공격자들이 GitHub Actions 러너를 악용해 cPanel과 WHM 서버를 공격하고 있다.
사이버 보안 연구자들이 GitHub 저장소를 악용한 대규모 캠페인에 대해 밝히고 있다. 이 캠페인은 cPanel과 WebHost Manager(WHM) 인스턴스를 겨냥한 분산 공격 인프라로 변모했다. 이 과정에서 합법적인 PHP 및 DevOps 개발자와 관련된 10개의 패키지에서 악성 Packagist 개발 버전이 확인되었다.
Attackers are exploiting GitHub Actions runners to target cPanel and WHM servers.
Cybersecurity researchers have revealed a large-scale campaign that utilizes compromised GitHub repositories as a distributed attack infrastructure targeting cPanel and WebHost Manager (WHM) instances. The activity involves malicious development versions of 10 packages associated with a legitimate PHP and DevOps developer. These developments occurred between July 12 and 13.