securityonline.info 5/27/2026, 2:03:23 PM · external

Serpens Hackers Exploit CVE-2026-48172, Roll Out New RAT Variants

Serpens Hackers Exploit CVE-2026-48172, Roll Out New RAT Variants

CISA adds LiteSpeed cPanel flaw CVE-2026-48172 to KEV catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the LiteSpeed cPanel Plugin flaw, identified as CVE-2026-48172, to its Known Exploited Vulnerabilities catalog. This critical vulnerability (CVSS score of 10.0) affects versions prior to 2.4.5 and allows privilege escalation to potentially root access. It originates from poor…

First seen 2026-05-23T08:30:29.348Z · Last seen 2026-05-28T10:31:56.592Z

CyberSIXT Evidence Panel
CISA KEV Listed in KEV
Patch Patch Available
Threat Actor
Screening Serpens

THE article discusses a critical cyber espionage campaign linked to the Iranian threat group, Screening Serpens, targeting nations including the U.S., Israel, and the UAE. Recently uncovered vulnerabilities, particularly CVE-2026-48172 associated with the LiteSpeed cPanel Plugin, highlight an urgent need for corporate network administrators to review security protocols. The attackers utilize advanced social engineering tactics, impersonating trusted companies to recruit victims, which leads to initial breaches.

Six new remote access Trojan (RAT) variants have emerged, enhancing the group's capabilities to harvest sensitive data and maintain control over infected networks. To counter these threats, organizations are advised to adapt their defenses, particularly in detecting sophisticated evasion techniques.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline