logo

South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940)

ID: 68b7fa57-1a5c-5a73-8027-ebb293e873fb

STIX ID: report--68b7fa57-1a5c-5a73-8027-ebb293e873fb

Feed Name: Ctrl-Alt-Int3l

Threat Score
86/100

Date Published: 2026-05-02

Date Updated: 2026-05-02

Author: Ctrl-Alt-Intel

...
...

Ctrl-Alt-Intel discovered an active campaign that rapidly weaponised CVE-2026-41940 (cPanel/WHM authentication bypass) using public PoCs to compromise internet-facing control panels and a separate custom SQLi->PostgreSQL RCE against an Indonesian defence portal; the operator used OpenVPN + Ligolo pivoting, AdaptixC2 and systemd-based persistence to access internal networks and exfiltrated ~4.37GB of China railway-sector documents (110 files), with numerous IOCs and MITRE ATT&CK mappings provided.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.