New cPanel vulnerabilities could allow file access and remote code execution
2026-05-10T20:51:50Z•cf0dc1b1f53d37281a82d75246f1d7a07aefa23a85f499766ea454f11ff0bdc0
BraintrustDirtyFragJDownloaderQuasarRATTrellixcPanelcritical-infrastructuredata-breachexploit-publicicskernellinuxmalwareprivilege-escalationransomwaresecurity-updatesupply-chainthird-party-breachwindows
What happened
This feed aggregates multiple high-impact security reports from May 2026: cPanel released fixes for three vulnerabilities allowing file reads, code execution and privilege escalation; the official JDownloader website was compromised (May 6–7) to distribute malicious Windows and Linux installers carrying a Python RAT; researchers uncovered Quasar Linux RAT (QLNX), a fileless Linux implant targeting developers for credential theft and persistence; Braintrust suffered an AWS account breach exposing secrets and prompting API-key rotation; RansomHouse claimed a breach of Trellix and leaked internal
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- cf0dc1b1f53d37281a82d75246f1d7a07aefa23a85f499766ea454f11ff0bdc0
- Enrichment time
- 2026-05-10T20:51:50Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.