South-East Asian Military Entities Targeted via cPanel (CVE-2026-41940)
ID: 68b7fa57-1a5c-5a73-8027-ebb293e873fb
STIX ID: report--68b7fa57-1a5c-5a73-8027-ebb293e873fb
Feed Name: Ctrl-Alt-Int3l
Ctrl-Alt-Intel discovered an active campaign that rapidly weaponised CVE-2026-41940 (cPanel/WHM authentication bypass) using public PoCs to compromise internet-facing control panels and a separate custom SQLi->PostgreSQL RCE against an Indonesian defence portal; the operator used OpenVPN + Ligolo pivoting, AdaptixC2 and systemd-based persistence to access internal networks and exfiltrated ~4.37GB of China railway-sector documents (110 files), with numerous IOCs and MITRE ATT&CK mappings provided.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
