Saturday, 8 Aug 2026
Subscribe to AIWatcher
AIWatcher
  • Home
  • News

    Agent browsers get a lightweight rival as Cloudflare ships Kitesurf

    By
    AIWadmin

    Astra tests OpenAI’s own red line for cyber capability

    By
    AIWadmin

    AI conjures sixteen new viruses that kill resistant bacteria

    By
    AIWadmin

    Kimi K3 joins rogue agents after strolling out of its sandbox

    By
    AIWadmin

    Toronto startup Taalas joins AMD to hard-code models in chips

    By
    AIWadmin

    SK hynix commits $39B to two new fabs for the AI memory boom

    By
    AIWadmin
  • Articles

    Liquid AI’s tiny 2.6B model brings agents to phones and robots

    By
    AIWadmin

    Google Maps’ Ask assistant starts booking hotels and meals

    By
    AIWadmin

    Ex-Anthropic founders land $100M Google Cloud pact for Mirendil

    By
    AIWadmin

    Anthropic eases Fable 5’s biology blocks after researcher backlash

    By
    AIWadmin

    Tencent’s 295B-parameter Hy3 heads overseas with Apache 2.0 weights

    By
    AIWadmin

    Black Hat research turns agentic browsers into WhatsApp spam worms

    By
    AIWadmin
  • Spotlight

    Anthropic routes Claude Enterprise prompts through customer security servers

    By
    AIWadmin

    Suno watermarks AI songs and tightens downloads to curb misuse

    By
    AIWadmin

    Nine months of AI abuse ads slipped through Meta’s ad review

    By
    AIWadmin

    DeepMind’s cyclone model beats forecasters by a day, then goes open

    By
    AIWadmin

    Unitree’s Shanghai listing brings DeepSeek aboard with $21M

    By
    AIWadmin

    Meta’s new Muse Code agent plans, codes, and checks its own work

    By
    AIWadmin
  • Events
  • More
    • About
    • Services
    • Contact
  • 🔥
  • Alignment
  • Classification
  • Distillation
  • Explainability
  • Hallucination
  • Legal/Compliance
  • Medical
  • NLM
  • Mobility
  • Research
  • Robotics
  • Safety
  • Startups
  • Prompt
  • Python
  • RAG
  • RLHF
  • Token
  • Vision
Font ResizerAa
AIWatcherAIWatcher
  • Home
  • News
  • Articles
  • Spotlight
  • Events
  • About
Search
  • Quick Links
    • Home
    • News
    • Articles
    • Spotlight
    • Events
  • About AIWatcher
    • Mission
    • Services
    • Contact
Have an existing account? Sign In
Follow US
© 2022 Foxiz News Network. Ruby Design Company. All Rights Reserved.
News

cPanel Zero Day Under Active Attack Exposes Millions of Websites

AIWadmin
Last updated: May 17, 2026 9:39 am
AIWadmin
ByAIWadmin
Global AI news & information.
Follow:
Share
SHARE

Critical Authentication Bypass in cPanel Under Active Exploitation

A newly disclosed vulnerability in cPanel and WebHost Manager (WHM), tracked as CVE-2026-41940 (cve.org), is being actively exploited by hackers to take full control of web servers. The bug allows remote attackers to bypass the login screen and gain unrestricted access to the administrative panel, which manages websites, emails, databases, and core server configurations. Given that cPanel is used by tens of millions of websites globally, the threat surface is enormous. Security researchers warn that the exploit is trivial to execute and gives attackers deep server level access, making it a goldmine for data theft, malware deployment, and ransomware campaigns.

Contents
Critical Authentication Bypass in cPanel Under Active ExploitationWeb Hosts Scramble to Patch as Evidence of Prior Attacks Emerges

Web Hosts Scramble to Patch as Evidence of Prior Attacks Emerges

Major web hosting companies including Namecheap and HostGator have already blocked access to customer panels and deployed patches to prevent exploitation. However, KnownHost’s CEO revealed on Reddit that attackers may have been probing the vulnerability as early as February 23, nearly two months before public disclosure. While KnownHost found no signs of active compromise, the timeline suggests that sophisticated threat actors likely had a head start. Canada’s national cybersecurity agency has labeled exploitation “highly probable” and urged immediate patching. The pattern is all too familiar: a critical flaw in ubiquitous infrastructure, delayed response, and the predictable chorus of hosting companies racing to catch up. With hundreds of thousands of unpatched servers still exposed, this is a ticking time bomb for the web hosting ecosystem.

Source: Techcrunch

TAGGED:authentication bypasscPanelCVE-2026-41940securityweb hostingzero-day
Share This Article
Email Copy Link Print
ByAIWadmin
Follow:
Global AI news & information.
Previous Article Musk admits under oath that xAI secretly siphoned OpenAI models to build Grok
Next Article Uber’s Sneaky Plan to Turn Every Driver into an AV Data Slave
Ad imageAd image

You Might Also Like

News

Europe’s Android Shakeup: Why Google’s AI Monopoly Is Finally Under the Knife

By
AIWadmin
News

Google Turns AI Search Into a Reddit Citation Engine: Chaos or Curation?

By
AIWadmin
ArticlesNewsSpotlight

Inside Amazon’s AI Pressure Cooker: Employees Resort to ‘Tokenmaxxing’ to Meet Usage Metrics

By
AIWadmin
News

CopilotKit’s $27M Bet: Killing the Chatbot, One Interactive UI at a Time

By
AIWadmin
AIWatcher
Facebook Twitter Youtube Linkedin Rss

Global AI News and Information
AIWatcher is your definitive source for AI updates worldwide, from Silicon Valley to Shanghai.
Our industry coverage keeps you in the loop with the latest news and trends shaping the future of AI.

Quick Links
  • News
  • Articles
  • Spotlight
  • Events
About Us
  • Mission
  • Services
  • Contact
  • Privacy Policy
  • Legal
© 2026 AIWatcher. All Rights Reserved.