PT-2026-88179 · Webpros · Cpanel
CVE-2026-67401
·
Published
2026-09-08
·
Updated
2026-09-11
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
🔒 CYBERSECURITY, PRIVACY & OPEN SOURCE ROUNDUP — September 9, 2026
1️⃣ CPANEL EMAILTRACK SQL INJECTION LEADS TO ROOT
A critical flaw in cPanel (CVE-2026-67401) turns the EmailTrack feature into a full remote-code-execution path: a regular authenticated cPanel account with mail privileges can abuse the SQL injection to create arbitrary files on the server, from which attackers reach code execution and ultimately root access. All supported cPanel versions are reportedly affected — if you run cPanel/WHM, the community advice is to check your build and patch immediately.
🔹 @thecybersecguru
2️⃣ HUNDREDS OF AI AGENTS RUN A CAMPAIGN AGAINST PAPERCUT NG/MF
GreyNoise published a detailed analysis of an AI-orchestrated campaign against PaperCut NG/MF, powered by hundreds of AI agents. The operation shows just how far agentic attacks have come — and where their limits still lie. A useful read for anyone running internet-exposed print servers, and a preview of what routine infrastructure scanning may look like.
🔹 @GreyNoiseIO
3️⃣ GERMAN POLICE READ "ENCRYPTED" CHATS THROUGH LEGITIMATE DEVICES
German investigations show that authorities can access WhatsApp, Telegram or Signal communications without breaking the encryption — by using legitimate app features to link a device the suspect is already authorized on. In one case, investigators activated WhatsApp Web from the suspect's own phone. In another, they retrieved older Telegram messages. In 2026, Germany's Federal Court of Justice ruled that covert access to older chats requires stricter legal safeguards. The encryption held; the authorized device did not.
🔹 @ULTIMAHORAENX
4️⃣ LG TVS SCAN HOME NETWORKS AND TRANSCRIBE STANDBY AUDIO IN PLAIN TEXT
A new 500-hour, $70,000 investigation by Gamers Nexus and Level1Techs claims LG TVs scan home networks and generate plain-text transcripts of audio captured while in standby — even offline — and upload everything once the TV reconnects. It follows the December 2025 Texas lawsuit over hidden screen tracking and LG's May 2026 settlement. LG denies the new claims, and the Texas case never got the chance to ask about the microphones.
🔹 @dataexplain
5️⃣ BIMO: AN OPEN-SOURCE 1.6 KG BIPEDAL ROBOT FOR RL WALKING
Mekion's Bimo project gives researchers, developers and makers a small (~45 cm) open-source biped they can actually train to walk: 8 servo motors, a 9-DOF IMU, four ToF sensors, two wide-FOV cameras and an RP2040 controller. It ships with a Python API and an Isaac Lab environment for training reinforcement-learning walking policies in simulation, plus a built-in CPG gait if you just want it moving quickly. A complete sim-to-real stack.
🔹 @Alacritic Super
6️⃣ QTFY: THE US MAPS A CHINA-LINKED HACKER GROUP'S CORPORATE WEB
The US advisory identifying the China-linked QTFY hacker group and its reported ties to a network of Chinese cybersecurity companies keeps expanding. New analysis widens the circle to two more firms — Elextec Cybersecurity (ELEX) and Nanjing Lexbell — and points to additional evidence of ties to China's military and security agencies. A reminder that in certain supply chains, the vendor itself can be the attack surface.
🔹 @eubenincasa
7️⃣ AUK, THE "NANO BANANA FOR AUDIO," GOES OPEN SOURCE
AuK, a unified foundation model for speech generation and editing, has just been open-sourced. The team describes it as the "nano banana" for audio — a single model that handles both generating and editing speech, already available on the project's site and via its Hugging Face paper.
🔹 @ddlbojack
💭 The common thread today: the weakest link is rarely the algorithm. Hundreds of AI agents can now run infrastructure campaigns at machine speed, police can read "encrypted" chats through devices the suspect already owns, and a plain SQL injection in a mail-tracking feature can still hand attackers root on one of the most common server control panels. Meanwhile, the open-source world keeps shipping complete, usable stacks — from bipedal robots you can teach to walk to foundation models for audio.
Where would you spend your next hour of defensive work: patching the boring legacy software, or auditing what is already logged in? 👇
#CyberSecurity #Privacy #OpenSource
Fix
RCE
LPE
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cpanel