Active exploitation is hitting cPanel right now, with more than two thousand attacker IPs racing to drop persistent backdoors on hosting control panels.