Hackers accessed BWH Hotels reservation system for months

2026-05-12T20:51:46Z3989d9db07093096cca3d2ce3db02fdd3ce7490a0af41463aa1d350ed14ffc2e
AI-threatsAndroid-banking-trojanAnthropic-MythosBWH-HotelsBerriAICISA-KEVCVE-2026-41940CVE-2026-42208CrimenetworkFilemanager-backdoorGitHub-repository-breachInstagramLiteLLMSailPointTON-networkTrickMoWannaCrycPanelcurlcybercrime-marketplacedata-breachend-to-end-encryptionhotel-reservationsransomwarevulnerability-research

What happened

Multiple high-impact incidents and trends were reported: threat actors are actively exploiting the critical cPanel vulnerability CVE-2026-41940 (CVSS 9.3) to deploy the Filemanager backdoor and gain admin access to hosting servers; CISA added CVE-2026-42208 in BerriAI LiteLLM to its Known Exploited Vulnerabilities catalog. Large-scale data breaches and exposures were disclosed (BWH Hotels reservation-system intrusion, SailPoint GitHub repository breach). Other noteworthy developments include an evolved TrickMo Android banking trojan using the TON network for C2, a revived/dismantled Crimenetw0

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
3989d9db07093096cca3d2ce3db02fdd3ce7490a0af41463aa1d350ed14ffc2e
Enrichment time
2026-05-12T20:51:46Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.