
Hackers are actively exploiting a bug in cPanel, used by millions of websites
Web hosts are scrambling to fix the bug under active attack by hackers. One company said hackers have been abusing the bug for months.
Use the header search or filters below.

Web hosts are scrambling to fix the bug under active attack by hackers. One company said hackers have been abusing the bug for months.
The government of Sri Lanka has lost more than $3 million in two recent, separate cybersecurity incidents as the country continues to recover from its 2022 debt crisis.
The American technology giant provides water and energy monitoring and utility meters to hundreds of millions of homes and businesses.

Grinex says needed hacking resources "available exclusively to ... unfriendly states."

Dozens of WordPress plug-ins were allegedly hijacked to push malware after they were sold to a new corporate owner.
It's not clear how many people were compromised by this hacking campaign, but a security researcher said the hackers were targeting victims since at least November 2025.
The U.K. energy company said a redirected payment meant for a contractor instead landed in a hacker's bank account.

A joint FBI, NSA, and CISA advisory warns that Iranian hackers have "escalated" their tactics in response to the ongoing U.S.-Israel war with Iran.
North Korean hackers pushed out malicious updates to a popular open source project by hacking a top developer's computer in a long-running campaign.

The U.S. telehealth giant says hackers stole customer support ticket data over the course of several days in February.