Attackers exploit cPanel CVE-2026-41940 to deploy Filemanager Backdoor

2026-05-12T14:51:41Zd039fe3676382724719af25428d33f3e714325a847a2daa576b4031684464daa
AI-enabled attacksAndroid banking trojanBerriAICISA KEVCVE-2026-41940CVE-2026-42208Crimenetwork takedownFilemanager backdoorGitHub breachInstagram E2EE removalJDownloaderPython RATSailPointTON networkTrickMocPanelremote code executionsupply chainvulnerability disclosurezero-day exploitation

What happened

Multiple active and high-impact threats reported: attackers are actively exploiting a critical cPanel vulnerability (CVE-2026-41940, CVSS 9.3) to deploy a Filemanager backdoor and gain admin access; CISA added a critical BerriAI LiteLLM flaw (CVE-2026-42208, CVSS 9.3) to its KEV catalog following rapid exploitation; the official JDownloader site was compromised to distribute installers containing a Python RAT (supply-chain malware); TrickMo Android banking malware evolved to use the TON network for C2 to improve stealth; SailPoint disclosed a GitHub repository breach (no customer data reported

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
d039fe3676382724719af25428d33f3e714325a847a2daa576b4031684464daa
Enrichment time
2026-05-12T14:51:41Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.