• News/
  • https://www.bleepingcomputer.com/news/security/massive-psaux-ransomware-attack-targets-22-000-cyberpanel-instances/

Massive PSAUX ransomware attack targets 22,000 CyberPanel instances

BleepingComputer
·
Lawrence Abrams
·
Published Oct 29, 2024
·
Updated

Article updated to add information from CyberPanel developer and with information on free decryptor. Over 22,000 CyberPanel instances exposed online to a critical remote code execution (RCE) vulnerability were mass-targeted in a PSAUX ransomware attack that took almost all instances offline. This week, security researcher DreyAnd disclosed that CyberPanel 2.3.6 (and likely 2.3.7) suffers from three distinct security problems that can result in an exploit allowing unauthenticated remote root access without authentication. Specifically, the researcher uncovered the following problems on CyberPanel version 2.3.6: The researcher, DreyAnd, developed a proof-of-concept exploit to demonstrate root-level remote command execution on the server, allowing him to take complete control of the server. DreyAnd told BleepingComputer that he could only test the exploit on version 2.3.6 as he did not have access to the 2.3.7 version at the time. However, as 2.3.7 was released on September 19, before the bug was found, it was likely impacted as well. The researcher said they disclosed the flaw to the CyberPanel developers on October 23, 2024, and a fix for the authentication issue was submitted later that evening on GitHub. After publication of this story, CyberPanel creator Usman Nasir told BleepingComputer that version 2.3.8 was released and the bug fixed within thirty minutes of receiving the security disclosure. Nasir says his team has been busy helping people with the upgrade and breaches...

Read full article

Affected Software

1 affected component
CyberPanel CyberPanel=2.3.6, >=2.3.6<=2.3.7
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a massive PSAUX ransomware attack that affected over 22,000 CyberPanel instances.

2

What security implications are discussed in the article?

The article highlights the critical remote code execution vulnerability that exposed CyberPanel instances to the ransomware attack.

3

What products or software are affected in this situation?

The affected software is CyberPanel, used for managing web hosting and servers.

4

How did the ransomware attack impact CyberPanel instances?

The attack caused almost all targeted CyberPanel instances to go offline.

5

Is there any solution mentioned for the ransomware attack?

Yes, the article mentions that there is a free decryptor available for affected users.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203