$ techbeacon▋
CVE & Exploits

Hackers Exploit cPanel Authentication Flaw, Fuel Surge in Mirai-Style Telnet Attacks

Hackers Exploit cPanel Authentication Flaw, Fuel Surge in Mirai-Style Telnet Attacks

Security analysts have confirmed that threat actors swiftly leveraged a critical authentication bypass in the popular web‑hosting control panels cPanel and WHM, gaining unauthorized access to a large number of internet‑facing servers worldwide.

The vulnerability, which allows an attacker to bypass normal login checks and assume administrative privileges, affects the core management interface used by millions of hosting providers to provision websites, email accounts and databases. Once inside, the intruders can install malicious software, alter configuration files, and use the compromised machines as launch points for further attacks.

Telemetry collected from Japanese network sensors revealed a sharp uptick in scanning activity that mirrors the behavior of the notorious Mirai botnet. The same data linked the surge to increased attempts to contact Telnet services on the compromised hosts, suggesting that the newly accessed servers are being enlisted to expand a Mirai‑like botnet capable of massive DDoS campaigns.

Hosting environments are attractive targets because they are typically exposed to the public internet and often run multiple customer sites on a single physical or virtual server. A breach can therefore affect a wide range of downstream users, from small businesses to high‑traffic e‑commerce platforms. In addition to potential data theft, the compromised infrastructure can be repurposed to host phishing sites, distribute ransomware, or amplify traffic‑shaping attacks.

cPanel and WHM have long been considered industry standards for shared hosting management, and the platform’s extensive adoption means that the flaw has a broad attack surface. Past incidents have shown that rapid patch deployment is essential; however, many administrators delay updates due to concerns over service interruption or compatibility with custom plugins.

Following the public disclosure, the cPanel development team issued an emergency patch that addresses the authentication bypass. Security experts are urging operators to apply the fix immediately, review access logs for signs of unauthorized activity, and enforce strong network segmentation to limit the impact of any future compromise. Continuous monitoring for abnormal Telnet traffic is also recommended, as it remains a key indicator of botnet recruitment attempts.

Source: GBHackers
Vikas Thakur — Vikas covers DDoS attacks, botnet infrastructure, and network-layer threats. Hands-on experience with mitigation and traffic analysis, covers IoT botnets and infra-level attacks.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related