TTPwire Vol. 1 · MITRE ATT&CK·Tagged

← All stories

The Register

Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-day

Connor Jones · 6 days ago · Read original ↗

ATT&CK techniques detected

2 predictions
T1190Exploit Public-Facing Application
92%
"bug of the year ( so far ) : nasty cpanel vulnerability probably exploited as a 0 - day bug of the year ( so far ) : nasty cpanel vulnerability probably exploited as a 0 - day emergency patches out now for those managing the millions of domains assumed to be affected emergency pa…"
T1190Exploit Public-Facing Application
51%
", email configurations, and domains, while whm is used for servers. they are both backbones of the internet. breaking into them would provide an attacker with unfettered access to all the secrets associated with these functions. or, as watchtowr put it : " think of it as the keys…"

Summary

Emergency patches out now for those managing the millions of domains assumed to be affected

Emergency patches are available for a critical vulnerability in cPanel and WHM that allows attackers to bypass authentication and gain root access to servers managed using it.…