✨ The Containment Era is here. Secure AI workloads before they breach. →The Containment Era is here. →The Containment Era is here. →Explore ✨
Internet
Breach intelligence, attack campaigns, and threat reports targeting the Internet sector.
Explore Other Sectors
Internet Threat Reports
xlabs_v1 Botnet: A New Threat Exploiting ADB-Exposed IoT Devices
In May 2026, cybersecurity researchers uncovered a new botnet named xlabs_v1, derived from the Mirai malware, which exploits internet-exposed devices running Android Debug Bridge (ADB) on TCP port 5555. This botnet targets devices such as Android TV boxes, set-top boxes, and smart TVs, enlisting them to perform distributed denial-of-service (DDoS) attacks, particularly against game servers and Minecraft hosts. The malware supports 21 flood variants across TCP, UDP, and raw protocols, including RakNet and OpenVPN-shaped UDP, capable of bypassing consumer-grade DDoS protection. Notably, xlabs_v1 lacks a persistence mechanism, requiring re-infection for each attack, and includes a 'killer' subsystem to eliminate competing malware, ensuring full control over the compromised device's bandwidth. ([thehackernews.com](https://thehackernews.com/2026/05/mirai-based-xlabsv1-botnet-exploits-adb.html?utm_source=openai)) The emergence of xlabs_v1 highlights the ongoing evolution of IoT-targeted malware and the increasing sophistication of DDoS-for-hire services. This incident underscores the critical need for securing IoT devices, particularly those with default-enabled services like ADB, to prevent their exploitation in large-scale cyber attacks.
2 months ago
Kill Chain
Urgent: cPanel Vulnerability CVE-2026-41940 Under Active Exploitation
In late April 2026, a critical authentication bypass vulnerability, CVE-2026-41940, was disclosed in cPanel and WHM software, affecting versions after 11.40. This flaw allows unauthenticated remote attackers to gain administrative access to servers, posing a significant risk to millions of websites. Within 24 hours of disclosure, multiple threat actors began exploiting the vulnerability, leading to server compromises, website defacements, and ransomware deployments. Notably, the "sorry" ransomware encrypts files and appends a ".sorry" extension, with over 7,000 cPanel instances identified as compromised. ([helpnetsecurity.com](https://www.helpnetsecurity.com/2026/05/04/multiple-threat-actors-actively-exploit-cpanel-vulnerability-cve-2026-41940/?utm_source=openai)) The rapid exploitation of CVE-2026-41940 underscores the critical need for organizations to promptly apply security patches and implement robust monitoring systems. The incident highlights the increasing speed at which threat actors exploit newly disclosed vulnerabilities, emphasizing the importance of proactive cybersecurity measures.
2 months ago
Kill Chain
Critical cPanel Vulnerability CVE-2026-41940 Exploited by 'Sorry' Ransomware
In late April 2026, a critical authentication bypass vulnerability, CVE-2026-41940, was discovered in cPanel and WHM software, affecting versions released after 11.40. This flaw allows unauthenticated attackers to gain root-level access to servers, leading to potential data theft, malware deployment, or complete server compromise. Exploitation of this vulnerability has been observed in the wild, with attackers deploying the 'Sorry' ransomware to encrypt data on compromised servers. The ransomware appends the '.sorry' extension to encrypted files and demands ransom payments via Tox messaging platform. Given the widespread use of cPanel and WHM across millions of websites, the impact is substantial, with thousands of servers reportedly compromised. Administrators are urged to apply the latest security patches immediately to mitigate this threat. ([support.cpanel.net](https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026?utm_source=openai)) This incident underscores the critical importance of timely patch management and robust security practices in web hosting environments. The rapid exploitation of CVE-2026-41940 highlights the evolving tactics of threat actors targeting widely used infrastructure components, emphasizing the need for continuous vigilance and proactive defense measures.
2 months ago
Kill Chain
Critical cPanel & WHM Authentication Bypass Vulnerability (CVE-2026-41940) Discovered
In April 2026, a critical authentication bypass vulnerability, CVE-2026-41940, was discovered in cPanel & WHM, affecting versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5. This flaw allows remote, unauthenticated attackers to gain root-level administrative access by injecting arbitrary values into server-side session files, effectively bypassing all credential checks. Exploitation in the wild has been confirmed, with attackers leveraging this vulnerability to compromise entire systems, leading to data theft, malware deployment, or complete server erasure. cPanel has released patches to address this issue, and administrators are urged to update immediately to secure their systems. ([support.cpanel.net](https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026?utm_source=openai)) The emergence of this vulnerability underscores the critical importance of timely software updates and robust security practices. With the availability of public proof-of-concept exploits and active exploitation observed, organizations must prioritize patching and monitoring to mitigate the risk of unauthorized access and potential system compromise.
2 months ago
Kill Chain
Urgent Security Update: cPanel & WHM Vulnerability CVE-2026-41940
In April 2026, a critical authentication bypass vulnerability, CVE-2026-41940, was discovered in cPanel and WebHost Manager (WHM) software versions prior to 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.134.0.20, and 11.136.0.5. This flaw allows unauthenticated remote attackers to gain unauthorized access to the control panel, potentially leading to data breaches, malware installation, or complete server compromise. The vulnerability has been actively exploited in the wild, prompting immediate action from hosting providers and website administrators. ([support.cpanel.net](https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026?utm_source=openai)) The inclusion of CVE-2026-41940 in CISA's Known Exploited Vulnerabilities Catalog underscores the ongoing threat posed by unpatched software vulnerabilities. This incident highlights the critical importance of timely software updates and robust security practices to mitigate risks associated with authentication bypass flaws. ([nvd.nist.gov](https://nvd.nist.gov/vuln/detail/CVE-2026-41940?utm_source=openai))
2 months ago
Kill Chain
Critical cPanel Authentication Bypass Vulnerability CVE-2026-41940
In April 2026, a critical authentication bypass vulnerability, CVE-2026-41940, was discovered in cPanel and WebHost Manager (WHM) versions released after 11.40. This flaw allowed unauthenticated remote attackers to gain unauthorized administrative access to affected systems. The vulnerability stemmed from improper handling of user input during the login process, enabling attackers to inject arbitrary data into server-side session files and bypass password verification entirely. cPanel released patches on April 28, 2026, addressing the issue across multiple version branches. However, exploitation had already been observed in the wild prior to the release of these fixes. The Cybersecurity and Infrastructure Security Agency (CISA) added the CVE to its Known Exploited Vulnerabilities list on April 30, 2026, underscoring the severity and active exploitation of this vulnerability. Given the widespread use of cPanel and WHM, with approximately 1.5 million instances exposed online, the potential impact of this vulnerability is significant. Organizations utilizing these platforms should prioritize applying the available patches and reviewing their systems for indicators of compromise to mitigate the risk of unauthorized access and potential data breaches.
2 months ago
Kill Chain
Critical cPanel & WHM Authentication Bypass Vulnerability (CVE-2026-41940) Exploited in the Wild
In late April 2026, a critical authentication bypass vulnerability, CVE-2026-41940, was discovered in cPanel & WHM, affecting versions released after 11.40. This flaw allows unauthenticated remote attackers to gain administrative access to affected systems by exploiting improper session handling during the login process. The vulnerability has been actively exploited in the wild since at least late February 2026, with approximately 1.5 million cPanel instances exposed online. Successful exploitation grants attackers control over the cPanel host system, its configurations, databases, and managed websites. The rapid exploitation of CVE-2026-41940 underscores the increasing sophistication and speed of threat actors in leveraging zero-day vulnerabilities. Organizations must prioritize timely patching and robust security measures to mitigate such risks. This incident highlights the critical importance of proactive vulnerability management and the need for continuous monitoring to detect and respond to emerging threats promptly.
2 months ago
Kill Chain
Huge Networks' Infrastructure Exploited in Massive DDoS Attacks on Brazilian ISPs
In April 2026, Huge Networks, a Brazilian firm specializing in DDoS mitigation, was implicated in orchestrating massive DDoS attacks against Brazilian ISPs. An exposed archive revealed that a threat actor had root access to Huge Networks' infrastructure, utilizing it to build a botnet by exploiting vulnerabilities in TP-Link Archer AX21 routers, specifically CVE-2023-1389. The botnet conducted DNS amplification attacks, significantly impacting targeted ISPs. Huge Networks' CEO attributed the malicious activity to a security breach, suggesting a competitor's involvement to tarnish the company's reputation. This incident underscores the persistent threat posed by botnets leveraging IoT vulnerabilities, even years after patches are released. It highlights the critical need for organizations to secure their infrastructure and monitor for unauthorized access to prevent exploitation in large-scale cyberattacks.
