Attackers have targeted the zero-day VML vulnerability on an unknown number of Windows-based machines, using a layered approach that first involved exploiting a hole in cpanel, an application that's popular with Web hosting services.
Criminals spread Windows exploit via Web host
Criminals spread Windows exploit via Web host