Hackers accessed BWH Hotels reservation system for months
2026-05-12T20:51:46Z•3989d9db07093096cca3d2ce3db02fdd3ce7490a0af41463aa1d350ed14ffc2e
AI-threatsAndroid-banking-trojanAnthropic-MythosBWH-HotelsBerriAICISA-KEVCVE-2026-41940CVE-2026-42208CrimenetworkFilemanager-backdoorGitHub-repository-breachInstagramLiteLLMSailPointTON-networkTrickMoWannaCrycPanelcurlcybercrime-marketplacedata-breachend-to-end-encryptionhotel-reservationsransomwarevulnerability-research
What happened
Multiple high-impact incidents and trends were reported: threat actors are actively exploiting the critical cPanel vulnerability CVE-2026-41940 (CVSS 9.3) to deploy the Filemanager backdoor and gain admin access to hosting servers; CISA added CVE-2026-42208 in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog. Large-scale data breaches and exposures were disclosed (BWH Hotels reservation-system intrusion, SailPoint GitHub repository breach). Other noteworthy developments include an evolved TrickMo Android banking trojan using the TON network for C2, a revived/dismantled Crimenetw0
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 3989d9db07093096cca3d2ce3db02fdd3ce7490a0af41463aa1d350ed14ffc2e
- Enrichment time
- 2026-05-12T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.