Related Threat Clusters
-
Critical Zero-Day Vulnerability in LiteSpeed cPanel Plugin Actively Exploited
A critical zero-day privilege escalation vulnerability in the LiteSpeed User-End cPanel plugin is being exploited in the wild, allowing authenticated cPanel users to execute arbitrary scripts as root. This flaw, tracked…
17 articles · Updated May 23, 2026 -
Critical cPanel Vulnerability Exploited in Southeast Asia Cyber Attacks
A sophisticated cyber campaign has exploited a critical cPanel vulnerability (CVE-2026-41940) to breach government and military servers in Southeast Asia, particularly targeting Indonesia. The attackers utilized a…
3 articles · Updated May 4, 2026 -
CISA Issues Urgent Warning on Actively Exploited LiteSpeed cPanel Plugin Vulnerability
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has issued a warning regarding a critical vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin, which allows attackers with FTP or web…
5 articles · Updated June 16, 2026 -
cPanel and WHM Critical Auth Bypass Vulnerability Patched
A critical authentication vulnerability affecting all supported versions of cPanel and WHM was disclosed on April 28, 2026. This flaw allows attackers to gain unauthorized access to the control panel, posing significant…
69 articles · Updated April 29, 2026 -
Critical cPanel Vulnerability Allows Full Database Access via Privilege Escalation
A critical privilege-escalation vulnerability, tracked as CVE-2026-58048, has been disclosed in cPanel & WHM, allowing authenticated users to execute arbitrary SQL commands with full administrative privileges. This flaw…
3 articles · Updated August 4, 2026 -
DigiCert Hacked via Malicious Screensaver File, EV Certificates Stolen
In April 2026, DigiCert experienced a breach due to a social engineering attack that compromised its tech support team. An attacker tricked two employees into executing a malicious screensaver file, leading to the theft…
6 articles · Updated May 4, 2026 -
GitHub Actions Exploited to Attack cPanel and WHM Servers
A large-scale cyber campaign has compromised multiple GitHub repositories to deploy malicious workflows targeting cPanel and WHM servers. Attackers are using GitHub Actions to automate the scanning of the internet for…
4 articles · Updated July 23, 2026 -
APT Groups Target Construction Sector for Credential Theft
Advanced persistent threat (APT) groups from China, Russia, North Korea, and Iran are increasingly attacking the construction industry to gain unauthorized access to corporate networks. These attacks exploit…
2 articles · Updated November 11, 2025 -
APT Groups Target Construction Sector for Credential Theft
The construction sector is facing increased cyber intrusions from state-backed APT groups from China, Russia, North Korea, and Iran. These groups are exploiting vulnerabilities related to the industry's digital…
2 articles · Updated November 11, 2025
Recent Intelligence Reports
- Critical cPanel Vulnerability Allows Execution of SQL Commands as Root User — Cybersecuritynews · August 4, 2026
- cPanel Database Privilege Escalation Flaw Enables Full Administrative Access — Gbhackers · August 4, 2026
- Hackers Abuse GitHub Actions to Exploit cPanel and WHM Servers and Steal Cloud Credentials — Cybersecuritynews · July 23, 2026
- Compromised GitHub repositories weaponized to attack cPanel and WHM servers — Feeds.4Sysops · July 23, 2026
- Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers — Thehackernews · July 23, 2026
- Hackers Turn GitHub Actions Into a Global Botnet for Attacking Web Hosting Servers — Gbhackers · July 23, 2026
- Security Update For Litespeed Cpanel Plugin 2 — blog.litespeedtech.com · June 16, 2026
- CISA warns of another cPanel plugin flaw exploited in attacks — Bleepingcomputer · June 16, 2026