CVE-2026-41940 was exploited as a zero-day for 68 days before a patch existed. CISA was breached via Ivanti vulnerabilities it had just ordered patched. Volt Typhoon had 5-year US infrastructure access. The case-by-case record of how government networks keep getting owned.
CVE-2026-48172 in LiteSpeed User-End cPanel Plugin (2.3-2.4.4) lets any authenticated cPanel user run arbitrary scripts as root. CVSS 10.0, actively exploited, on the CISA KEV list. Patch to WHM Plugin 5.3.1.0 / cPanel Plugin 2.4.7 immediately.
Dutch FIOD seized 800 servers on May 22, dismantling Stark Industries and its post-sanctions successor THE.Hosting. The bulletproof host built by brothers from Transnistria hosted NoName057, Sandworm, and the Doppelganger campaign; JA4T fingerprints proved the rebrand was the same hardware.
On May 2, hosting provider 4VPS disclosed a breach of its billing systems. Two days later, The Gentlemen ransomware group's backend appeared for sale online. Check Point Research confirmed the dataset included victim lists, ransom negotiations, and internal communications from one of 2026's most active ransomware operations.