Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Government Servers Compromised Through cPanel Vulnerability

Government Servers Compromised Through cPanel Vulnerability

Posted on May 2, 2026 By CWS

A recent cyber attack has targeted the infrastructure of government and military entities in Southeast Asia. The breach began with the rapid exploitation of a critical cPanel authentication bypass vulnerability, leading to the infiltration of sensitive data from the Chinese railway sector.

Exploiting cPanel Vulnerabilities

The attackers utilized CVE-2026-41940, a severe flaw in cPanel and WHM software, which allowed unauthorized access. This vulnerability involved a CRLF injection in the login processes, enabling attackers to manipulate session cookies and gain administrative access without credentials.

Even before a patch was released on April 28, 2026, this flaw was actively exploited, prompting CISA to add it to the Known Exploited Vulnerabilities list. The breach was part of a larger operation discovered through a compromised command-and-control (C2) server.

Advanced Exploit Techniques

The attackers further exploited a custom vulnerability targeting an Indonesian defense portal. By using valid credentials and bypassing CAPTCHA through session cookie manipulation, they accessed sensitive systems. SQL injection techniques were then employed to escalate to operating system-level access.

This was achieved by leveraging PostgreSQL’s capabilities to execute arbitrary commands. The attackers captured command outputs and reintegrated them into the system using stealthy methods, making detection difficult.

Data Exfiltration and Persistence

To maintain access, the attackers used a combination of OpenVPN and Ligolo, ensuring persistent re-entry even after system reboots. They routed through a VPN server and installed proxy agents under hidden directories, disguising them as legitimate services.

Using these methods, approximately 4.37GB of sensitive documents were exfiltrated from the China Railway Society. The stolen data included financial workbooks containing personal information and state-related data, hinting at a targeted intelligence gathering effort.

Security organizations urge those using cPanel/WHM to upgrade to the latest versions and review server logs for any signs of compromise. The attack highlights the need for robust cybersecurity measures to protect sensitive infrastructure.

Cyber Security News Tags:C2 Server, cPanel, CRLF injection, cyber attack, Cybersecurity, data breach, data exfiltration, government hacking, Ligolo, network security, OpenVPN, PowerShell, Southeast Asia, SQL injection, zero-day exploit

Post navigation

Previous Post: Trellix Faces Security Breach in Source Code Repository
Next Post: CISA Highlights Critical Linux Vulnerability Exploitation

Related Posts

Critical RCE Flaw in n8n Poses Security Threat Critical RCE Flaw in n8n Poses Security Threat Cyber Security News
ChatGPT-5 Downgrade Attack Let Hackers Bypass AI Security With Just a Few Words ChatGPT-5 Downgrade Attack Let Hackers Bypass AI Security With Just a Few Words Cyber Security News
Apache NuttX Vulnerability Let Attackers to Crash Systems Apache NuttX Vulnerability Let Attackers to Crash Systems Cyber Security News
Tropic Trooper Cyberattack Uses Novel Tools for Infiltration Tropic Trooper Cyberattack Uses Novel Tools for Infiltration Cyber Security News
Microsoft Bookings Vulnerability Let Attackers Alter the Meeting Details Microsoft Bookings Vulnerability Let Attackers Alter the Meeting Details Cyber Security News
CISA Adds Digiever Authorization Vulnerability to KEV List Following Active Exploitation CISA Adds Digiever Authorization Vulnerability to KEV List Following Active Exploitation Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OnionDrop Campaign Delivers LegionLoader via gainmsg C2
  • GitGuardian Enhances Developer Security with New Endpoint Protection
  • Hackers Exploit Microsoft Teams to Mask Ransomware Traffic
  • Arch Linux Halts AUR Signups Amid Major Supply Chain Threat
  • Google Cloud Vertex AI SDK Flaw Exposed Model Uploads

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OnionDrop Campaign Delivers LegionLoader via gainmsg C2
  • GitGuardian Enhances Developer Security with New Endpoint Protection
  • Hackers Exploit Microsoft Teams to Mask Ransomware Traffic
  • Arch Linux Halts AUR Signups Amid Major Supply Chain Threat
  • Google Cloud Vertex AI SDK Flaw Exposed Model Uploads

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark