GoDaddy’s Multi-Year cPanel Breach: 2.5 Years of Dwell
GoDaddy’s 2023 filing admitted intermittent intruder access since 2020, malware in cPanel servers, and email interception affecting ~6.95M customers.
GoDaddy’s 2023 filing admitted intermittent intruder access since 2020, malware in cPanel servers, and email interception affecting ~6.95M customers.
Five threat streams converged in May 2026: the actively exploited Ivanti EPMM zero-day, a fake OpenAI repo on Hugging Face dropping infostealers, cPanel CVEs reaching CVSS 8.8, TCLBANKER worming through WhatsApp and Outlook, and ShinyHunters hitting Canvas LMS. One briefing, one action plan.
CVE-2026-41940 let unauthenticated attackers bypass cPanel/WHM/Webmail logins entirely — exploits hit before the patch existed. Ports 2082-2096 went dark industry-wide within the hour. Patched versions, response timeline, and audit steps inside.