WPMarbella Oficial

7.7K posts

WPMarbella Oficial banner
WPMarbella Oficial

WPMarbella Oficial

@wpmarbellaorg

Cuenta Oficial de las WordPress Meetup Marbella que se realizan cada mes. http://t.co/yvHMYPjSiY #wpmarbella

Marbella Katılım Ocak 2015
965 Takip Edilen1.1K Takipçiler
WPMarbella Oficial retweetledi
Fernando Tellado Ⓦ
Fernando Tellado Ⓦ@fernandot·
Ojo cuidado esta vulnerabilidad en CPanel y WHM 🫤
International Cyber Digest@IntCyberDigest

🚨 BREAKING: cPanel and WHM, the control panels behind an estimated 70+ million websites, have a critical security flaw that lets anyone become root admin without a password. CVE-2026-41940 affects every supported version. It’s already being exploited in the wild. watchTowr Labs published the full attack today, after the hosting company KnownHost confirmed the bug was already being used to break into a significant chunk of the internet. If you've never heard of cPanel: it's the dashboard that hosting providers and millions of website owners use to manage their servers, domains, email accounts, databases, and SSL certificates. WHM is the admin version that controls the entire server. If someone gets root access to WHM, they get the keys to the kingdom and to every apartment inside it. How the attack works, in plain English: 🔴 Step 1: The attacker sends a deliberately wrong login. cPanel still creates a temporary "you tried to log in" record on disk and gives the attacker a cookie tied to it. 🔴 Step 2: The attacker tweaks the cookie to disable cPanel's password encryption. Normally cPanel encrypts the password field on disk. With one small change to the cookie, cPanel just stores it as plain text instead. 🔴 Step 3: The attacker sends a fake login attempt where the password field secretly contains hidden line breaks. cPanel does not strip these line breaks out, so they get written straight to the session file. Each line break creates a brand new fake record. The attacker uses this to inject lines that say "this user is root" and "this user already authenticated successfully." 🔴 Step 4: The attacker visits one more random page on the site to nudge cPanel into re-reading the file. cPanel then promotes the injected fake lines into its main session memory. 🔴 Step 5: On the next request, cPanel sees a flag that says "this user already passed the password check." cPanel trusts that flag, skips checking the actual password, and lets the attacker in as root. From start to finish, the attack takes a handful of HTTP requests. If you run cPanel or WHM, the patched versions are: 🔴 cPanel/WHM 110.0.x → 11.110.0.97 🔴 cPanel/WHM 118.0.x → 11.118.0.63 🔴 cPanel/WHM 126.0.x → 11.126.0.54 🔴 cPanel/WHM 132.0.x → 11.132.0.29 🔴 cPanel/WHM 134.0.x → 11.134.0.20 🔴 cPanel/WHM 136.0.x → 11.136.0.5 If your version is older than these, assume someone has already broken in and act accordingly. Patch right now, then rotate every password and key the server touched: root passwords, API tokens, SSL private keys, SSH keys, mail passwords, and database passwords.

Español
0
2
6
762
WPMarbella Oficial
WPMarbella Oficial@wpmarbellaorg·
Si eres #WordPresser@ y estás en Andalucía NO te puedes perder esta oportunidad/If you are #WordPresser and are in Andalusía you CANNOT MISS IT: 1⃣ CONOCE al equipo de JETPACK/MEET the JETPACK Team 📅 4-Oct 19:30 h 📌 Higuerón Hotel Málaga (Benalmádena) meetup.com/es-ES/wordpres…
Español
0
1
1
105
WPMarbella Oficial
WPMarbella Oficial@wpmarbellaorg·
Este viernes la Comunidad #WordPress Marbella vuelve a reunirse. Si eres WordPressero y te apetece compartir con otros profesionales, ¡apúntate! Seguro que lo pasas bien y consigues buenos contactos. 🔜 meetup.com/es-ES/wordpres…
WPMarbella Oficial tweet media
Español
0
4
3
0
WPMarbella Oficial retweetledi
Pablo Moratinos 🦊
Pablo Moratinos 🦊@pablomoratinos·
Buen día hoy para pillarse el MultilingualPress o alguna extensión wapa para WooCommerce, como la RedSys Gateway de @josecontic, por ejemplo. Está todo un 40% más barato.
Español
0
5
19
0
WPMarbella Oficial retweetledi
Policía Nacional
Policía Nacional@policia·
🚩URGENTE⚠️ Carmen tiene 13 años y desapareció ayer en #Madrid. Necesita medicación. Si la has visto o tienes cualquier información, llámanos📞: 091, 062, 112. Tu RT no cuesta nada y puede ayudar a encontrarla🙏
Policía Nacional tweet media
Español
37
7.6K
1.8K
0
WPMarbella Oficial retweetledi
mundofunnel 🔥
mundofunnel 🔥@mundofunnel·
¿Cuáles son los mejores plugins para controlar la visibilidad de eidgets y menús en #WordPress? Cómo modificar la visibilidad en: 🔸Menús. 🔸Elementos de menús. 🔸Widgets. Te lo contamos aquí: mundofunnel.pro/wordpress-tecn…
mundofunnel 🔥 tweet media
Español
0
2
2
0
WPMarbella Oficial
WPMarbella Oficial@wpmarbellaorg·
Packagist, GitLab, and GitHubUpdater Plugin Work to Improve Support for Alternative Default Branch Names bit.ly/3dvxT5x
WPMarbella Oficial tweet media
English
0
0
0
0