Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
cPanel

cPanel Vendor Cyber Rating & Cyber Score

cpanel.net

cPanel is the leading control panel for website and server management, trusted by hosting providers, system administrators, and web professionals worldwide. For more than two decades, cPanel has given customers a reliable way to configure, monitor, and secure hosting environments through an intuitive dashboard and a rich ecosystem of integrations. The platform supports tens of millions of websites globally and continues to expand with automation, security, and AI-driven capabilities that help customers and partners reduce operational overhead and scale their businesses. cPanel is part of the WebPros family. Learn more at cpanel.net.


cPanel A.I CyberSecurity Scoring

cPanel
Company Information
Website:http://cpanel.net
Employees number:182
Number of followers:15,111
NAICS:5112
Industry Type:Software Development
Homepage:cpanel.net
cPanel Risk Score (AI oriented)
Between 550 and 599
logo
cPanelSoftware Development
Updated:
23/09/2026
589/1000
Very Poor
Ca
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
✖ Insurance prefers TPRM score to calculate premium
cPanel Global Score (TPRM)
xxxx
logo
cPanelSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

cPanelVery Poor
Current Score
589Ca (VERY POOR)
01000
10 incidents
-20.3 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
OCTOBER 2026
590Before Incident
SEPTEMBER 2026
594Before Incident
Vulnerability
22 Sep 2026 • cPanel
cPanel: New Cpanel Vulnerability Allows Attackers to Access Other Users’ Accounts

cPanel Patches Critical Vulnerabilities Threatening Shared-Hosting Security

589After Incident
CRITICAL-5
CPA1790180943
cPanel Patches Critical Vulnerabilities Threatening Shared-Hosting Security On September 22, 2026, cPanel released a security update addressing three critical vulnerabilities that compromise tenant isolation on shared-hosting servers. The most notable flaw, CVE-2026-68490, involves incorrect permissions in cPanel’s CalDAV and CardDAV functionality, allowing local users to access other accounts’ calendars and contacts. While exploitation is limited to read-only access, exposed data such as names, emails, and meeting schedules could fuel phishing or social-engineering attacks. The vulnerability affects cPanel and WHM versions 120 and later, with fixes available in builds 11.134.0.57, 11.136.0.41, 11.138.0.8, and WP Squared 11.138.1.11 or newer. The same update resolves CVE-2026-87899, a severe privilege-escalation bug in CalDAV and CardDAV that enables authenticated users to execute code as root, potentially seizing full server control. Additionally, CVE-2026-87900 impacts WP Toolkit, where a logged-in user could modify databases belonging to other accounts, posing a cross-tenant integrity risk. WP Toolkit versions 6.11.2-10794 and earlier are vulnerable; administrators must upgrade to 6.11.3 or later. cPanel recommends immediate updates via WHM or the command line, followed by verification of installed versions and monitoring for unauthorized cross-user access. The disclosures follow a string of recent cPanel ecosystem flaws, including CVE-2026-65638 (unauthenticated command injection), CVE-2026-67401 (SQL injection leading to root code execution), and CVE-2026-65643 (domain-parking exploit). A separate LiteSpeed Enterprise vulnerability (fixed in version 6.3.7) also allowed low-privileged users to bypass tenant isolation and gain root access. Hosting providers are urged to prioritize patching, as a single compromised account could expose neighboring tenants or the entire server.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: Names, emails, meeting schedules, calendars, contacts, databasesSystems Affected: Shared-hosting servers running cPanel and WHM versions 120 and later, WP Toolkit versions 6.11.2-10794 and earlierOperational Impact: Potential full server control, cross-tenant integrity risk, unauthorized access to other accounts' dataBrand Reputation Impact: Potential reputational damage due to tenant isolation failuresIdentity Theft Risk: Phishing or social-engineering attacks due to exposed PII
DATA BREACH
Type Of Data Compromised: Calendars, contacts, databases, personally identifiable information (PII)Sensitivity Of Data: High (PII, meeting schedules, emails)Personally Identifiable Information: Names, emails, meeting schedules
SEPTEMBER 2026
598Before Incident
Vulnerability
16 Sep 2026 • cPanel
Acronis, cPanel & WHM and Plesk: Acronis Plugin Vulnerability in cPanel and Plesk Exploited in the Wild

