Critical cPanel Vulnerability Weaponized to Target Government and MSP Networks
ID: 4458bd74-d899-5f34-9ded-e67565feebbe
STIX ID: report--4458bd74-d899-5f34-9ded-e67565feebbe
Feed Name: The Hacker News
A previously unknown threat actor actively exploited CVE-2026-41940 in cPanel/WHM to target government and military domains in Southeast Asia and a cluster of MSPs and hosting providers globally. The campaign used public PoCs and a custom exploit chain (authenticated SQL injection + RCE) against an Indonesian defense portal, employed AdaptixC2 plus OpenVPN and Ligolo for persistent access and pivoting, and resulted in exfiltration of Chinese railway-sector documents; Shadowserver observed up to ~44,000 likely compromised IPs scanning honeypots, and third parties rapidly weaponized the vulnerability with Mirai variants and the Sorry ransomware.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
