Connect with us

Tech

Hackers are actively exploiting a bug in cPanel, used by millions of websites

Published

on

Security researchers are sounding the alarm on a newly discovered vulnerability in the widely used web server management software cPanel and WebHost Manager (WHM). 

The bug allows hackers to hijack and take full control of the servers running the affected software, which is thought to be used by tens of millions of website owners around the world.

Many commercial web hosting companies have patched their customers’ systems already. But the cPanel maker urged customers to ensure that their systems are patched as the bug affects all supported versions of the software.

cPanel and WHM are two software suites used for managing web servers that host websites, manage emails, and handle important configurations and databases needed to maintain an internet domain. The two suites have deep-access to the servers that they manage, allowing a malicious hacker potentially unrestricted access to data managed by the affected software.

The bug, officially tracked as CVE-2026-41940, allows malicious hackers to remotely bypass its login screen to gain full access to the software’s administration panel. 

Given the ubiquity of the cPanel and WHM software across the web hosting industry, hackers could compromise potentially large numbers of websites that haven’t patched the bug.

Canada’s national cybersecurity agency said in an advisory that the bug could be exploited to compromise websites on shared hosting servers, such as large web hosting companies.

The agency said that “exploitation is highly probable” and that immediate action from cPanel customers, or their web hosts, is necessary to prevent malicious access.

Web hosting giant Namecheap, which uses cPanel to allow its customers to manage their web servers, said the company blocked access to customers’ cPanel panels after learning of the flaw to prevent exploitation, and to give it time to patch its customers’ systems

Hostgator also said it patched its systems and is considering the bug a “critical authentication-bypass exploit.”

One web hosting company says it found evidence that hackers have been abusing the vulnerability for months before the attempts were discovered.

KnownHost CEO Daniel Pearson said in a post on Reddit that his company has seen attempts to exploit the vulnerability as far back as February 23. The company said it also briefly began blocking access to customer systems before applying patches.

According to Pearson, around 30 servers at KnownHost showed signs of unauthorized attempted access out of thousands of computers on its network. Pearson likened the efforts to attempts, and has not seen signs of active compromise. cPanel also said it rolled out a security fix for WP Squared, a similar tool for managing WordPress websites.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Tech

Planned Amazon data center could become the biggest climate polluter in the U.S.

Published

on

As part of a planned data center in Pecos County, Texas, Amazon is investing in an on-site power plant that could become the largest source of climate pollution in the United States, according to The New York Times.

The NYT says the plant would burn natural gas and is permitted to release 33 million tons of carbon dioxide per year — more than any other power plant in the U.S.

In a statement, an Amazon spokesperson confirmed that the data center will “be powered by new on-site generation that won’t raise electricity costs for Texas families.” (Data centers face growing political opposition for a number of reasons, including their effect on electricity costs.)

AI has already had a significant impact on Amazon’s carbon emissions, which it reported were up 16% last year — the wrong direction for a company that pledged to eliminate its carbon emissions by 2040. And that could get worse as Amazon and tech companies back the development of huge natural gas plants to support their power-hungry data centers.

The Amazon spokesperson said, “The world looks different now than when we co-founded the climate pledge,” while also claiming, “Our commitment hasn’t changed.”

>

Continue Reading

Tech

OpenAI acquires presentation startup NextSlide

Published

on

NextSlide recently announced that it’s joining OpenAI, with the presentation startup’s team members now working on ChatGPT.

The NextSlide website currently displays a note from founder Ahmed Beshry describing the startup’s product as one “that could turn prompts, notes, documents, or research into a polished, editable presentation.”

The ultimate goal, Beshry said, was “to make visual communication more accessible and help more people express their ideas clearly.” So by joining OpenAI, the team will “continue pursuing that same mission: building AI products that help people create, communicate, and turn their ideas into meaningful work.”

The financial terms of the deal were not disclosed. In a note on LinkedIn, Beshry said the announcement is coming “a few months late,” as the acquisition took place “earlier this year.”

Beshry was previously a co-founder at Caper AI, a smart cart/cashier-less checkout startup acquired by Instacart in 2021.

>

Continue Reading

Tech

X replaces ‘misaligned’ revenue sharing program with Original Content Rewards

Published

on

X, the social media platform now owned by Elon Musk’s SpaceX, is shaking up how it pays influencers and creators.

In announcing the change, the company said it will be winding down its existing Revenue Sharing program and replacing it with something called Original Content Rewards. X will stop accepting new Revenue Sharing participants, while existing participants will continue earning money through September 7.

Then, starting on September 8, they’ll be able to apply for the new program. Participants will still need to subscribe to one of X’s Premium tiers, and there will be qualifying thresholds for follower count (500 verified followers) and impressions (500,000 Home Timeline impressions from verified users in 90 days), but it sounds like the big change is the emphasis on originality. 

What counts as original content? X said it can include original reporting and analysis, photos and videos created by the poster, or memes and graphics they’ve designed themselves. Commentary also counts, but “if your content regularly incorporates material created by others, you’ll need to contribute meaningful original value for it to qualify under our original content guidelines.”

The company also included examples of posts that won’t count as original, such as those just copied over from another account, downloaded from one account and re-uploaded to your own, or reposting content “without meaningful transformation.”

This announcement follows repeated attempts by X to reform the Revenue Sharing program, for example reducing payments to aggregators and “clickbait” accounts in April. But these efforts have also prompted complaints from popular accounts profiting from the current system; Musk even reversed some of those changes (giving a creator’s local audience more weight when calculating payouts) after a backlash.

In a post about the new changes, X’s Allegra Jacchia wrote that the existing program “had reached a point where its incentives were misaligned.”

“Creators should be focused on bringing net new content to the platform instead of maximizing payouts,” she said. “We could have kept adding more rules and exceptions, but ultimately the better decision was to start fresh and build a program designed from day one to reward originality.”

Jacchia added that X be “continue refining the program, improving our models, and raising the bar over time.”

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.

>

Continue Reading

Trending

Copyright © 2017 Zox News Theme. Theme by MVP Themes, powered by WordPress.