Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
6 / 6 results
highbug_reportVulnerabilitycPanel SQL privilege escalation lets hosting customers run commands as root
cPanel & WHM all supported versions prior to 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32, and WP Squared prior to 138.1.6. Requires authenticated cPanel account with MySQL/MariaDB feature access.
highperson_alertThreat ActorGitHub Actions Abused to Scan and Exploit cPanel/WHM Servers
The threat actor behind this campaign remains unattributed. The operation demonstrates sophisticated understanding of GitHub Actions infrastructure and supply chain attack vectors.
criticalbug_reportVulnerabilityCISA orders patch for exploited LiteSpeed cPanel plugin flaw (3-day deadline)
LiteSpeed cPanel user-end plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. U.S. federal agencies explicitly targeted by CISA directive.
highbug_reportVulnerabilityCISA adds LiteSpeed cPanel Plugin privilege escalation to KEV catalog
LiteSpeed cPanel Plugin (specific versions not disclosed). Affects web hosting environments using cPanel with LiteSpeed integration. Federal agencies and hosting providers running this plugin are in scope.
criticalbug_reportVulnerabilityCISA orders federal agencies to patch LiteSpeed cPanel plugin in 4 days
LiteSpeed cPanel user-end plugin. Specific vulnerable versions not disclosed. Affects organizations using cPanel with LiteSpeed integration.
criticalbug_reportVulnerabilityLiteSpeed cPanel/WHM plugin under active exploit (CVE-2026-48172)
LiteSpeed plugin for cPanel/WHM. Specific vulnerable versions not disclosed in provided data. Affects web hosting environments using LiteSpeed with cPanel/WHM integration.