cPanel and WHM Emergency Patches Address Three Critical Flaws

cPanel and WHM have released emergency patches for three vulnerabilities that could allow attackers to compromise web hosting environments through authentication bypass and privilege escalation.

The Latest

Breaking News and Alerts

Hackers Exploit Critical cPanel Flaw to Breach Governments and Hosting Firms

The threat actor also used a prior custom exploit chain involving SQL injection and CAPTCHA bypass against an Indonesian defense training portal before pivoting to cPanel attacks.

Spotlight

Cybersecurity Profiles and Stories

DigiCert Breach: Stolen EV Code Signing Certificates Linked to Zhong Stealer Malware

The attacker exploited a malfunctioning endpoint sensor to maintain undetected access for ten days, stealing certificates used to sign Zhong Stealer malware.

Bluekit Phishing Platform Bundles Domain Automation, 2FA Circumvention, and Session Hijack Tools

Varonis researchers found that Bluekit's centralized dashboard captures session tokens and cookies after victims complete 2FA, rendering that security measure ineffective.

New Supply Chain Worm Hits SAP npm Packages, Targets Developer Secrets

The Mini Shai-Hulud worm uses a Bun runtime bootstrap to silently harvest credentials from developer machines, cloud platforms, and AI coding tools before npm install completes.

Apache MINA Flaws Expose Enterprise Apps to Full Takeover

A botched merge left critical Apache MINA deserialization fixes unpublished until project maintainers caught the error and reissued versions 2.2.7 and 2.1.12.

Features

Research and Thought Leadership