A factual account of the 2026 data breach that destroyed six years of ACJ UNIBEN's published journalism — and what survives.
In early 2026, a critical, widely reported security flaw in cPanel and WHM — the control panel software used by SterkHost and thousands of other hosting providers worldwide — was actively exploited by attackers before a patch was available. The vulnerability allowed unauthenticated remote access to hosting control panels, and was exploited in the wild for roughly two months before an emergency fix was released. Shared hosting environments, where many customer websites run on the same server, were especially exposed during this window. ACJ UNIBEN's website and files were affected during this period. No backup of our site existed at the time, and the loss is complete and irreversible.
The vulnerability at the centre of this incident — tracked as CVE-2026-41940 and assigned the highest possible severity rating of 9.8 — allowed attackers to bypass the cPanel and WHM login system entirely, without needing a valid username or password. According to security researchers, in-the-wild exploitation began as early as February 23, 2026, meaning the vulnerability was being actively abused for roughly two months before an emergency patch was released on April 28, 2026.
In a shared hosting environment — where multiple customer websites run on the same server — a breach at the WHM (Web Host Manager) level gives an attacker administrative access to every account on that server: every website, every database, every file. This is materially different from a single website being hacked. It is an infrastructure-level compromise. ACJ UNIBEN's website, along with its entire six-year publishing archive, was stored on one such shared server.
The US Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-41940 to its Known Exploited Vulnerabilities catalogue on April 30, 2026. Major hosting providers including Namecheap, KnownHost, HostPapa, and InMotion temporarily suspended access to their own cPanel interfaces as an emergency measure while patches were deployed. The scale of exposure was significant: security researchers identified approximately 1.5 million internet-accessible cPanel instances at the time of disclosure.
Every news report, investigation, opinion piece, editorial, and multimedia story published on acjuniben.com from 2020 to early 2026 was lost as a result of this breach. This represents six years of original campus journalism produced by ACJ UNIBEN correspondents, editors, and contributors — work that covered student welfare, university governance, national affairs, press freedom, and the life of UNIBEN's campus community.
The loss also includes our gallery archives, publication files, and all records stored on the server. No backup existed at the time. The reporting itself — the sourcing, the writing, the editing, the verification — cannot be recovered. Only what was independently archived elsewhere survives.
A partial archive of ACJ UNIBEN's published work from 2020 to 2023 is accessible via our legacy WordPress.com platform at acjuniben.wordpress.com. This archive is not complete — it represents the work published during that period on the WordPress.com platform before the primary site was the main publishing outlet — but it is the most intact record of ACJ UNIBEN's early journalism that remains publicly accessible.
We encourage readers, researchers, and archivists to visit that legacy site. We are grateful it exists.
The rebuilt ACJ UNIBEN website operates with regular automated backups stored independently of our hosting server — meaning a breach at the server level cannot destroy our archive a second time. We have moved our site to a clean, patched hosting environment, and we maintain a backup copy of all published content that is not dependent on a single point of infrastructure.
We are also recommitting to the editorial standards that produced the work we lost. The reporting will be rebuilt — story by story, source by source — on this platform, beginning now.
“Losing six years of journalism is not a technical inconvenience. It is the loss of a public record — of stories told, facts established, and accountability exercised on behalf of this campus community. We do not minimise that loss. We acknowledge it on this page, in this form, because transparency is what we ask of others, and we owe it to ourselves. We are still here. The work continues.”