TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

CyberScoop

cPanel’s authentication bypass bug is being exploited in the wild, CISA warns

Greg Otto · 6 days ago · Read original ↗

ATT&CK techniques detected

2 predictions
T1190Exploit Public-Facing Application
93%
"cpanel ’ s authentication bypass bug is being exploited in the wild, cisa warns a severe authentication bypass vulnerability in cpanel, one of the most widely deployed web hosting control panel platforms on the internet, is being actively exploited in the wild, according to secur…"
T1190Exploit Public-Facing Application
49%
"to its known exploited vulnerabilities ( kev ) list thursday. cybersecurity firm watchtowr provided technical details in a blog posted wednesday : the flaw stems from improper handling of user input during the login process. when a user attempts to log in, cpanel writes data from…"

Summary

The agency added the flaw to the KEV list days after hosting providers confirmed active, ongoing attacks.

The post cPanel’s authentication bypass bug is being exploited in the wild, CISA warns appeared first on CyberScoop.