Namecheap, Inc A.I CyberSecurity Scoring
Namecheap, Inc
Company Information
Website:http://www.namecheap.com/
Employees number:1,641
Number of followers:64,289
NAICS:
Industry Type:Information Technology & Services
Homepage:namecheap.com
Namecheap, Inc Risk Score (AI oriented)
Between 750 and 799
Namecheap, IncInformation Technology & Services
Updated:
16/06/2026
16/06/2026
753/1000
Fair
Baa
Namecheap, Inc Global Score (TPRM)
xxxx
Namecheap, IncInformation Technology & Services
Score locked

Namecheap, IncFair
Current Score
753Baa (FAIR)
01000
3 incidents
-5 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JULY 2026
754
JUNE 2026
758
Vulnerability
31 May 2026 • Namecheap, Inc
LiteSpeed and Namecheap: LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild
Critical Zero-Day in LiteSpeed cPanel Plugin Exploited in the Wild
753
CRITICAL-5
NAMLIT1781598529
Critical Zero-Day in LiteSpeed cPanel Plugin Exploited in the Wild
A severe zero-day vulnerability (CVE-2026-54420) in the LiteSpeed cPanel user-end plugin is being actively exploited, enabling attackers to escalate privileges to root and fully compromise affected servers. The flaw, discovered by Namecheap researchers after observing suspicious activity, specifically targets shared hosting environments by breaking tenant isolation mechanisms like CloudLinux’s CageFS.
The vulnerability stems from improper API handling in the plugin, allowing attackers with limited access such as FTP credentials or a web shell to chain internal functions (generateEcCert and packageUserSize) in rapid, automated sequences. These exploitation attempts generate detectable anomalies, including bursts of 7–10 concurrent requests from a single IP, deviating from normal user behavior.
LiteSpeed released a patch on June 1, 2026, in cPanel plugin version 2.4.8 (bundled with WHM plugin 5.3.2.1), addressing the issue by tightening access controls. The vulnerability was responsibly disclosed on May 31, 2026, with the CVE assigned on June 14, 2026. While the flaw affects only the user-end plugin, its inclusion in WHM plugin installations leaves many environments exposed if unpatched.
Security experts warn of severe risks in multi-tenant setups, where a single compromised account could lead to full server takeover. Temporary mitigation involves removing the user-end plugin, but immediate patching is strongly recommended. Administrators are also advised to audit logs for signs of exploitation, such as unauthorized privilege changes or suspicious file modifications.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
MAY 2026
757
APRIL 2026
762
Vulnerability
29 Apr 2026 • Namecheap, Inc
cPanel and Namecheap: Critical cPanel Authentication Vulnerability Identified — Update Your Server Immediately
cPanel Critical Authentication Vulnerability Affecting Control Panel Access
757
LOW-5
NAMCPA1777466222
cPanel Patches Critical Authentication Vulnerability Affecting Control Panel Access
cPanel has released urgent security updates to fix a critical vulnerability in its control panel software that could allow attackers to gain unauthorized access through authentication flaws. The issue impacts all currently supported versions, with patches now available in the following releases:
- 11.110.0.97
- 11.118.0.63
- 11.126.0.54
- 11.132.0.29
- 11.136.0.5
- 11.134.0.20
cPanel warned that unsupported versions may also be vulnerable, urging users to update immediately. While the company did not disclose technical details, web hosting provider Namecheap revealed the flaw involves an authentication exploit targeting login mechanisms.
As a precaution, Namecheap temporarily blocked access to TCP ports 2083 and 2087, disrupting customer access to cPanel and WHM interfaces until the patch was deployed. The company confirmed that fixes were applied to Reseller and Stellar Business servers by April 29, 2026, at 02:42 a.m. UTC, with remaining systems updated shortly after. No active exploitation has been reported.
