A cPanel auth-bypass flaw is under active exploitation right now, with more than two thousand attacker IPs hammering hosting panels and dropping a Filemanager backdoor that survives patching.