On April 29, 2026, a highly targeted supply chain attack hit the JavaScript ecosystem. An attacker … Malicious “tanstack” Package Hijacks npm to Steal Dev SecretsRead more
Latest News
Bluekit: The All-in-One Phishing Suite Automating 2FA Bypass
Cybercrime is entering a phase of extreme professionalization, and a newly identified phishing kit called Bluekit … Bluekit: The All-in-One Phishing Suite Automating 2FA BypassRead more
Cybersecurity Pros Turned Ransomware Affiliates Sentenced to Federal Prison
In a case that has sent shockwaves through the information security community, two American cybersecurity professionals … Cybersecurity Pros Turned Ransomware Affiliates Sentenced to Federal PrisonRead more
New “xlabs_v1” Botnet Hijacks Android Devices to Crush Minecraft Servers
In a throwback to the original 2016 Mirai attacks, a new botnet dubbed xlabs_v1 has emerged … New “xlabs_v1” Botnet Hijacks Android Devices to Crush Minecraft ServersRead more
CISA Flags Critical cPanel & WHM Flaw in Active Attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued an urgent alert about a critical cPanel & WHM vulnerability that is being actively exploited to gain administrative access to web hosting systems. CISA added the flaw to its Known Exploited Vulnerabilities (KEV) catalog after observing threat actors using the bug in real-world attacks, raising the risk for hosting providers and site owners. Tracked as CVE-2026-41940, the authentication-bypass defect impacts WebPros cPanel & WHM (WebHost Manager) and WP2 (WordPress Squared), allowing unauthenticated attackers to potentially take control of affected panels. Understanding the Authentication Bypass Flaw CVE-2026-41940 is classified as “Missing Authentication for Critical Function” (CWE-306). In short, the flaw allows unauthenticated remote actors to circumvent the normal login checks in affected control panel software. The vulnerability resides in the login flow of WebPros cPanel & WHM (WebHost Manager) and WP2, meaning attackers can gain administrative access without valid credentials and without completing standard authentication steps. Because control panels provide centralized access to hosting and server configuration, successful exploitation effectively hands attackers the keys to hosted websites and backend servers. What attackers can do if they gain control Why hosting providers and site owners should care Control panels like cPanel & WHM are the administrative backbone for millions of websites and servers; a single exploited bug can affect large numbers of customers and escalate into widespread compromise across hosting infrastructure. Detection tips for administrators For technical details and proof-of-concept reporting, see the linked analysis. When publishing information about PoCs (for example, the referenced exploit write-ups), avoid disclosing step-by-step exploit code in public posts to reduce copycat attempts while still informing defenders about indicators to look for. Required Mitigations and Deadlines CISA has mandated immediate remediation for federal agencies and strongly urges private-sector hosting providers, site owners, and server administrators to take the same urgent steps to close this cPanel & WHM vulnerability. Priority actions for security teams and system administrators: Follow CISA guidance and applicable Binding Operational Directives (for example, BOD 22-01 where relevant) and consult vendor advisories for exact patch commands, file paths, and verification steps. Typical verification includes checking package/version strings, control-panel build numbers, or vendor-provided checksum files. … CISA Flags Critical cPanel & WHM Flaw in Active AttacksRead more
Multiple Exim Flaws Allow Server Crashes via DNS
The Exim development team has released a high-priority security update, version 4.99.2, to address four newly … Multiple Exim Flaws Allow Server Crashes via DNSRead more
High-Speed “Spider” Attacks Bypass MFA to Raid SaaS Data
A new breed of cyber adversary is moving away from traditional malware and focusing entirely on … High-Speed “Spider” Attacks Bypass MFA to Raid SaaS DataRead more
Warning: Multiple Exim Flaws Allow Server Crashes via DNS
The Exim development team has released a high-priority security update, version 4.99.2, to address four newly … Warning: Multiple Exim Flaws Allow Server Crashes via DNSRead more
Critical: 44,000 Servers Compromised via “cPanelSniper” Exploit
The web hosting world is reeling following the release of cPanelSniper, a weaponized proof-of-concept (PoC) exploit … Critical: 44,000 Servers Compromised via “cPanelSniper” ExploitRead more
Warning: New Fake CAPTCHA Scam Explodes Credential Theft
Cybercriminals have found a psychological “cheat code” to bypass your security: the CAPTCHA. In the first … Warning: New Fake CAPTCHA Scam Explodes Credential TheftRead more