THE content reports on a critical cybersecurity alert concerning two active exploits: CVE-2026-16232 and CVE-2026-50522. Researchers uncovered a campaign involving GitHub Actions abuse, which facilitated credential theft and exploitation of cPanel and WHM servers. Approximately 583 malicious workflows linked to PHP packages on Packagist were used, resulting in potential access to 6,100 to 16,000 GitHub repositories.
The attackers, an unattributed threat actor, gained push access to a maintainer's repositories and executed malicious actions without the PHP code being directly compromised. The stolen credentials included AWS keys and database logins. Defenders are advised to patch vulnerabilities, restrict access, and audit workflows.