Security Check-in Quick Hits: cPanel Ransomware Rampage, Linux Zero-Days, Trellix Breach, and Agentic AI Warnings
For May 2, 2026
cPanel/WHM Zero-Day (CVE-2026-41940) Fuels Ransomware and Botnet Surge
A pre-authentication bypass in cPanel and WHM has gone from disclosure to mass exploitation in under 24 hours. Attackers are hitting login flows to gain remote unauthenticated access, then deploying two distinct payloads: a Mirai variant (“nuclear.x86”) for botnet recruitment and a ransomware strain that drops “.sorry” encrypted files in web directories.
DFIR teams report over 15,000 newly compromised cPanel hosts in a single day—nearly 80 % of all fresh infections observed—concentrated on VPS and cloud providers like DigitalOcean, Contabo, and OVH. Open directories are already leaking ransom notes, and security researchers are urging immediate patching plus log reviews for suspicious authentication activity between April 29 and May 1.
Takeaway for defenders: If you run cPanel, treat this as an emergency. Rotate credentials, scan for the known Mirai binary, and block unusual web-process network connections. Hosting providers are the new soft underbelly.
Linux “Copy Fail” Bug and Kernel LPE Give Attackers Root on Servers
Multiple X threads are flagging a quiet but nasty Linux zero-day dubbed “Copy Fail” that enables root-level takeovers on servers. Paired with reports of Linux kernel local privilege escalation (LPE), the bug is showing up in the same conversations as the cPanel wave—suggesting attackers are chaining supply-chain and hosting-panel flaws to own bare-metal and virtual Linux environments.
The issue appears tied to file-copy operations or kernel handling that quietly escalates privileges when certain conditions are met. Enterprise developers and cloud teams are being told to watch for anomalous root processes and unexpected package updates.
Takeaway: Update Linux kernels immediately where possible and enable strict file-integrity monitoring. The overlap with cPanel attacks indicates coordinated campaigns targeting the full hosting stack.
Trellix Confirms Source-Code Breach via Unauthorized Repository Access
Security vendor Trellix disclosed unauthorized access to its internal repositories, confirming that attackers made off with source code. The breach was flagged quickly, but the potential for weaponized exploits built from leaked code is now a live concern for any organization using Trellix products or relying on similar EDR/AV ecosystems.
X conversations are treating this as the latest in a string of supply-chain incidents (Bitwarden and SAP package credential theft also mentioned in the same breath). Adversaries increasingly target vendors’ dev environments because one successful repo compromise can yield implants for thousands of downstream customers.
Takeaway: Review your vendor risk posture. Ask Trellix partners for their incident timeline and any IOCs. For internal teams, double down on code-signing, SBOM tracking, and isolated build pipelines.
CISA Sounds Alarm on Agentic AI in Critical Infrastructure + Fresh AI-Targeted CVE
CISA released fresh guidance on securing agentic AI systems in critical infrastructure, warning that increased autonomy expands attack surfaces and privilege risks. The agency is pushing threat modeling, defense-in-depth, and hardened deployment practices.
Hot on its heels, researchers disclosed CVE-2026-7600 in the ArtMin96 yii2-mcp-server—an agentic AI component that lets remote attackers execute OS commands and achieve full server compromise. The vuln is already being called out as a “must-patch” for anyone running AI-driven automation.
X is buzzing about how AI systems are moving from experimental to production in power grids, utilities, and industrial environments—exactly the places where one bad prompt or exploited plugin could cascade into physical impact.
Takeaway: Treat every agentic AI deployment like a high-privilege service. Apply CISA’s threat-modeling checklist today and patch the yii2-mcp-server CVE immediately.
Stay safe out there—the weekend threat velocity is real. Patch aggressively, hunt for the IOCs above, and keep an eye out for the next wave. These four stories dominated the last 24 hours; expect them to keep trending into next week.



