• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Internet

Hackers use fake security advisory to target cPanel users

August 10, 2020
Share on FacebookShare on Twitter

cPanel users are being targeted in a new phishing scam that uses a fake security advisory to trick them into giving up their credentials.

cPanel provides shared web hosting users with a Linux-based graphical user interface (GUI) and control panel which simplifies website and server management.

Recently cPanel and WebHost Manager (WHM) users reported that a targeted phishing campaign that used the subject line “cPanel Urgent Update Request” in its emails had appeared online. The fake security advisory was well-crafted and used language that made it really look as if it had come from the company itself.

In their advisory, the cybercriminals behind the targeted phishing attack warned that updates had been released to fix security concerns in cPanel and WHM versions 88.0.3+, 86.0.12+ and 78.0.49+.

Fake security advisory

At the bottom of their security advisory, the attackers explained why cPanel had not released an official statement on the security issues the updates addresses, saying:

“The cPanel Security Team identified the resolved security issues. There is no reason to believe that these vulnerabilities have been made known to the public. As such, cPanel will only release limited information about the vulnerabilities at this time. Once sufficient time has passed, allowing cPanel & WHM systems to automatically update to the new versions, cPanel will release additional information about the nature of the security issues.” 

To make their targeted phishing campaign appear more legitimate, the attackers also registered the domain ‘cpanel7831.com’ and used Amazon’s Simple Email Service (SES) to send out the emails to cPanel and WHM users.

If a user fell for the scam and clicked on the “Update your cPanel & WHM installations” button, they were bought to a website that prompted them to login using their cPanel credentials. Thankfully though, the phishing landing page has since been taken down and now redirects to a Google search for the keyword cPanel.

For those who did happen to fall victim to this scam, it is highly recommended that you log in to your web hosting provider and change the password on your account. Users should also perform a complete audit of their sites and look for any odd PHP files which can be used as backdoors.

Via BleepingComputer

Next Post

Trump administration announces major midband spectrum auction for 5G – TechCrunch

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • Best AirPods deal: Save $59.01 on AirPods 4 (with ANC) at Amazon
  • Silent Hill 2 Remake Tops 5 Million Players – Sales
  • Google Maps receives major upgrade with ‘Ask Maps’ AI feature and 3D redesign
  • Did your Google Home devices just stage a mass exodus? You’re not alone
  • ‘Anima’ review: Science fiction with a generous dose of human yearning

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously