Michaela Stranovská retweetledi

🚨 BREAKING: Hackers are now exploiting the cPanel authentication bypass flaw (CVE-2026-41940) to deploy "Sorry" ransomware on compromised websites.
Numerous sources say attacks began Thursday, with threat actors breaching servers and deploying a Go-based Linux encryptor that appends the .sorry extension to files.
What the ransomware does:
🔴 Encrypts files and appends the ".sorry" extension.
🔴 Protects the encryption key with an embedded RSA-2048 public key
🔴 Drops a README.md ransom note in every folder
🔴 Uses a fixed Tox ID for ransom negotiations
Victims are being instructed to contact the attacker via Tox to pay for decryption.
This is not related to the older 2018 HiddenTear ".sorry" ransomware. This is a new, Linux-targeting encryptor tied directly to active cPanel exploitation.
If you're running cPanel or WHM, patch immediately.


English




