Acronis Patches High-Severity Privilege Escalation Flaw in cPanel & Plesk Backup Tools

593After Incident
CRITICAL-5
PLEACRCPA1789547109
Acronis Patches High-Severity Privilege Escalation Flaw in cPanel & Plesk Backup Tools Acronis has released security updates to address a high-severity local privilege-escalation vulnerability (CVE-2026-87886) in its Backup plugin for cPanel & WHM and Backup extension for Plesk. The flaw, rated 7.8 on the CVSS scale, stems from insecure file permissions in Linux-based Acronis backup components, classified as CWE-276 (incorrect default permissions). Exploitation requires local access with low-level privileges but no user interaction. Successful attacks could allow threat actors to escalate privileges, compromising system confidentiality, integrity, and availability. Attackers with initial access via compromised accounts, weak credentials, or vulnerable web applications could leverage the flaw to access backup data, system files, or other customer accounts on shared hosting infrastructure. Acronis confirmed limited, targeted exploitation in the wild but warned that public disclosure and patch availability may increase attack risks. The vulnerability was patched in: - Acronis Backup plugin for cPanel & WHM (version 1.9.3 HF3) - Acronis Backup extension for Plesk (version 1.8.11) Managed service providers and hosting companies are urged to prioritize updates, as cPanel and Plesk servers often host multiple customer workloads. Security teams should monitor for unauthorized local access, unexpected privilege changes, and suspicious activity in Acronis-related files or directories. For organizations unable to patch immediately, Acronis recommends restricting local access, limiting shell permissions, and isolating backup infrastructure from standard hosting environments. The vendor’s advisory confirms the fix addresses one high-severity flaw, with exploitation already detected.
INCIDENT DETAILS -
TYPE
Privilege Escalation
IMPACT
Data Compromised: Backup data, system files, customer accounts on shared hosting infrastructureSystems Affected: Acronis Backup plugin for cPanel & WHM, Acronis Backup extension for PleskOperational Impact: Compromised system confidentiality, integrity, and availability
DATA BREACH
Type Of Data Compromised: Backup data, system files, customer account dataSensitivity Of Data: High (backup data, system files, customer accounts)
SEPTEMBER 2026
602Before Incident
Vulnerability
08 Sep 2026 • cPanel
cPanel: New cPanel Vulnerability Allows Attacker to Gain Full Control of the Server

Critical SQL Injection Flaw in cPanel’s EmailTrack Grants Root Access (CVE-2026-67401)

597After Incident
CRITICAL-5
CPA1788949718
Critical SQL Injection Flaw in cPanel’s EmailTrack Grants Root Access (CVE-2026-67401) On September 8, 2026, cPanel disclosed CVE-2026-67401, a critical SQL injection vulnerability in its EmailTrack feature, which could allow authenticated attackers to gain root-level control of vulnerable servers. The flaw affects all supported cPanel/WHM versions prior to patched releases, including 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, and 11.138.1.9. Exploitation requires a valid cPanel account with mail-related privileges, limiting the attack surface to authenticated users rather than unauthenticated internet-wide threats. However, the impact remains severe, particularly for shared-hosting providers, managed servers, and multi-tenant environments, where a single compromised account could endanger other customers on the same server. The vulnerability stems from an SQL injection flaw in EmailTrack, a tool that monitors email delivery activity. Attackers can abuse this weakness to create arbitrary files on the server, enabling them to place malicious content in sensitive locations. Successful exploitation grants root access, providing full control over the system including hosted websites, databases, email accounts, backups, configuration files, and stored credentials. With root privileges, attackers could: - Deploy malware or persistence mechanisms - Alter website content or steal customer data - Disable security tools - Use the compromised server as a launchpad for further attacks Security researcher Ali Mustafa (nd abe1526) reported the flaw. cPanel has released patches for affected versions, and administrators are urged to upgrade immediately. While restricting public access is insufficient (since exploitation requires authenticated access), security teams should also: - Review cPanel accounts with email-related permissions and remove unnecessary privileges - Enforce multi-factor authentication (MFA) for exposed accounts - Monitor for suspicious files, unexpected changes, or unusual root-level processes - Analyze logs for signs of exploitation attempts The vulnerability underscores the risks of privilege escalation in multi-user hosting environments, where a single compromised account can lead to a full server takeover.
INCIDENT DETAILS -
TYPE
SQL Injection
IMPACT
Data Compromised: Hosted websites, databases, email accounts, backups, configuration files, stored credentialsSystems Affected: cPanel/WHM servers (versions prior to 11.110.0.143, 11.134.0.55, 11.136.0.39, 11.138.0.4, 11.138.1.9)Operational Impact: Full system compromise, potential malware deployment, security tool disablement, further attack launchpadIdentity Theft Risk: High (due to access to stored credentials and customer data)
DATA BREACH
Hosted websitesDatabasesEmail accountsBackupsConfiguration filesStored credentialsSensitivity Of Data: High (personally identifiable information, credentials, customer data)Personally Identifiable Information: Yes
AUGUST 2026
606Before Incident
Vulnerability
27 Aug 2026 • cPanel
cPanel: Critical cPanel Vulnerability Allows Attackers to Take Full Server Control

Critical cPanel Vulnerability (CVE-2026-65643) Grants Root Access via Low-Privilege Accounts

601After Incident
CRITICAL-5
CPA1787891604
Critical cPanel Vulnerability (CVE-2026-65643) Grants Root Access via Low-Privilege Accounts A severe vulnerability in cPanel and WHM, the widely used web hosting control panel software, has been disclosed, allowing authenticated users with low privileges to gain root-level control of entire servers. Tracked as CVE-2026-65643, the flaw was detailed in an advisory published on August 27, 2026, by cPanel support engineer Devon Courtney. The vulnerability resides in cPanel’s domain parking functionality, a common feature enabling users to point additional domains to an existing website. Exploitation requires only a legitimate cPanel account with permission to add parked or addon domains, making it accessible to attackers via cheap shared hosting plans or compromised accounts. The flaw allows arbitrary file creation anywhere on the server, leading to remote code execution (RCE) as root effectively granting full control over the system. On shared hosting environments, this poses a catastrophic risk: a single compromised account could expose all websites, databases, and email accounts on the same server. Hosting providers face the threat of mass defacement, data theft, malware deployment, or lateral movement across their infrastructure. The vulnerability affects all supported cPanel and WHM versions, with patches released for: - 11.110.0.141 or later - 11.134.0.53 or later - 11.136.0.37 or later - 11.138.0.2 or later - WP2 build 11.138.1.7 or later Servers running end-of-life (EOL) versions remain unpatched unless upgraded to a supported release. While cPanel typically deploys automatic updates, administrators with manual policies must verify their build numbers and apply fixes immediately. Hosting providers are also advised to review and restrict domain-parking permissions on unpatched servers to mitigate risk. Given cPanel’s dominance in shared and reseller hosting, rapid exploitation attempts are expected, making urgent patching the primary defense.
INCIDENT DETAILS -
TYPE
Vulnerability Exploitation
IMPACT
Data Compromised: All websites, databases, and email accounts on the same serverSystems Affected: cPanel and WHM serversOperational Impact: Mass defacement, data theft, malware deployment, lateral movement across infrastructure
DATA BREACH
WebsitesDatabasesEmail accountsSensitivity Of Data: High (potential for personally identifiable information, payment data, etc.)
AUGUST 2026
608Before Incident
Vulnerability
04 Aug 2026 • cPanel
cPanel and WebPros: Critical cPanel Vulnerability Allows Execution of SQL Commands as Root User

Critical Privilege-Escalation Flaw in cPanel & WHM Exposes Servers to Root-Level Compromise

603After Incident
CRITICAL-5
WEBCPA1785839895
Critical Privilege-Escalation Flaw in cPanel & WHM Exposes Servers to Root-Level Compromise A severe vulnerability in cPanel & WHM (CVE-2026-58048) has been disclosed, allowing authenticated users to execute arbitrary SQL commands with full database administrative privileges. The flaw, which affects the platform’s database management functionality, could lead to root-level server compromise in certain configurations, particularly in shared hosting environments. ### Key Details - Who: The vulnerability impacts all supported versions of cPanel & WHM prior to patched releases. - What: An authenticated attacker with access to the MySQL or MariaDB feature can escalate privileges, bypassing assigned permissions to execute administrative SQL commands. - Impact: Successful exploitation could enable attackers to: - Access or exfiltrate sensitive customer databases. - Modify database users and permissions. - Extract credentials or deploy malicious triggers. - Gain filesystem access, potentially leading to full server compromise. - Where: The risk is highest in shared hosting environments, where multiple users share the same server. - When: The flaw was disclosed by WebPros, with credit to security researcher Vincent55 Yang. No technical exploitation details have been publicly released. ### Mitigation & Patching cPanel has released patched versions to address the issue: - 11.110.0.137 - 11.118.0.71 - 11.126.0.78 - 11.134.0.48 - 11.136.0.32 - 138.1.6 (for WP2 deployments) For administrators unable to patch immediately, a temporary mitigation involves revoking the MySQL feature from affected cPanel users via feature list management. Security teams are advised to review database audit logs for suspicious activity, such as unauthorized privilege assignments or unusual file-related operations. Hosting providers should prioritize patching, as the severity of the flaw makes rapid remediation critical.
INCIDENT DETAILS -
TYPE
Privilege Escalation
IMPACT
Data Compromised: Sensitive customer databases, credentials, payment information riskSystems Affected: cPanel & WHM servers (shared hosting environments)Operational Impact: Potential full server compromise, unauthorized database modificationsIdentity Theft Risk: YesPayment Information Risk: Yes
DATA BREACH
Customer databasesCredentialsSensitivity Of Data: HighData Exfiltration: PotentialPersonally Identifiable Information: Potential
JULY 2026
626Before Incident
Cyber Attack
12 Jul 2026 • cPanel
Packagist, WHM, cPanel and GitHub: Hackers Abuse GitHub Actions to Exploit cPanel and WHM Servers and Steal Cloud Credentials

Large-Scale Cyber Campaign Hijacks GitHub Actions to Target Web Hosting Servers

606After Incident
CRITICAL-20
WHMPACGITCPA1784816835
Large-Scale Cyber Campaign Hijacks GitHub Actions to Target Web Hosting Servers A sophisticated cyber campaign is exploiting GitHub Actions to weaponize trusted open-source projects, turning them into tools for scanning and compromising web hosting servers. The attack, uncovered by analysts at Socket.dev, abuses free GitHub compute resources to target cPanel and WHM servers critical infrastructure for managing websites, email accounts, and databases. Between July 12 and 13, 2026, attackers compromised a legitimate PHP developer’s Packagist account, injecting malicious GitHub Actions workflow files into ten development versions of their packages. These workflows, containing 55–62 malicious files each, launch temporary Ubuntu runners that download Linux payloads and scan the internet for vulnerable hosts. The campaign extends beyond the initial compromise, with thousands of matching workflow files discovered across unrelated repositories, indicating a broad effort to hijack automation pipelines. The attack chain begins when a compromised repository triggers a workflow, spinning up an ephemeral GitHub runner. The runner fetches a processor-specific payload from a threat actor-controlled server (43.228.157.68) and exploits CVE-2026-41940, an authentication bypass flaw in cPanel and WHM. Successful breaches expose cloud credentials, payment data, and source control tokens including AWS keys, GitHub/GitLab tokens, OpenAI/Google API keys, Stripe credentials, and SSH material. The malware exfiltrates stolen data in small chunks via HTTP POST requests, with heartbeats sent every 30 seconds. While installing the affected PHP packages does not directly execute the malware, root-level GitHub Actions in compromised repositories serve as the attack engine. A single WHM compromise can jeopardize multiple customer accounts, databases, and application secrets. The campaign remains active despite the suspension of one GitHub account, underscoring its persistence. Indicators of compromise include the C2 server IP (43.228.157.68), payload delivery URLs, and the compromised maintainer account (dinushchathurya). Affected Packagist packages span multiple repositories, all tied to the same developer. Defensive measures include disabling suspicious workflows, rotating credentials, and patching cPanel/WHM systems. The incident highlights the risks of untrusted automation in CI/CD pipelines, echoing past supply chain attacks where stolen credentials enabled further breaches.
INCIDENT DETAILS -
TYPE
Supply Chain Attack
MOTIVATION
Data exfiltration, credential theft, financial gain
IMPACT
Data Compromised: Cloud credentials, payment data, source control tokens (AWS keys, GitHub/GitLab tokens, OpenAI/Google API keys, Stripe credentials, SSH material)Systems Affected: cPanel and WHM servers, web hosting infrastructureOperational Impact: Compromise of multiple customer accounts, databases, and application secretsIdentity Theft Risk: High (exposure of personally identifiable information and credentials)Payment Information Risk: High (Stripe credentials and payment data compromised)
DATA BREACH
Type Of Data Compromised: Credentials, payment data, API keys, SSH materialSensitivity Of Data: High (personally identifiable information, financial data, authentication tokens)Data Exfiltration: Yes (via HTTP POST requests in small chunks)Personally Identifiable Information: Yes (cloud credentials, source control tokens, payment information)
JUNE 2026
625Before Incident
MAY 2026
619Before Incident
APRIL 2026
624Before Incident
Vulnerability
29 Apr 2026 • cPanel
cPanel and Namecheap: Critical cPanel Authentication Vulnerability Identified — Update Your Server Immediately

cPanel Critical Authentication Vulnerability Affecting Control Panel Access

619After Incident
LOW-5
NAMCPA1777466222
cPanel Patches Critical Authentication Vulnerability Affecting Control Panel Access cPanel has released urgent security updates to fix a critical vulnerability in its control panel software that could allow attackers to gain unauthorized access through authentication flaws. The issue impacts all currently supported versions, with patches now available in the following releases: - 11.110.0.97 - 11.118.0.63 - 11.126.0.54 - 11.132.0.29 - 11.136.0.5 - 11.134.0.20 cPanel warned that unsupported versions may also be vulnerable, urging users to update immediately. While the company did not disclose technical details, web hosting provider Namecheap revealed the flaw involves an authentication exploit targeting login mechanisms. As a precaution, Namecheap temporarily blocked access to TCP ports 2083 and 2087, disrupting customer access to cPanel and WHM interfaces until the patch was deployed. The company confirmed that fixes were applied to Reseller and Stellar Business servers by April 29, 2026, at 02:42 a.m. UTC, with remaining systems updated shortly after. No active exploitation has been reported.
INCIDENT DETAILS -
TYPE
Authentication Vulnerability
IMPACT
Systems Affected: cPanel and WHM interfacesDowntime: Temporary disruption due to port blockingOperational Impact: Temporary loss of access to cPanel and WHM interfaces
APRIL 2026
639Before Incident
Vulnerability
28 Apr 2026 • cPanel
GitHub, cPanel, ADT and Robinhood: Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months

Cybersecurity Roundup: Key Incidents and Developments from April 2026

619After Incident
CRITICAL-20
GITCPAADTROB1777796722
Cybersecurity Roundup: Key Incidents and Developments from April 2026 Last week saw a surge in cybersecurity threats, regulatory actions, and technological advancements highlighting both emerging risks and evolving defenses. Here’s a breakdown of the most critical developments: ### AI and Automation: New Frontiers for Cybercrime and Defense - AI-Powered Cybercrime: Threat actors are leveraging gig platforms like RentAHuman to hire AI agents for tasks such as physical surveillance, item delivery, and in-person meetings, blurring the line between digital and real-world attacks. - AI Supply Chain Risks: Cisco released an open-source toolkit to verify AI model lineage, addressing concerns that enterprises lack visibility into modifications made to downloaded models from repositories like Hugging Face. - AI-Driven Attacks: OpenAI warned that attackers are scaling operations using AI, while Anthropic adopted a more restrictive approach to advanced AI access. Meanwhile, automated LLM red teaming tools are evolving, with Capital One proposing Adaptive Instruction Composition to prioritize high-impact attack vectors. - AI Traffic Surge: AI workflows are generating larger, less predictable data flows, with Backblaze reporting a shift toward high-bandwidth traffic between fewer endpoints. ### Data Breaches and Privacy Violations - Massive Fines: U.S. state privacy regulators imposed $3.425 billion in fines in 2025 nearly double the 2024 total reflecting stricter enforcement trends. - High-Profile Breaches: - ADT confirmed a breach on April 20, exposing customer data after hackers accessed its systems. - Udemy suffered a breach claimed by ShinyHunters, leaking 1.4 million records with sensitive user details. - UK Biobank: Medical data from 500,000 British volunteers was listed for sale on Alibaba, raising concerns about genetic and clinical data misuse. - Academic Data Leaks: A study of 2.7 million arXiv submissions found that 88% of LaTeX source files contained unintended public disclosures, including drafts, comments, and project data. ### Critical Vulnerabilities and Exploits - Windows Zero-Day (CVE-2026-32202): Actively exploited in the wild, this Windows Shell spoofing flaw allows attackers to force authentication to malicious servers. It stems from an incomplete patch for a prior vulnerability (CVE-2026-21510) linked to APT28 (Fancy Bear). - Linux Kernel Flaw (CVE-2026-31431): A nine-year-old privilege escalation bug ("Copy Fail") affects nearly all major Linux distributions since 2017, with a public proof-of-concept exploit available. - GitHub Enterprise Server RCE (CVE-2026-3854): While patched on GitHub.com, 88% of self-hosted instances remain vulnerable to remote code execution. - cPanel Zero-Day (CVE-2026-41940): Exploited since February 2026, this authentication bypass flaw in the web hosting control panel highlights delayed patching risks. - Vect Ransomware Bug: A flaw in the Vect ransomware-as-a-service (RaaS) effectively turns it into a data wiper, with affiliates encrypting files irreversibly. ### Threat Actor Activity - UNC6692: A new threat group impersonated IT helpdesk staff via Microsoft Teams, tricking employees into downloading malware disguised as a "Mailbox Repair Utility" in a campaign active since December 2025. - Robinhood Phishing: Cybercriminals hijacked Robinhood’s email systems to send phishing emails to users, with reports surfacing on April 26. - Black Axe Arrests: Swiss police arrested 10 suspected members of the Black Axe cybercrime gang, including its Southern Europe "Regional Head," in a coordinated raid on April 28. - Roblox Account Theft: Ukrainian police detained three suspects accused of stealing and reselling 600,000 Roblox accounts via malware disguised as game tools. - SMS Blaster Operation: Canadian authorities arrested three men for operating a mobile cell tower spoofing device, used to send fraudulent SMS messages across the Greater Toronto Area. ### Regulatory and Law Enforcement Actions - Chinese Hacker Extradited: Xu Zewei, a Chinese national, was extradited from Italy to the U.S. for allegedly breaching thousands of systems, including those tied to COVID-19 research. - Albanian Call Center Bust: A joint operation dismantled a €50 million fraud ring operating