Article updated to add information from CyberPanel developer and with information on free decryptor. Over 22,000 CyberPanel instances exposed online to a critical remote code execution (RCE) vulnerability were mass-targeted in a PSAUX ransomware attack that took almost all instances offline. This week, security researcher DreyAnd disclosed that CyberPanel 2.3.6 (and likely 2.3.7) suffers from three distinct security problems that can result in an exploit allowing unauthenticated remote root access without authentication. Specifically, the researcher uncovered the following problems on CyberPanel version 2.3.6: The researcher, DreyAnd, developed a proof-of-concept exploit to demonstrate root-level remote command execution on the server, allowing him to take complete control of the server. DreyAnd told BleepingComputer that he could only test the exploit on version 2.3.6 as he did not have access to the 2.3.7 version at the time. However, as 2.3.7 was released on September 19, before the bug was found, it was likely impacted as well. The researcher said they disclosed the flaw to the CyberPanel developers on October 23, 2024, and a fix for the authentication issue was submitted later that evening on GitHub. After publication of this story, CyberPanel creator Usman Nasir told BleepingComputer that version 2.3.8 was released and the bug fixed within thirty minutes of receiving the security disclosure. Nasir says his team has been busy helping people with the upgrade and breaches...
Massive PSAUX ransomware attack targets 22,000 CyberPanel instances
BleepingComputer
·Lawrence Abrams
·Published Oct 29, 2024
·Updated
Affected Software
1 affected component
CyberPanel CyberPanel=2.3.6, >=2.3.6<=2.3.7
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a massive PSAUX ransomware attack that affected over 22,000 CyberPanel instances.
2
What security implications are discussed in the article?
The article highlights the critical remote code execution vulnerability that exposed CyberPanel instances to the ransomware attack.
3
What products or software are affected in this situation?
The affected software is CyberPanel, used for managing web hosting and servers.
4
How did the ransomware attack impact CyberPanel instances?
The attack caused almost all targeted CyberPanel instances to go offline.
5
Is there any solution mentioned for the ransomware attack?
Yes, the article mentions that there is a free decryptor available for affected users.