Actively exploited cPanel bug exposes millions of websites to takeover
2026-05-01T20:51:51Z•a8a8754d16feaa1e99c1d1823cfecb824ffb6a05c14ceb288296da688dfa4407
AIAndroidWHMactive-exploitationbiobankbrowser-hijackcPanelcredential-theftdata-leakiOSmalwarepaypalphishingprivacyrobloxspywaretech-support-scamtrojanweb-hostingzero-day
What happened
Malwarebytes Labs roundup (Apr 20 – May 1, 2026): an actively exploited cPanel/WHM bug allows website takeover at scale; PayPal emails are being abused to steer victims into tech‑support scams; hundreds of thousands of Roblox accounts were stolen via trojanized game “enhancements” and sold; multiple trojanized installers and a malicious trading site deliver browser‑hijacking malware; fake CAPTCHA pages are being used to rack up international SMS charges; a researcher alleges Claude Desktop installed spyware on macOS; Apple patched an iOS bug that exposed deleted notifications (including Signal
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- malwarebytes_labs
- Record identifier
- a8a8754d16feaa1e99c1d1823cfecb824ffb6a05c14ceb288296da688dfa4407
- Enrichment time
- 2026-05-01T20:51:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.