Domains.co.za DDoS

Just an update, domains got back to me with more info. I've removed some identifiers, apparently its the CVE-2026-41940 issue:

"Thank you for bringing this to our attention. We've investigated and found that several unauthorized FTP accounts were created under your cPanel username, but appear to be from some time ago as no ftp creation exist in the existing logs. No SSH keys or API tokens were affected.

We have noticed this occurred on websites related to (redacted) and it seems very targeted by a Turkish group that appears to be doing this for (redacted) by attempting to hijack your Google rankings.

It's likely that these ftp accounts were created before the recent cPanel session vulnerability patches, as the vulnerability allowed for the bypassing of 2FA. However, based on the ftp logs, they only logged in this morning and uploaded files."

Anyway, all sorted now, wonder when this happened as one affected domain is only 2 months old.
 
Last edited:
Just an update, domains got back to me with more info. I've removed some identifiers, apparently its the CVE-2026-41940 issue:

"Thank you for bringing this to our attention. We've investigated and found that several unauthorized FTP accounts were created under your cPanel username, but appear to be from some time ago as no ftp creation exist in the existing logs. No SSH keys or API tokens were affected.

We have noticed this occurred on websites related to (redacted) and it seems very targeted by a Turkish group that appears to be doing this for (redacted) by attempting to hijack your Google rankings.

It's likely that these ftp accounts were created before the recent cPanel session vulnerability patches, as the vulnerability allowed for the bypassing of 2FA. However, based on the ftp logs, they only logged in this morning and uploaded files."

Anyway, all sorted now, wonder when this happened as one affected domain is only 2 months old.
is the domain thats 2 months old ...on the same cpanel?
 
I'm not sure as thats one that I've been helping someone with, and I don't have direct access to check, but they were affected.
Cause if the domains and sites are under that one cpanel user thats probably how they did it to the fresh one as sounds like they created a ftp accounts.

same with wordpress Medium to XL can have 2-4 sites on them under that 1 user.

But as long as its patched etc you should hopefully be fine.

not like we go look for ftp users when we have no need to look. surprised

Suprised Immuify didnt pick it up
 
Cause if the domains and sites are under that one cpanel user thats probably how they did it to the fresh one as sounds like they created a ftp accounts.

same with wordpress Medium to XL can have 2-4 sites on them under that 1 user.

But as long as its patched etc you should hopefully be fine.

not like we go look for ftp users when we have no need to look. surprised

Suprised Immuify didnt pick it up
It would have been under a different cpanel user with seperate domains and cpanel login, completely unconnected. It just shares the same niche that was targeted. I picked up on the ftp users on my sites, and yeah, would never have noticed it otherwise.
 
It would have been under a different cpanel user with seperate domains and cpanel login, completely unconnected. It just shares the same niche that was targeted. I picked up on the ftp users on my sites, and yeah, would never have noticed it otherwise.
then someone at domains didnt check or let you know correctly about "it must of been ages ago" bit
 
Just an update, domains got back to me with more info. I've removed some identifiers, apparently its the CVE-2026-41940 issue

Hi,

Just an update on this, it is not due to this CVE-2026-41940 - we are completely patched for that, but initially it looked like it could have been that.

We have discovered an exploit and how they were able to create the FTP accounts. It's related to a privilege escalation vulnerability in Litespeed cPanel plugin that allows for WHM commands to be run on the server. Because the ftp account is created using the whm command, it does not log in the cpanel access logs.

Analysis of the exploit shows it's purpose is to list cpanel domains and create ftp accounts on cpanel accounts. It does not performs no other whm actions, however this could be easily altered to do more harm like run root commands.

Litespeed was not aware of this vulnerability or the exploit when we reported it to them last night.
They are releasing a patch today to fix the vulnerability (version 5.2.10) . We are waiting on them to raise the CVE for it.

We also reported the exploit to Monarx, Imunify as well as the cPanel security team.

cPanel has released a cPanel update now to disable the plugin - https://support.cpanel.net/hc/en-us...lly-removed-during-nightly-update-May-19-2026

This is the email cPanel has now just sent out regarding this:

1779262986756.png


From our side, we disabled the Litespeed plugin last night already to mitigates the issue and run clean up's on the affected accounts.

Regards,
Dave @ Domains.co.za
 
From our side, we disabled the Litespeed plugin last night already to mitigates the issue and run clean up's on the affected accounts.

Regards,
Dave @ Domains.co.za
Thanks for the detailed response Dave, appreciate it.
 
Top
Sign up to the MyBroadband newsletter
X