INCIDENT DETAILS -
TYPE
IMPACT
REFERENCES
MARCH 2026
762
FEBRUARY 2026
762
JANUARY 2026
762
DECEMBER 2025
762
NOVEMBER 2025
762
OCTOBER 2025
762
SEPTEMBER 2025
762
AUGUST 2025
762
JULY 2018
763
Cyber Attack
19 Jul 2018 • Namecheap, Inc
Namecheap, UnifiedLayer, IONOS and GoDaddy: New SystemBC Botnet Discovered Hijacking 10,000 Devices For DDoS Attacks
SystemBC Botnet Resurfaces with 10,000+ Infected IPs, Targeting Hosting Providers and Government Infrastructure
745
CRITICAL-18
UNINAMIONGOD1770273279
SystemBC Botnet Resurfaces with 10,000+ Infected IPs, Targeting Hosting Providers and Government Infrastructure
Researchers at Silent Push have uncovered a resurgent SystemBC botnet, now controlling over 10,340 unique infected IP addresses worldwide. The malware, first identified in 2019 as "Coroxy" or "DroxiDat," converts compromised systems into SOCKS5 proxies, enabling attackers to launch DDoS attacks and obscure malicious operations.
### Scope and Persistence
The botnet maintains an average of 2,888 daily active infections, with some systems remaining compromised for over 100 days. Unlike typical consumer-focused malware, SystemBC disproportionately targets hosting providers, with top affected networks including Network Solutions, UnifiedLayer, Namecheap, GoDaddy, and IONOS. This concentration in data centers ensures high-bandwidth, persistent access for cybercriminals.
### Global Distribution and High-Value Targets
The U.S. leads in infections (4,300+ IPs), followed by Germany (829), France (448), Singapore (419), and India (294). Notably, compromised IPs have been linked to government infrastructure, including:
- Vietnam’s Phutho provincial government (`duchop[.]gov[.]vn` on `103.28.36[.]105`)
- Burkina Faso domains (`196.13.207[.]92`)
Many infected systems also scanned WordPress sites for vulnerabilities, suggesting ties to broader exploitation campaigns, including ransomware deployment.
### Evasion and Command Infrastructure
SystemBC’s command-and-control (C2) servers rely on bulletproof hosting providers like `bthoster[.]com` and AS213790 (BTCloud) to resist takedowns. The malware uses RC4-encrypted custom protocols in a backconnect setup, functioning as both a backdoor and ransomware loader.
A newly discovered Perl-based Linux variant evaded detection by all 62 VirusTotal scanners, while droppers like SafeObject (SHA256: `0f5c81eaf357...`) unpack to deploy 264 payloads, with Russian-language artifacts hinting at its origins. The botnet’s developer, "psevdo," continues to post updates on the underground forum forum[.]exploit[.]in, despite Europol’s 2024 Operation Endgame targeting similar threats.
### Key Indicators of Compromise (IOCs)
- Perl variant SHA256: `c729bf6ea292116b3477da4843aaeec73370e2bd46e7a27674671e9a65fb473a`
- C2 IPs: `36.255.98[.]159` (and others)
The botnet’s resilience underscores its role in DDoS operations and stealthy cyberattacks, with hosting providers and government entities remaining prime targets.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Namecheap, Inc ??
What was Namecheap, Inc's A.I Rankiteo Cyber Score in June 2026 ??
What was Namecheap, Inc's A.I Rankiteo Cyber Score in May 2026 ??
What was Namecheap, Inc's A.I Rankiteo Cyber Score in April 2026 ??
What was Namecheap, Inc's A.I Rankiteo Cyber Score in March 2026 ??
What was Namecheap, Inc's A.I Rankiteo Cyber Score in February 2026 ??
What was Namecheap, Inc's A.I Rankiteo Cyber Score in January 2026 ??
What was Namecheap, Inc's A.I Rankiteo Cyber Score in December 2025 ??
What was Namecheap, Inc's A.I Rankiteo Cyber Score in November 2025 ??
What was Namecheap, Inc's A.I Rankiteo Cyber Score in October 2025 ??
What was Namecheap, Inc's A.I Rankiteo Cyber Score in September 2025 ??
What was Namecheap, Inc's A.I Rankiteo Cyber Score in August 2025 ??
What is the average per-incident point impact on Namecheap, Inc's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Namecheap, Inc ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Namecheap, Inc's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?