WHM and cPanel's 2FA bypassed by hackers exploiting vulnerability
Bruteforcing attacks have allowed hackers to bypass 2FA of WHM and cPanel.
Vulnerability dubbed as CVE-2020-27641 has allowed malicious actors to bypass 2-factor authentication of Web Hosting Manager and cPanel. The targeted products have been actively working to ease various features for webmasters.
The listed products allow people who don’t know much about coding to implement a range of features like installing new websites in one click. However, it is important to understand that the entire setup in itself could be vulnerable as well.
Security researchers have alerted people about the vulnerability which allows hackers to compromise the 2FA by simply using brute force attacks. The vulnerability rose because of the unlimited amount of trials available for entering the 2FA code.
cPanel has issued patches and users can protect themselves by updating to its latest version. If you think on the other hand that you may have been a victim of such an attack, it is best to contact their support team who can help you secure your account further on.
Install NPAV on your devices to keep them safe and secure from all kinds of cyberattacks. Use NPAV and join us on a mission to secure the cyber world.
- Other (42)
- Ransomware (128)
- Events and News (26)
- Features (45)
- Security (434)
- Tips (79)
- Google (22)
- Achievements (9)
- Products (33)
- Activation (7)
- Dealers (1)
- Bank Phishing (42)
- Malware Alerts (195)
- Cyber Attack (222)
- Data Backup (11)
- Data Breach (81)
- Phishing (139)
- Securty Tips (1)
- Browser Hijack (16)
- Adware (15)
- Email And Password (67)
- Android Security (56)
- Knoweldgebase (38)
- Botnet (15)
- Updates (3)
- Alert (71)
- Hacking (57)
- Social Media (7)
- vulnerability (54)
- Hacker (31)
- Spyware (8)
- Windows (6)
- Microsoft (21)
- Uber (1)
- YouTube (1)
- Trojan (2)
- Website hacks (3)
- Paytm (1)
- Credit card scam (1)
- Telegram (3)
- RAT (5)
- Bug (3)
- Twitter (2)
- Facebook (7)
- Banking Trojan (5)
- Mozilla (2)
- COVID-19 (5)
- Instagram (2)
- NPAV Announcement (6)
- IoT Security (1)
- Deals and Offers (1)
- Cloud Security (8)
- Offers (5)
- Gaming (1)
- FireFox (2)
- LinkedIn (2)
- WhatsApp (4)
- Amazon (1)
- DMart (1)
- Payment Risk (4)
- Occasion (3)
- firewall (1)
- Cloud malware (2)
- Cloud storage (2)
- Financial fraud (8)
- Impersonation phishing (1)
- DDoS (4)
- Smishing (2)
- Whale (0)
- Whale phishing (3)
- WINRAR (2)
- ZIP (2)