Actively exploited cPanel bug exposes millions of websites to takeover

2026-05-01T20:51:51Za8a8754d16feaa1e99c1d1823cfecb824ffb6a05c14ceb288296da688dfa4407
AIAndroidWHMactive-exploitationbiobankbrowser-hijackcPanelcredential-theftdata-leakiOSmalwarepaypalphishingprivacyrobloxspywaretech-support-scamtrojanweb-hostingzero-day

What happened

Malwarebytes Labs roundup (Apr 20 – May 1, 2026): an actively exploited cPanel/WHM bug allows website takeover at scale; PayPal emails are being abused to steer victims into tech‑support scams; hundreds of thousands of Roblox accounts were stolen via trojanized game “enhancements” and sold; multiple trojanized installers and a malicious trading site deliver browser‑hijacking malware; fake CAPTCHA pages are being used to rack up international SMS charges; a researcher alleges Claude Desktop installed spyware on macOS; Apple patched an iOS bug that exposed deleted notifications (including Signal

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
malwarebytes_labs
Record identifier
a8a8754d16feaa1e99c1d1823cfecb824ffb6a05c14ceb288296da688dfa4407
Enrichment time
2026-05-01T20:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.