惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Microsoft Security Blog
Microsoft Security Blog
J
Java Code Geeks
GbyAI
GbyAI
aimingoo的专栏
aimingoo的专栏
L
LangChain Blog
I
InfoQ
D
Docker
F
Fortinet All Blogs
Y
Y Combinator Blog
Martin Fowler
Martin Fowler
月光博客
月光博客
B
Blog
Engineering at Meta
Engineering at Meta
T
Tailwind CSS Blog
罗磊的独立博客
博客园_首页
G
Google Developers Blog
Stack Overflow Blog
Stack Overflow Blog
Recent Announcements
Recent Announcements
D
DataBreaches.Net
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
B
Blog RSS Feed
IT之家
IT之家
V
V2EX

Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises | CSO Online

Die besten DAST- & SAST-Tools CISA mulls new three-day remediation deadline for critical flaws CISA pushes critical infrastructure operators to prepare to work in isolation CISOs step up to the security workforce challenge 10 Anzeichen für einen schlechten CSO Anthropic Mythos spurs White House to weigh pre-release reviews for high-risk AI models Security agencies draw red lines around agentic AI deployments The fake IT worker problem CISOs can’t ignore How CISOs should utilize data security posture management to inform risk Was ist ein Botnet? Human-centric failures: Why BEC continues to work despite MFA Just 34% of cyber pros plan to stick with their current employer Managing OT risk at scale: Why OT cyber decisions are leadership decisions 4 ways to prepare your SOC for agentic AI ‘Trivial’ exploit can give attackers root access to Linux kernel Bank regulator sounds warning over cybersecurity threat posed by AI models Dismantle implicit trust in OT networks, CISA tells critical infrastructure operators Max-severity RCE flaw found in Google Gemini CLI Stopping the quiet drift toward excessive agency with re-permissioning ODNI to CISOs on threat assessments: You’re on your own 10 wichtige Security-Eigenschaften: So setzen Sie die Kraft Ihres IT-Sicherheitstechnik-Teams frei Researchers unearth industrial sabotage malware that predated Stuxnet by 5 years AWS leans on prior ingenuity to face future AI and quantum threats What it takes to win that CSO role Third Party Risk Management: So vermeiden Sie Compliance-Unheil Critical Cursor bug could turn routine Git into RCE Securing RAG pipelines in enterprise SaaS What CISOs need to get right as identity enters the agentic era Stopping AiTM attacks: The defenses that actually work after authentication succeeds EDR-Software – ein Kaufratgeber
cPanel flaw exposes enterprises to hosting supply-chain r...
2026-05-12 · via Google adds end-to-end Gmail encryption to Android, iOS devices for enterprises | CSO Online

A newly disclosed cPanel vulnerability is being exploited at scale, giving attackers a route into web hosting environments that many enterprises may not monitor closely. Analysts say the risk highlights weak visibility into hosting supply chains.

The flaw, tracked as CVE-2026-41940, has been used to deploy backdoors, plant SSH keys, steal credentials, and compromise hosting systems, according to researchers at XLab. The researchers linked some of the activity to a long-running threat group they call Mr_Rot13.

For CISOs, the worry is not just the bug, but where it sits. cPanel and similar tools often operate at the edge of the enterprise, managing websites, portals, and hosted applications. If they are exposed to the internet and not monitored with the same rigor as endpoints, cloud workloads, or core business systems, they can become attractive entry points for attackers.

“This is a classic aggregator-level attack: instead of targeting individual companies, threat actors compromise the centralized management layer that aggregates hundreds of unrelated tenants on the same server,” said Sunil Varkey, a cybersecurity analyst.

XLab said exploitation began after the vulnerability was publicly disclosed in late April. The researchers observed more than 2,000 attacker source IPs involved in automated attacks. The activity included cryptomining, ransomware deployment, botnet propagation, backdoor installation, and data theft, suggesting the flaw has drawn broad attacker interest.

Varkey said security researchers estimate that more than 40,000 servers may have been at risk in the initial wave alone.

“The speed and scale of exploitation after CVE-2026-41940’s disclosure should tell CISOs that internet-facing control panels are now high-priority exploitation targets, not just administrative utilities,” said Sakshi Grover, senior research manager for IDC Asia Pacific Cybersecurity Services.

Keith Prabhu, founder and CEO of Confidis, said the speed of exploitation shows that internet-facing management planes now have little to no grace period once a critical authentication-bypass flaw becomes public.

Distributed scanning infrastructure and botnets have made attack automation easier to scale, he said, increasing the chances that high-impact flaws will be exploited soon after disclosure.

Mr_Rot13 has operated with a low detection rate for about six years, according to XLab. Its tooling includes a cross-platform remote control program, PHP webshells, JavaScript credential stealers, and components designed to collect SSH data, bash history, database passwords, and cPanel virtual aliases.

“Many organizations have improved visibility across endpoints, cloud workloads, and SaaS platforms, but shared hosting, control panels, web shells, and Linux administrative layers are still often treated as operational infrastructure rather than high-risk attack surfaces,” Grover said.

Grover added that the gap is also about whether the right tools are watching this layer at all. Many security products are not deployed or tuned for cPanel-layer activity, which can leave even mature security teams with limited visibility into the hosting control plane.

The enterprise risk may extend beyond organizations that directly run cPanel. Many companies rely on hosting providers, managed service providers, marketing agencies, and external web teams to operate public-facing sites, customer portals, microsites, and application infrastructure. That can make exposure difficult to identify when security teams do not have direct visibility into the hosting stack.

Steps for security teams

Security teams should first determine whether any internet-exposed cPanel servers were accessible during the exploitation window, Varkey said.

The response should go beyond applying the vendor fix, including credential rotation, checks for unauthorized SSH keys, webshell hunting, review of anomalous processes, and signs that attackers modified login pages or planted persistence mechanisms.

Prabhu said organizations should treat potential exposure as an incident response matter, not just a patch management task. A review should include session and authentication logs, persistence hunting, identity and credential checks, web application compromise analysis, and correlation of logs and telemetry, he said.

Security teams should pay particular attention to data exfiltration channels that may not be covered by standard monitoring tools, according to Grover.

Organizations should also review hosted website content for injected scripts and examine outbound traffic for Telegram-based exfiltration, Grover said. The campaign has reportedly used Telegram to route stolen data, including bash history, SSH credentials, database passwords, and cPanel aliases, which may not be flagged by standard data-loss prevention or egress monitoring tools.

For internet-facing management systems, patching timelines can no longer be measured in days. Security teams need to move within hours, Varkey said.

SUBSCRIBE TO OUR NEWSLETTER

From our editors straight to your inbox

Get started by entering your email address below.