New cPanel IOC
http://180[.]93[.]243[.]75:8080
http://45[.]140[.]164[.]151:8080/IXhwpJOUk4/blue.drx
http://180[.]93[.]243[.]75:8080/ovh
http://68[.]183[.]190[.]253/fav.ico|sh
https://raw[.]githubusercontent[.]com/nezhahq/scripts/main/agent/install.sh
#cpanel#ioc#malware
Following the disclosure of the cPanel vulnerability CVE-2026-41940, threat actors wasted no time. Read our full breakdown to see exactly what they did once they were inside.
hawktrace.com/blog/cpanel/
CVE-2025-49704:
This vulnerability arises from the implementation of the SurrogateSelector interface.
CVE-2025-49706 authentication bypass, allows import/update operations on SharePoint WebPart components via the ToolPane endpoint.
Accordingly, you can contact the @hawktrace