theratman
Honorary Master
Just an update, domains got back to me with more info. I've removed some identifiers, apparently its the CVE-2026-41940 issue:
"Thank you for bringing this to our attention. We've investigated and found that several unauthorized FTP accounts were created under your cPanel username, but appear to be from some time ago as no ftp creation exist in the existing logs. No SSH keys or API tokens were affected.
We have noticed this occurred on websites related to (redacted) and it seems very targeted by a Turkish group that appears to be doing this for (redacted) by attempting to hijack your Google rankings.
It's likely that these ftp accounts were created before the recent cPanel session vulnerability patches, as the vulnerability allowed for the bypassing of 2FA. However, based on the ftp logs, they only logged in this morning and uploaded files."
Anyway, all sorted now, wonder when this happened as one affected domain is only 2 months old.
"Thank you for bringing this to our attention. We've investigated and found that several unauthorized FTP accounts were created under your cPanel username, but appear to be from some time ago as no ftp creation exist in the existing logs. No SSH keys or API tokens were affected.
We have noticed this occurred on websites related to (redacted) and it seems very targeted by a Turkish group that appears to be doing this for (redacted) by attempting to hijack your Google rankings.
It's likely that these ftp accounts were created before the recent cPanel session vulnerability patches, as the vulnerability allowed for the bypassing of 2FA. However, based on the ftp logs, they only logged in this morning and uploaded files."
Anyway, all sorted now, wonder when this happened as one affected domain is only 2 months old.
Last edited:
