A critical cPanel vulnerability (CVE-2026-41940) is being actively exploited at scale, with over 2,000 attacker IPs observed deploying backdoors, planting SSH keys, stealing credentials, and running cryptominers and ransomware. The threat group Mr_Rot13, active for six years, is linked to some activity. Security experts warn that hosting control panels are often under-monitored compared to endpoints and cloud workloads, creating a blind spot in enterprise security. Recommended response includes credential rotation, SSH key audits, webshell hunting, and reviewing outbound traffic for Telegram-based data exfiltration. Organizations relying on third-party hosting providers face indirect exposure risks that are difficult to detect without direct visibility into the hosting stack.

4m read timeFrom csoonline.com
Post cover image
159 Impressions