DAILY BRIEFING
cPanel SQL Flaw, N-able KEV Addition, and DOUBLECUP Loader Attacks
Today's briefing covers critical privilege escalation in cPanel, active N-able exploitation, Google AI workflow risks, and DOUBLECUP malware deployment.
5 stories2 min read

Critical infrastructure and host management tools face significant exposure today following active exploitation reports and severe privilege escalation flaws. High-privilege management components continue to present prime targets for lateral movement and system takeover.
System administrators and security teams managing hosting environments or remote monitoring platforms must prioritize patching immediately. Boundary controls around automated bots, CI/CD runners, and client-side execution vectors also require urgent review.
New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root
cPanel patched a critical flaw (CVE-2026-58048) affecting cPanel & WHM and WP Squared. The vulnerability allows authenticated hosting customers with MySQL/MariaDB access to execute database commands with root administrative privileges, potentially leading to full operating-system-level compromise.
- Why it matters
- Web hosting providers and server administrators are exposed to privilege escalation where malicious or compromised tenant accounts can gain full database root access.
- What to do
- Patch cPanel & WHM to version 11.110.0.137, 11.118.0.71, 11.126.0.78, 11.134.0.48, 11.136.0.32, or WP Squared to 138.1.6.
Google Deletes 3 ADK AI Workflows After Malicious GitHub Issue Could Trigger Privileged Agent
Google deleted three AI agent workflows from its Agent Development Kit Python repository after researchers demonstrated how public GitHub issues could manipulate a triage agent to execute privileged actions. The flaw allowed prompt injection to abuse a trusted bot identity for arbitrary code execution in CI runners.
- Why it matters
- Development teams using automated AI agents in CI/CD pipelines are exposed to indirect prompt injection, token exfiltration, and potential compromise of cloud service accounts.
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT
A new Russian loader-as-a-service named DOUBLECUP relies on ClickFix social engineering lures to store steganographic PNG images in browser caches. The hidden payload decrypts CountLoader and a new remote access trojan, DeviceManager, using a custom cipher tied to the victim's public IP.
- Why it matters
- End users on Windows and macOS are vulnerable to stealthy malware delivery that evades detection by caching encrypted payloads in local browser storage.
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises
The U.S.
- Why it matters
- Managed service providers and IT teams using N-able N-central face total administrative takeover, exposing all downstream customer endpoints to unauthorized access.
- What to do
- Update N-able N-central instances immediately to version 2026.3 HF1.
When Vibe Hacking Turns AI into the Junior Hacker Every Adversary Always Wanted
Generative AI is shifting the attacker capability paradigm, allowing lower-skilled threat actors to bridge technical knowledge gaps. Attackers leverage AI to accelerate security research, explain concepts, generate malicious code, troubleshoot execution errors, and adapt public techniques to target environments.
- Why it matters
- Organizations must prepare for an increased volume of sophisticated cyberattacks from less experienced threat actors using AI to enhance their offensive capabilities.
- What to do
- Review defensive postures and threat models to account for a broader range of AI-assisted threat actors.
Key takeaways
- Patch cPanel & WHM immediately to resolve CVE-2026-58048, which allows authenticated users to execute SQL as root.
- Update N-able N-central to version 2026.3 HF1 to mitigate CVE-2026-18577 authentication bypass attempts.