cPanel Vulnerability Exploited in Mass Ransomware Campaign
A newly disclosed critical flaw in cPanel is being actively exploited to breach websites and deploy 'Sorry' ransomware across multiple targets.
A critical vulnerability in cPanel, tracked as CVE-2026-41940, is under active mass exploitation by threat actors deploying ransomware identified as 'Sorry.' The flaw allows attackers to breach websites hosted on affected cPanel installations and encrypt data.
The vulnerability's severity and the scale of exploitation suggest attackers are targeting web hosting environments where cPanel is widely deployed. cPanel is used by millions of websites globally, making the attack surface substantial. The 'Sorry' ransomware campaign appears coordinated, with multiple breaches reported in a compressed timeframe.
The disclosure timing indicates the flaw may have been exploited as a zero-day before public acknowledgment. Organizations running cPanel infrastructure face immediate risk if patches have not been applied. The ransomware's naming convention — 'Sorry' — follows recent trends of threat actors using ironic or apologetic branding.
- 01Web hosting providers face immediate breach risk if cPanel instances remain unpatched.
- 02Website owners on shared hosting may experience data loss or service disruption.
- 03Security teams must audit cPanel deployments and monitor for ransomware indicators.
- 04Delayed patch availability extends exposure window for mass exploitation.
Multi-Year Phishing Campaign Compromises Over 500 Organizations
A sustained phishing operation has breached more than 500 entities across aviation, energy, logistics, and critical infrastructure over several years.
JDownloader site compromised to distribute Python RAT malware
Popular download manager's official website served malicious Windows and Linux installers this week, deploying remote access trojan to unsuspecting users.
Linux zero-day grants root access across major distributions
Dirty Frag exploit enables local privilege escalation with a single command, affecting most enterprise Linux deployments currently in production.