from Albania, with 10 arrests and €900,000 seized. ### Tooling and Infrastructure Updates - IPFire DNS Firewall: The open-source firewall now includes built-in domain blocking, replacing third-party tools like Pi-hole for malware and phishing protection. - Open-Source Privacy Tools: - BleachBit 6.0.0 enhanced secure deletion and browser cleaning for Windows/Linux. - Kiji Privacy Proxy (by Dataiku) masks PII before prompts reach external AI services. - SimpleX Chat released a user-identifier-free encrypted messenger. - Linux Storage: Stratis 3.9.0 added online encryption and cache-less pool startup for improved security. - Proxmox Backup Server 4.2 introduced S3 storage support and parallel sync jobs. ### SOC and Identity Challenges - SOC Metrics Under Scrutiny: The UK’s NCSC warned that ticket-based metrics (e.g., IT service desk KPIs) can undermine security operations by failing to measure real attack detection. - AI and IAM Gaps: Identity and access management (IAM) systems, designed for human users, struggle with AI agents that bypass traditional authentication. The FIDO Alliance is exploring new frameworks for AI-driven payments. - Shadow AI Risks: 31% of employees using AI tools receive no employer training, widening the gap between adoption and governance. ### Industrial and Infrastructure Threats - ICS Blind Spots: Researchers identified three critical gaps in industrial control system (ICS) intrusion detection, complicating plant security. - GPS Spoofing Detection: Oak Ridge National Laboratory developed a portable tool to expose GPS signal manipulation in transit networks. ### Open-Source and Developer Tools - Visual Studio Updates: GitHub Copilot now integrates cloud agents for scalable task execution, while VS Code 1.118 added auto-model selection for Copilot CLI. - Warp Terminal: The AI-centric terminal open-sourced its client under the AGPL license, with OpenAI as a founding sponsor. - LuLu Firewall: A free macOS tool now monitors outbound connections to block unauthorized data exfiltration. ### Emerging Trends - Bad Bots: AI agents now account for 40% of internet traffic, alongside traditional "good" and "bad" bots, per Thales’ 2026 report. - AI Prompt Confidentiality: Researchers raised concerns about unpublished research and proprietary data being leaked via commercial AI tools like Research Rabbit and Elicit AI. - Met Police AI Scrutiny: London’s Metropolitan Police faced backlash for using Palantir’s AI to monitor officers’ movements for misconduct investigations. This wave of incidents underscores the accelerating convergence of AI, automation, and cyber threats while also highlighting the urgent need for adaptive defenses, stricter data governance, and proactive vulnerability management.
INCIDENT DETAILS -
TYPE
Data BreachRansomwarePhishingZero-Day ExploitAI-Powered AttackGPS SpoofingSMS BlasterAccount Theft
MOTIVATION
Financial GainData TheftEspionageCybercrimeFraudAI-Powered Scaling
IMPACT
Financial Loss: €50 million (Albanian Call Center Bust) + $3.425 billion in fines (2025 US privacy violations)1.4 million Udemy records500,000 UK Biobank medical records600,000 Roblox accountsADT customer data88% of 2.7 million arXiv submissions (unintended disclosures)Windows Systems (CVE-2026-32202)Linux Distributions (CVE-2026-31431)GitHub Enterprise Servers (CVE-2026-3854)cPanel Hosting Panels (CVE-2026-41940)Industrial Control Systems (ICS)Mobile Networks (GPS Spoofing)AI workflow disruptionsIdentity and Access Management (IAM) failuresSOC inefficiencies due to ticket-based metricsData exfiltration risksADTUdemyUK BiobankRobinhood$3.425 billion in fines (2025 US privacy violations)Regulatory violations (GDPR, state privacy laws)Roblox accountsUdemy user detailsADT customer data
DATA BREACH
Customer DataMedical DataUser AccountsResearch DataPersonally Identifiable Information (PII)Genetic DataClinical Data1.4 million (Udemy)500,000 (UK Biobank)600,000 (Roblox)2.7 million (arXiv)High (Medical/Genetic Data)Medium (PII, User Accounts)Low (Research Drafts)UK Biobank data listed for sale on AlibabaRoblox account theftADT customer data breachVect Ransomware (irreversible encryption)LaTeX source files (arXiv)Medical records (UK Biobank)Udemy user detailsADT customer dataRoblox account information
APRIL 2026
645Before Incident
Vulnerability
27 Apr 2026 • cPanel
cPanel and Reborn Gaming: Have I Been Pwned’s Post

