Latest Daily News Hosting, Technology News, Updates, and Trends
Latest Daily News Hosting, Technology News, Updates, and Trends
  • Home
  • News Categories
    • Cyber Security
    • Cloud Hosting
    • Data Center
    • WordPress
    • Search Engine Ranking
    • cPanel Hosting
    • CDN Hosting
    • Press Release
    • WordPress.org-Wp Engine Battle
    • World
  • Web Stories
 CyberPanel Ransomware Attack: Vulnerabilities forced thousands of instances to be taken offline   
Cyber Security

CyberPanel Ransomware Attack: Vulnerabilities forced thousands of instances to be taken offline   

by Manvinder Singh November 4, 2024 0 Comment

A massive PSAUX ransomware attack by Cybercriminals has disrupted CyberPanel instances after taking advantages of multiple vulnerabilities in CyberPanel.  

Due to a massive PSUAX ransomware attack, thousands of CyberPanel instances are forced to be taken offline. Cybercriminals have taken advantage of multiple vulnerabilities in CyberPanel and installed PSUAX ransomware which forced thousands of CyberPanel instances offline. Attacks involved a pair of scripts, one for CyberPanel bug exploitation and the other for file encryption. 

Why is PSAUX Ransomware harmful? 

PSAUX ransomware targets Linux- based systems. It has advanced techniques to avoid detection which make it harmful for businesses and organizations which are using Linux systems for critical applications. 

What were the CyberPanel vulnerabilities? 

Alias DreyAnd, a cybersecurity researcher, has announced finding three major vulnerabilities in CyberPanel 2.3.6 and most likely to be 2.3.7 that allowed cybersecurity breachers for remote code execution, and arbitrary system commands execution. 

Security researcher DreyAnd disclosed that CyberPanel 2.3.6 (and likely 2.3.7) suffers from three distinct security problems like defective authentication, command injection and security filter bypass that can result in an exploit allowing unauthenticated remote root access without authentication. 

In a statement to Bleeping Computer, Cybersecurity researcher Alias DreyAnd has said that “he could only test the exploit on version 2.3.6 as he did not have access to the 2.3.7 version at the time. However, as 2.3.7 was released on September 19, before the bug was found, it was likely impacted as well. They also published a Proof – of – Control (PoC) on How to take over vulnerable server. 

As per Bleeping Computer’s report, over 22,000 CyberPanel instances exposed online to a critical remote code execution (RCE) vulnerability were mass-targeted in a PSAUX ransomware attack that took almost all instances offline.  

As per threat intelligence search engine LeakIX, most of these CyberPanel implementations were in the United States, followed by Germany, Singapore, Indonesia, India and France. These files i.e. PSAUX files had a loophole which enabled LeakIX to develop a decryptor.   

The Businesses and Organizations that were affected by  CyberPanel PSUAX Ransomware attack were immediately asked to install the latest version of the software from GitHub.   

Related News:  

Cloudflare’s Threat report Q3 2024: 6 million attacks across 330 cities 
MIT’s protocol to shield cloud-based server data 
Google Introduces AI to Support Global Startups with Cybersecurity Program 

Tags: Cyber Attack CyberPanel ransomware attack Ransomware threat
Previous post
Next post

Manvinder Singh (Website)

author

Manvinder Singh, with 15 years in the web hosting industry, now shares his expertise as a news auditor, enriching web hosting users with valuable insights and guidance. His extensive experience spans server management, security protocols, and customer support, making him a trusted source in navigating the complexities of web hosting solutions. Passionate about transparency and reliability, Manvinder continues to empower businesses and individuals with practical knowledge, ensuring they make informed decisions in optimizing their online presence.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Recent News

  • CITRA to Sign Lease Contract with Google to Establish Three Data Centers  
  • Last Algorithm Update of 2024; Google Rolls Out December Core Update
  • WP Engine Scores Legal Win Against Automattic
  • Search Engine Update: Google Resolved Indexing Issues
  • Google Asks US Government to Break Up Microsoft’s Cloud Deal with Open AI

Recent Comments

No comments to show.

Archives

  • December 2024
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • October 2022
  • September 2022
  • August 2022
  • March 2022
  • February 2022
  • January 2022
  • December 2021
  • November 2021

Categories

  • Cloud Hosting
  • cPanel Hosting
  • Cyber Security
  • Data Center
  • Press Release
  • Search Engine Ranking
  • WordPress
  • WordPress.org-Wp Engine Battle
  • World

About Hosting Daily News

Hosting Daily news primarily focuses on delivering quality and authentic content related to the hosting industry. Hosting Daily News covers a wide range of news, articles, announcements, community-based content to keep the tech enthusiasts engaged with the latest development of hosting industry which includes Cloud Hosting, Web Hosting, cybersecurity, WordPress, AI technology and various topics related to hosting. We aim to foster collaborations and knowledge sharing content among industry stakeholders.

Top Categories

  • Cloud Hosting
  • cPanel Hosting
  • Cyber Security
  • Data Center
  • Press Release
  • Search Engine Ranking
  • WordPress
  • WordPress.org-Wp Engine Battle
  • World

Latest News

  • CITRA to Sign Lease Contract with Google to Establish Three Data Centers  
  • Last Algorithm Update of 2024; Google Rolls Out December Core Update
  • WP Engine Scores Legal Win Against Automattic
  • Search Engine Update: Google Resolved Indexing Issues
  • Google Asks US Government to Break Up Microsoft’s Cloud Deal with Open AI
Copyright © 2025 HostingDailyNews. All Right Reserved.
  • Instagram
  • Facebook
  • X
  • LinkedIn