2 months ago
Kill Chain
Critical cPanel & WHM Authentication Bypass Vulnerability (CVE-2026-41940) Discovered
In April 2026, a critical authentication bypass vulnerability, identified as CVE-2026-41940, was discovered in cPanel and WebHost Manager (WHM) software. This flaw allowed unauthenticated remote attackers to gain administrative access to affected systems by exploiting a weakness in the login flow. The vulnerability impacted all supported versions of cPanel and WHM prior to the patched releases. cPanel promptly released security updates to address the issue, urging administrators to apply the patches immediately to prevent unauthorized access. ([support.cpanel.net](https://support.cpanel.net/hc/en-us/articles/40073787579671-Critical-Vulnerability-with-cPanel-WHM-Login-Authentication?utm_source=openai)) The incident underscores the importance of timely software updates and vigilant monitoring of web hosting environments. With the widespread use of cPanel and WHM in managing web servers, such vulnerabilities pose significant risks to data integrity and system security. Organizations are reminded to maintain up-to-date systems and implement robust security practices to mitigate potential threats.
2 months ago
Kill Chain
BlueNoroff's AI-Driven Fake Zoom Attacks on Crypto Executives
In April 2026, the North Korean state-sponsored hacking group BlueNoroff launched a sophisticated campaign targeting cryptocurrency executives. The attackers impersonated trusted contacts to schedule fake Zoom meetings, utilizing AI-generated avatars and stolen video footage to create convincing virtual environments. During these meetings, victims were prompted to install malicious software under the guise of resolving technical issues, leading to the installation of malware designed for credential theft, persistent access, and cryptocurrency wallet exfiltration. This campaign underscores the evolving threat landscape where attackers leverage advanced social engineering techniques and AI to enhance the credibility of their schemes. Organizations, especially in the cryptocurrency sector, must remain vigilant against such deceptive tactics and implement robust security measures to protect against these sophisticated attacks.
2 months ago
Kill Chain
Critical cPanel Authentication Vulnerability: Immediate Action Required
In April 2026, cPanel identified a critical authentication vulnerability affecting all supported versions of its software, potentially allowing unauthorized access to control panel interfaces. The issue was addressed with patches released on April 28, 2026, for versions 11.110.0.97, 11.118.0.63, 11.126.0.54, 11.132.0.29, 11.136.0.5, and 11.134.0.20. Organizations were urged to update their systems promptly to mitigate the risk of exploitation. ([thehackernews.com](https://thehackernews.com/2026/04/critical-cpanel-authentication.html?utm_source=openai)) This incident underscores the importance of timely patch management and proactive security measures, as attackers were reportedly exploiting the vulnerability before the patch was available. ([cyberkendra.com](https://www.cyberkendra.com/2026/04/cpanel-authentication-bypass-was.html?utm_source=openai))
2 months ago
Kill Chain
Vercel's 2026 Security Breach: A Wake-Up Call for Third-Party Integration Risks
In April 2026, Vercel, a cloud development platform known for supporting frameworks like Next.js, experienced a security breach originating from a compromised third-party AI tool, Context.ai. An attacker exploited this tool to access a Vercel employee's Google Workspace account, subsequently infiltrating Vercel's internal systems. This led to unauthorized access to non-sensitive environment variables, posing potential risks to customer data. The breach underscores the vulnerabilities associated with interconnected systems and the importance of stringent access controls. ([vercel.com](https://vercel.com/kb/bulletin/vercel-april-2026-security-incident/?utm_source=openai)) This incident highlights the growing threat landscape where attackers leverage third-party integrations to gain unauthorized access to enterprise systems. Organizations must reassess their security postures, especially concerning third-party tools, to mitigate such risks effectively.
3 months ago
Kill Chain
Stop Active Cloud Data Exfiltration
Aviatrix Breach Lock helps teams instantly identify what data is leaving the environment, from which workload, and where it’s going — during an active breach.
Looking for threats in a different sector?
Browse All Threat Reports