In today’s cybersecurity news… Critical cPanel and WHM bug exploited as zero-day Experts are warning about a critical CVE numbered (CVE-2026-41940) authentication bypass vulnerability in cPanel, a Linux-based web hosting control panel, as well as WHM, and WP Squared. The bug is being actively exploited in the wild. Hosting provider KnownHost, which uses cPanel, said it noticed successful exploits in the wild on the very day the vulnerability was disclosed. cPanel released a fix on Tuesday, after receiving pressure from hosting providers. According to Rapid7, “Shodan internet scans show that there are approximately 1.5 million cPanel instances exposed online,” but there is no data on how many are vulnerable to this particular bug. Swiss police arrest suspected members of Black Axe group The arrests, made in conjunction with German police, followed house searches across several Swiss cantons. The 10 suspects, believed to be members of the Nigerian gang are aged between 32 and 54, are accused of carrying out romance scams and money-laundering operations. The gang itself, Black Axe, is regarded by law enforcement as “a highly structured transnational criminal organization with a global presence.” Authorities “believe the group has about 30,000 registered members worldwide” and describe it as highly organized. HHS ponders government posture for protecting data centers The question revolves around whether to designate data centers as a standalone critical infrastructure sector. Given that they are regularly targeted, a hearing was held Wednesday to contemplate whether the federal government currently has the right setup for defending them. “Some industry witnesses and experts at the hearing of the House Homeland Security Subcommittee on Cybersecurity and Infrastructure Protection suggested that data centers be given their own standalone designation, especially in light of the boom in the building of such facilities across the country. This would follow a move already taken