THEY ARE GOING TO BAN VPNs
THEY ARE GOING TO BAN VPNs
THEY ARE GOING TO BAN VPNs
THEY ARE GOING TO BAN VPNs
THEY ARE GOING TO BAN VPNs
THEY ARE GOING TO BAN VPNs
THEY ARE GOING TO BAN VPNs
THEY ARE GOING TO BAN VPNs
THEY ARE GOING TO BAN VPNs
THEY ARE GOING TO BAN VPNs
🚨 The cPanel Situation Is Spiraling Fast
On April 29, CVE-2026-41940 was disclosed: a critical pre-authentication bypass in cPanel/WHM that lets remote attackers skip the login flow entirely and gain elevated access. Within 24 hours, it was already being weaponized. Censys watched the fallout in real time.
The 6-day timeline (cPanel hosts flagged malicious):
Apr 26: 117
Apr 27: 47
Apr 28: 106
Apr 29: 70
Apr 30: 146
May 1: 15,448
On May 1 alone, total malicious hosts jumped by +19,131, and 15,302 of those (roughly 80%) were cPanel/WHM systems. Compare that to the prior days where cPanel made up well under 1.2% of daily changes. This was not background noise. It was a coordinated spike.
Top affected providers:
DigitalOcean: 1,043
Contabo: 716
OVH: 501
Vultr: 391
Oracle: 321
Unified Layer: 280
Hetzner: 277
Akamai/Linode: 275
GoDaddy: 209
Microsoft: 169
With 1,052,657 cPanel/WHM hosts exposed on the public internet and only 9,595 currently flagged as malicious, the attack surface is enormous and growing. At least two campaigns are running in parallel: a Mirai botnet variant (nuclear.x86) deployed post-compromise, and a ransomware campaign tied to the Sorry/Hidden-Tear family.
Ransomware footprint:
~7,000 cPanel servers with ".sorry" encrypted files
6,465 hosts: index.html.sorry
1,637 hosts: index.php.sorry
795 hosts: wp-config.php.sorry
Victims directed to attackers via qTox
If you run cPanel/WHM, patch immediately.
Source: https://t.co/49i8p33EER
Ce n’est pas une théorie.
C’est déjà arrivé. En Utah.
Étape 1 : loi de vérification d’âge contre les sites pornographiques.
Étape 2 : la loi échoue. Les utilisateurs contournent avec des VPN.
Étape 3 : nouvelle loi. Restriction d’usage des VPN. Pas limitée aux mineurs ni au porno.
C’est exactement le pattern que je décrivais ce matin.
→ “Donnez-nous vos données pour votre sécurité”
→ La solution ne fonctionne pas
→ Les utilisateurs trouvent un contournement
→ On légifère contre le contournement
Virkkunen disait le 29 avril que rendre l’app “non contournable” était “une partie importante des prochaines étapes”.
L’Utah vient de nous montrer ce que ça veut dire concrètement.
The “age verification app” the EU wants to impose on the world got hacked in 2 minutes.
Step 1: Present a “privacy-respecting” but hackable solution.
Step 2: Get hacked (you are here).
Step 3: Remove privacy to "fix" it.
Result: a surveillance tool sold as “privacy-respecting”.
‼️🇪🇺 The EU's new Age Verification app was hacked with little to no effort.
When you set it up, the app asks you to create a PIN. But that PIN isn't actually tied to the identity data it's supposed to protect. An attacker can delete a couple of entries from a file on the phone, restart the app, pick a new PIN, and the app happily hands over the original user's verified identity credentials as if nothing happened.
It gets worse. The app's "too many attempts" lockout is just a counter in a text file. Reset it to 0 and keep guessing. The biometric check (face/fingerprint) is a simple on/off switch in the same file. Flip it to off and the app skips it entirely.
Next, Next, SYSTEM: Exploiting NSIS installer bugs to escalate privileges in Zscaler Client Connector
In this blog post I show how patch gaps in Zscaler's bundled NSIS versions led to LPE..
includes PoCs and yara rule to help you find other affected s/w
https://t.co/cFiDsPFDES
Relayed NTLM creds are powerful, if you can use them.
@senderend shows why browsers fail through ntlmrelayx SOCKS and introduces ghostsurf to make NTLM-authenticated web apps accessible.
Read more ⤵️ https://t.co/BdtzoKquD1
Confirmation sérieuse : le ministère de l'Intérieur a bien été piraté.
Ce ministère souhaite :
- le scan des messageries (#ChatControl)
- identification+preuve d'âge sur les réseaux sociaux
"Aucune raison de craindre des fuites d'informations personnelles sensibles"...
🔥Introducing a new Red Team tool - SessionHop: https://t.co/oU2R60ayPD
SessionHop utilizes the IHxHelpPaneServer COM object to hijack specified user sessions. This session hijacking technique is an alternative to remote process injection or dumping LSASS. Kudos to @tiraniddo for first discovering this years ago.
Blue Team tip: Look for unusual child processes spawning from HelpPane.exe
My very first blog post is live: https://t.co/tQgJZpuDos
During research, I've run into and documented a simple universal SQLite Injection RCE trick. Enjoy!
N-day Analysis about Synology Beestation RCE (CVE-2024-50629~50631) by legendary DEVCORE 🎃 🍊
Thanks to @u1f383@orange_8361 for original finding and allowing to post, and to @the_emmons for the invaluable references 🔥
Enjoy the Demo!
PoC: https://t.co/rM1CEfhkjr
Cloudflare has recently started blocking proxy tools like Burp Suite by identifying their unique TLS and request fingerprints.
If you encounter this issue, install the “Bypass Bot Detection” extension from the BApp Store. This extension spoofs Burp’s TLS fingerprint, making it appear like normal browser traffic and bypass it.
Credential Guard was supposed to end credential dumping. It didn't.
@bytewreck just dropped a new blog post detailing techniques for extracting credentials on fully patched Windows 11 & Server 2025 with modern protections enabled.
Read for more ⤵️ https://t.co/mYPHg1mTKj
I've been researching the Microsoft cloud for almost 7 years now. A few months ago that research resulted in the most impactful vulnerability I will probably ever find: a token validation flaw allowing me to get Global Admin in any Entra ID tenant. Blog: https://t.co/jD6EaGtsn3
New attack vector: FileFix.
A phishing trick that executes PowerShell straight from your browser no Run dialog, no pop-ups.
Just a fake file path + clipboard + File Explorer.
Red teamers, this one’s wild.
📽️ PoC + write-up: https://t.co/65BgBrTPvq
No one is likely surprised by this, but it does feed into the narrative of humanity actually dumbing down instead of becoming more intelligent.
I have no empirical evidence at hand to support my gut feeling, but ever since the internet in general, I feel like we are dumber.