New cPanel vulnerabilities could allow file access and remote code execution

2026-05-10T20:51:50Zcf0dc1b1f53d37281a82d75246f1d7a07aefa23a85f499766ea454f11ff0bdc0
BraintrustDirtyFragJDownloaderQuasarRATTrellixcPanelcritical-infrastructuredata-breachexploit-publicicskernellinuxmalwareprivilege-escalationransomwaresecurity-updatesupply-chainthird-party-breachwindows

What happened

This feed aggregates multiple high-impact security reports from May 2026: cPanel released fixes for three vulnerabilities allowing file reads, code execution and privilege escalation; the official JDownloader website was compromised (May 6–7) to distribute malicious Windows and Linux installers carrying a Python RAT; researchers uncovered Quasar Linux RAT (QLNX), a fileless Linux implant targeting developers for credential theft and persistence; Braintrust suffered an AWS account breach exposing secrets and prompting API-key rotation; RansomHouse claimed a breach of Trellix and leaked internal

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
cf0dc1b1f53d37281a82d75246f1d7a07aefa23a85f499766ea454f11ff0bdc0
Enrichment time
2026-05-10T20:51:50Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.