Connect with us

News

Hackers are actively exploiting a bug in cPanel, used by millions of websites

info

Published

on

Cpanel security flaw bug.jpeg

Security researchers are sounding the alarm on a newly discovered vulnerability in the widely used web server management software cPanel and WebHost Manager (WHM). 

The bug allows hackers to hijack and take full control of the servers running the affected software, which is thought to be used by tens of millions of website owners around the world.

Many commercial web hosting companies have patched their customers’ systems already. But the cPanel maker urged customers to ensure that their systems are patched as the bug affects all supported versions of the software.

cPanel and WHM are two software suites used for managing web servers that host websites, manage emails, and handle important configurations and databases needed to maintain an internet domain. The two suites have deep-access to the servers that they manage, allowing a malicious hacker potentially unrestricted access to data managed by the affected software.

The bug, officially tracked as CVE-2026-41940, allows malicious hackers to remotely bypass its login screen to gain full access to the software’s administration panel. 

Given the ubiquity of the cPanel and WHM software across the web hosting industry, hackers could compromise potentially large numbers of websites that haven’t patched the bug.

Canada’s national cybersecurity agency said in an advisory that the bug could be exploited to compromise websites on shared hosting servers, such as large web hosting companies.

The agency said that “exploitation is highly probable” and that immediate action from cPanel customers, or their web hosts, is necessary to prevent malicious access.

Web hosting giant Namecheap, which uses cPanel to allow its customers to manage their web servers, said the company blocked access to customers’ cPanel panels after learning of the flaw to prevent exploitation, and to give it time to patch its customers’ systems

Hostgator also said it patched its systems and is considering the bug a “critical authentication-bypass exploit.”

One web hosting company says it found evidence that hackers have been abusing the vulnerability for months before the attempts were discovered.

KnownHost CEO Daniel Pearson said in a post on Reddit that his company has seen attempts to exploit the vulnerability as far back as February 23. The company said it also briefly began blocking access to customer systems before applying patches.

According to Pearson, around 30 servers at KnownHost showed signs of unauthorized attempted access out of thousands of computers on its network. Pearson likened the efforts to attempts, and has not seen signs of active compromise. cPanel also said it rolled out a security fix for WP Squared, a similar tool for managing WordPress websites.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

News

Super Eagles Impressive in Narrow Defeat by World Cup-bound Portugal in Leiria

info

Published

on

By

IMG 20260610 WA0370.jpg

The Super Eagles showed great form, confidence and praiseworthy fighting spirit despite losing 1-2 to FIFA World Cup-bound Portugal in an explosive friendly match in Leiria on Wednesday night.

Just before kick-off, Chairman of the National Sports Commission, Mallam Shehu Dikko and NFF Executive Committee member Sharif Rabiu Inuwa presented a special framed shirt to midfielder Alexander Iwobi to mark the occasion of his 100th appearance for the Super Eagles.

Cristiano Ronaldo, one of the greatest individuals to have played the game, led the Seleção das Quinas out onto the turf of the Estádio Dr Magalhães Pessoa, but the home team and crowd soon realized that the three-time African champions were not in any mood to simply turn up and be dazzled.

Ronaldo missed with only goalkeeper Maduka Okoye to beat in the 9th minute, but at the other end, Akor Adams also missed as he dragged his shot a little too wide to the left.

In the 23rd minute, Pedro Neto steered Portugal in front as he fired a grounder past Okoye from close range, after a pass by Diogo Dalot as das Quinas broke forward again.

Ten minutes later, Okoye spectacularly saved a fierce shot by Bruno Fernandes, and just a minute after, Ronaldo missed narrowly with a glancing header from Fernandes’ corner.

Nigeria kept probing. The fit-fight Akor contested an aerial ball close to the centre circle and tipped the ball away from two Portuguese defenders, ran to his left to await delivery by Fisayo Dele-Bashiru, and blasted past Diogo Costa for Nigeria’s leveller with 37 minutes gone.

In the second half, Okoye made a double save from João Félix, in the 48th and 49th minutes. Five-time Ballon d’Or winner Ronaldo also continued his search for a goal, but he failed to connect well from a cross in the 50th minute.

On the hour, Coach Éric Chelle made a number of changes, bringing in Abdullahi Bewene, Zaidu Sanusi, Terem Moffi, Raphael Onyedika and Frank Onyeka.

This appeared to rejuvenate Nigeria’s game, and they were once more pushing forward with elan, as Ronaldo exited in the 65th minute without the goal he wanted so much.

With 15 minutes left, Francisco Çonceicao got the winner for the das Quinas, firing home after cutting in from the right and with Okoye’s sight somewhat impaired.

Félix’s efforts to get on the scoresheet was again scuttled in the 84th minute by Okoye, who pushed away another fierce delivery by the forward.

The loss was only the second in regulation time for Coach Chelle after leading the Super Eagles in 25 matches over the past 15 months.

Continue Reading

Business

NCC Chief Aminu Maida to Keynote 2026 DigitalSENSE Forum in Lagos

info

Published

on

By

IMG 2059.jpeg

The Executive Vice Chairman and CEO of the Nigerian Communications Commission (NCC), Dr. Aminu Maida, is set to deliver the Keynote Address at the upcoming 2026 Nigeria DigitalSENSE Forum (NDSF) on Internet Governance for Development (IG4D). Scheduled for this Thursday, June 11, 2026, at the Banquet Hall, Welcome Centre Hotels in Lagos, the landmark 17th milestone edition will anchor its deliberations on the crucial theme: “Sustaining WSIS Vision with Multistakeholder Synergy in Nigeria.”

Dr. Maida’s address will focus on the regulatory frameworks required to preserve the World Summit on the Information Society (WSIS) vision through inclusive, multi-stakeholder partnerships. The high-level forum and its prestigious industry awards have rallied robust support from the foundational pillars of Nigeria’s telecommunications and digital infrastructure ecosystem.

Major public and private sector players are heavily backing the forum as part of their commitment to promoting critical national infrastructure and securing Nigeria’s digital possibilities. Among the leading sponsors driving this momentum are IHS Nigeria—the nation’s premier digital infrastructure champion boasting over 16,000 telecom towers and 15,000km of fiber optic cables—and data center colocation leader Digital Realty.

Ogbuefi Remmy Nweke, the Editor-in-Chief of host media organization ITREALMS Media Group, commended the immense institutional support flowing from the industry ahead of the event.

“Achieving sustainable internet governance and digital trust requires an intentional alignment of regulation and infrastructure,” Nweke remarked. “The active collaboration of the NCC, IHS Nigeria, and Digital Realty ensures that the 2026 forum will move beyond mere dialogue to produce clear, actionable policy recommendations for our digital economy.”

The event will be presided over by Dr. Olusola Teniola (hon), Director of Strategic Business Initiatives at ipNX Nigeria and former President of the Association of Telecommunications Companies of Nigeria (ATCON), who will deliver the Chairman’s Opening Speech on the 2026 NDSF blueprint.

A broad coalition of leading telecommunications, technology, and internet governance stakeholders have also thrown their weight behind the event. These include ICT infrastructure leader MTN Nigeria; the Association of Licensed Telecoms Operators of Nigeria (ALTON); premier software and DNS infrastructure firm Upperlink Limited; and the Nigeria Internet Registration Association (NiRA), managers of the .NG country code Top Level Domain name.

The post NCC Chief Aminu Maida to Keynote 2026 DigitalSENSE Forum in Lagos appeared first on Business Today NG.

Continue Reading

Trending