Hackers target governments and MSPs via critical cPanel flaw CVE-2026-41940
ID: 6101a2c5-297d-5d15-aed7-51dd09ba23a4
STIX ID: report--6101a2c5-297d-5d15-aed7-51dd09ba23a4
Feed Name: Security Affairs
Attackers are actively exploiting CVE-2026-41940, an authentication-bypass in cPanel/WHM, to compromise government, military, MSP and hosting provider systems across Southeast Asia and other countries. Observed activity includes exploitation via public PoCs (notably linked to IP 95.111.250.175), a custom exploit chain against an Indonesian defense training portal, deployment of AdaptixC2 and PowerShell reverse shells, persistent pivoting using OpenVPN and Ligolo, and exfiltration of approximately 4.37 GB of sensitive technical and personal data.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