Reborn Gaming Data Breach Exposing 126 Email Addresses

624After Incident
MEDIUM-21
CPAREB1777868647
Reborn Gaming Suffers Data Breach Exposing 126 Email Addresses Last week, gaming platform Reborn Gaming experienced a data breach affecting 126 unique email addresses, along with associated IP addresses and Steam IDs. The incident stemmed from a vulnerability in cPanel/WHM, a widely used web hosting control panel. According to breach notification platform Have I Been Pwned, 68% of the exposed email addresses were already linked to LinkedIn profiles, increasing the risk of targeted phishing or credential-stuffing attacks. The breach highlights ongoing security risks tied to misconfigured or unpatched hosting infrastructure, particularly in gaming and online communities where user data is frequently targeted. No further details on the timeline of the attack or remediation efforts have been disclosed. The incident serves as a reminder of the persistent threats posed by unsecured third-party services in digital ecosystems.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: 126 unique email addresses, IP addresses, Steam IDsSystems Affected: cPanel/WHM hosting infrastructureIdentity Theft Risk: Increased risk of targeted phishing or credential-stuffing attacks
DATA BREACH
Email addressesIP addressesSteam IDsNumber Of Records Exposed: 126Sensitivity Of Data: Personally identifiable information (email addresses, IP addresses, Steam IDs)Personally Identifiable Information: Email addresses, IP addresses, Steam IDs
MARCH 2026
643Before Incident
FEBRUARY 2026
753Before Incident
Ransomware
26 Feb 2026 • cPanel
cPanel: Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks

Critical cPanel Flaw Exploited in Widespread 'Sorry' Ransomware Attacks

641After Incident
CRITICAL-112
CPA1777760619
Critical cPanel Flaw Exploited in Widespread "Sorry" Ransomware Attacks A critical authentication bypass vulnerability in cPanel and WHM (CVE-2026-41940) is being actively exploited to deploy the "Sorry" ransomware, targeting Linux-based web hosting servers. The flaw, patched in an emergency update this week, allows attackers to gain unauthorized access to control panels managing websites, databases, and webmail. Exploitation attempts date back to late February, with attacks escalating rapidly after the vulnerability was disclosed. Security firm Shadowserver reports that at least 44,000 IP addresses running cPanel have been compromised. Threat actors began mass-exploiting the flaw on Thursday, deploying a Go-based Linux encryptor that appends the ".sorry" extension to encrypted files. The ransomware uses ChaCha20 encryption, with keys secured via an embedded RSA-2048 public key, making decryption impossible without the attacker’s private key. Victims receive a ransom note (README.md) directing them to contact the threat actor via Tox (ID: 3D7889AEC00F2325E1A3FBC0ACA4E521670497F11E47FDE13EADE8FED3144B5EB56D6B198724). Hundreds of compromised sites have already been indexed by Google, indicating widespread impact. This campaign is unrelated to a 2018 ransomware operation that also used the ".sorry" extension. Security experts warn that exploitation is expected to intensify in the coming days.
INCIDENT DETAILS -
TYPE
Ransomware
MOTIVATION
Financial Gain
IMPACT
Data Compromised: Files encrypted with '.sorry' extensionSystems Affected: Linux-based web hosting servers running cPanel/WHMOperational Impact: Unauthorized access to control panels managing websites, databases, and webmail
DATA BREACH
Type Of Data Compromised: Encrypted files ('.sorry' extension)Sensitivity Of Data: High (files on web hosting servers)Data Encryption: ChaCha20 with RSA-2048 public key
JANUARY 2026
753Before Incident
DECEMBER 2025
753Before Incident
NOVEMBER 2025
753Before Incident

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for cPanel ?
?
What was cPanel's A.I Rankiteo Cyber Score in September 2026 ?
?
What was cPanel's A.I Rankiteo Cyber Score in August 2026 ?
?
What was cPanel's A.I Rankiteo Cyber Score in July 2026 ?
?
What was cPanel's A.I Rankiteo Cyber Score in June 2026 ?
?
What was cPanel's A.I Rankiteo Cyber Score in May 2026 ?
?
What was cPanel's A.I Rankiteo Cyber Score in April 2026 ?
?
What was cPanel's A.I Rankiteo Cyber Score in March 2026 ?
?
What was cPanel's A.I Rankiteo Cyber Score in February 2026 ?
?
What was cPanel's A.I Rankiteo Cyber Score in January 2026 ?
?
What was cPanel's A.I Rankiteo Cyber Score in December 2025 ?
?
What was cPanel's A.I Rankiteo Cyber Score in November 2025 ?
?
What is the average per-incident point impact on cPanel's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with cPanel ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view cPanel's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
cPanel Cyber Scoring History | Rankiteo