CPanel released security patches for three newly discovered vulnerabilities following a ransomware attack that compromised approximately 44,000 servers. The incident highlighted critical gaps in the hosting platform's security infrastructure.
CPanel addressed three previously unknown vulnerabilities this week after attackers exploited them to breach a significant portion of servers running the popular web hosting control panel. The attack affected an estimated 44,000 systems, marking a major incident for the platform used by hosting providers and website administrators worldwide.
The three vulnerabilities were patched following the discovery of active exploitation. CPanel released updates addressing the flaws, though specific technical details remain limited as the company manages disclosure alongside remediation efforts.
The timing of the incident, termed "Black Week" by security observers, underscores persistent challenges in server security. Hosting providers and administrators using CPanel were advised to apply patches immediately to prevent further compromise. The attack demonstrates how vulnerabilities in widely-deployed management tools can create cascading risks across numerous organizations.
CPanel's response included coordinated notifications to affected parties and hosting providers. Security researchers on platforms like Hacker News noted the incident represents a significant supply chain risk, as compromised hosting infrastructure can impact hundreds of thousands of downstream websites and applications.
The company urged users to update to patched versions and review server logs for signs of compromise. Industry analysts recommend hosting providers prioritize CPanel updates in their maintenance schedules and implement additional monitoring for suspicious activity.
This incident adds to a growing list of vulnerabilities discovered in critical hosting infrastructure. CPanel has faced security scrutiny in recent years, making these newly patched flaws a concern for the broader hosting ecosystem.
Organizations running affected versions should treat the patches as critical and deploy them without delay. The incident also highlights the importance of network segmentation and access controls for hosting management interfaces.
A limited-permission Kubernetes user can potentially gain full control of a Google Cloud organization by exploiting the Google Kubernetes Config Connector. The vulnerability represents a classic confused deputy problem in cloud infrastructure.
Enterprise infrastructure management systems are under sustained attack, with critical vulnerabilities being exploited before or immediately after vendor patches become available, according to a new InfraTrust report.
Comma's hands-off driving technology is being investigated following at least two fatal crashes. The inquiry involves instances where drivers were operating modified versions of Comma's software.
Sweden's data privacy regulator IMY has fined IT systems provider Miljödata $183,000 for inadequate security measures that led to a data breach in August 2025. The incident exposed personal information of 2.2 million individuals.