discovered that they can use these runners to execute malicious code on compromised servers, effectively gaining remote access to sensitive systems. The vulnerability allows an attacker to inject a payload into the runner’s environment variables, which is then executed without any additional authentication or verification.
This attack vector specifically targets cPanel and WHM servers, which are widely used by web hosting providers and resellers due to their ease of use and feature-rich interface. The attackers appear to be exploiting a combination of factors, including outdated software, weak passwords, and poor configuration settings on these servers. Once inside, they can install malware, steal sensitive data, or even take control of the server’s administrative privileges.
The severity of this attack is compounded by the fact that it relies on a critical vulnerability in GitHub Actions Runners, which has been exploited in conjunction with other weaknesses in cPanel and WHM software. This highlights the need for organizations to prioritize patching and updating their software, especially when it comes to automation tools like GitHub Actions Runners.
Furthermore, this attack demonstrates how AI-powered threat detection can be both a blessing and a curse. On one hand, AI models have proven effective in discovering previously unknown vulnerabilities and identifying potential security risks. On the other hand, attackers are now using these same AI techniques to identify and exploit weaknesses in server infrastructure. This has significant implications for cybersecurity professionals, who must adapt their strategies to stay ahead of increasingly sophisticated threats.
In light of this incident, we urge all organizations that rely on cPanel or WHM servers to take immediate action by reviewing their security configurations, updating software to the latest versions, and implementing robust access controls. Additionally, users should be aware of any suspicious activity on their GitHub repositories and take steps to secure their automation workflows. By doing so, they can significantly reduce their exposure to this type of attack and protect their sensitive systems from potential compromise.
Source: The Hacker News — 2026-07-23