Hackers Breach Government and Military Servers by Exploiting cPanel Vulnerability
ID: 5790702c-f689-5eb3-afcb-ea49d9b30e1a
STIX ID: report--5790702c-f689-5eb3-afcb-ea49d9b30e1a
Feed Name: cybersecurityNews.com
A sophisticated, multi-stage campaign exploited a critical cPanel authentication bypass (CVE-2026-41940) and a custom authenticated SQLi → PostgreSQL RCE against an Indonesian defence training portal to achieve root access, deploy C2 (95.111.250.175 / delicate-dew.serveftp.com), maintain persistence via OpenVPN and Ligolo, and exfiltrate 110 files (~4.37 GB) of sensitive China Railway Society documents containing PII and financial records; the report provides payloads, IoCs, and remediation advice but does not assign firm attribution.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
