Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
ID: e7d97a51-0142-5d4d-8822-1cc74b711a24
STIX ID: report--e7d97a51-0142-5d4d-8822-1cc74b711a24
Feed Name: Bleeping Computer
Threat Score
A critical cPanel/WHM authentication bypass (CVE-2026-41940) has been patched but is being actively exploited in the wild to breach servers and deploy a Linux-specific 'Sorry' ransomware encryptor that appends .sorry to files; Shadowserver reports around 44,000 compromised IPs and victims receive README.md ransom notes pointing to a Tox contact.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
