A critical CRLF injection vulnerability (CVSS 9.8) in cPanel/WHM authentication was exploited within 24 hours of disclosure, compromising at least 44,000 IP addresses. Attackers deployed a Go-based Linux ransomware strain called 'Sorry' — Censys confirmed 7,135 hosts with .sorry artifacts. Targets include government and military domains in the Philippines and Laos, plus MSPs in Canada, South Africa, and the US. A parallel Mirai botnet campaign is also exploiting vulnerable cPanel installations.