Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Government Servers Compromised Through cPanel Vulnerability

Government Servers Compromised Through cPanel Vulnerability

Posted on May 2, 2026 By CWS

A recent cyber attack has targeted the infrastructure of government and military entities in Southeast Asia. The breach began with the rapid exploitation of a critical cPanel authentication bypass vulnerability, leading to the infiltration of sensitive data from the Chinese railway sector.

Exploiting cPanel Vulnerabilities

The attackers utilized CVE-2026-41940, a severe flaw in cPanel and WHM software, which allowed unauthorized access. This vulnerability involved a CRLF injection in the login processes, enabling attackers to manipulate session cookies and gain administrative access without credentials.

Even before a patch was released on April 28, 2026, this flaw was actively exploited, prompting CISA to add it to the Known Exploited Vulnerabilities list. The breach was part of a larger operation discovered through a compromised command-and-control (C2) server.

Advanced Exploit Techniques

The attackers further exploited a custom vulnerability targeting an Indonesian defense portal. By using valid credentials and bypassing CAPTCHA through session cookie manipulation, they accessed sensitive systems. SQL injection techniques were then employed to escalate to operating system-level access.

This was achieved by leveraging PostgreSQL’s capabilities to execute arbitrary commands. The attackers captured command outputs and reintegrated them into the system using stealthy methods, making detection difficult.

Data Exfiltration and Persistence

To maintain access, the attackers used a combination of OpenVPN and Ligolo, ensuring persistent re-entry even after system reboots. They routed through a VPN server and installed proxy agents under hidden directories, disguising them as legitimate services.

Using these methods, approximately 4.37GB of sensitive documents were exfiltrated from the China Railway Society. The stolen data included financial workbooks containing personal information and state-related data, hinting at a targeted intelligence gathering effort.

Security organizations urge those using cPanel/WHM to upgrade to the latest versions and review server logs for any signs of compromise. The attack highlights the need for robust cybersecurity measures to protect sensitive infrastructure.

Cyber Security News Tags:C2 Server, cPanel, CRLF injection, cyber attack, Cybersecurity, data breach, data exfiltration, government hacking, Ligolo, network security, OpenVPN, PowerShell, Southeast Asia, SQL injection, zero-day exploit

Post navigation

Previous Post: Trellix Faces Security Breach in Source Code Repository
Next Post: CISA Highlights Critical Linux Vulnerability Exploitation

Related Posts

Critical Ivanti Endpoint Manager Flaw Raises Security Concerns Critical Ivanti Endpoint Manager Flaw Raises Security Concerns Cyber Security News
WhatsApp Developers Under Attack From Weaponized npm Packages with Remote Kill Switch WhatsApp Developers Under Attack From Weaponized npm Packages with Remote Kill Switch Cyber Security News
GTFire Phishing Attacks Exploit Google Services for Data Theft GTFire Phishing Attacks Exploit Google Services for Data Theft Cyber Security News
6000+ Vulnerable SmarterTools SmarterMail Servers Exposed to Actively Exploited RCE Vulnerability 6000+ Vulnerable SmarterTools SmarterMail Servers Exposed to Actively Exploited RCE Vulnerability Cyber Security News
CISA Adds HP Enterprise OneView Code Injection Vulnerability to KEV Following Active Exploitation CISA Adds HP Enterprise OneView Code Injection Vulnerability to KEV Following Active Exploitation Cyber Security News
Matryoshka Malware Targets macOS with New Stealer Variant Matryoshka Malware Targets macOS with New Stealer Variant Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Zoom Software Vulnerabilities Pose Security Risks
  • Enhancing MSSP Security with Real-Time Threat Visibility
  • SAP Addresses Critical Vulnerabilities in S/4HANA
  • Ivanti Releases Security Patches for Multiple Products
  • Apple Updates macOS, iOS to Fix Numerous Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Zoom Software Vulnerabilities Pose Security Risks
  • Enhancing MSSP Security with Real-Time Threat Visibility
  • SAP Addresses Critical Vulnerabilities in S/4HANA
  • Ivanti Releases Security Patches for Multiple Products
  • Apple Updates macOS, iOS to Fix Numerous Security Flaws

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark