Weaver E-cology critical bug exploited in attacks since March
2026-05-05T01:23:29Z•26c691627ecd182f1e2283d3a204724f159571d0fb291e942dacaace37ca6041
authentication-bypassbackdoorcloud-email-abusecredential-theftcritical-vulnerabilitydata-breachexploitation-in-the-wildlinux-rootoauth-abusepackage-managementphishingransomwaresoftware-repository-compromisesupply-chain-compromisetelegram-fraud
What happened
Multiple high-impact incidents and active exploits reported: a critical Weaver E-cology vulnerability (CVE-2026-22679) has been exploited since March to run discovery commands, and a critical cPanel flaw (CVE-2026-41940) is being mass-exploited by "Sorry" ransomware operators. Other notable items include a critical authentication-bypass in MOVEit Automation (customers urged to patch), the "Copy Fail" Linux flaw now used to gain root, and a backdoored PyTorch Lightning PyPI package that drops a credential-stealer. Widespread abuse and fraud trends were also observed — Amazon SES is increasingly
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 26c691627ecd182f1e2283d3a204724f159571d0fb291e942dacaace37ca6041
- Enrichment time
- 2026-05-05T01:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.