Nginx Just Patched old Rewrite Module Flaw. RCE Was Possible With a Single HTTP Request.

A flaw sitting in nginx since 2008 was patched on May 13, 2026. CVSS 9.2, unauthenticated, and present in the default rewrite module.

HOSTAFRICA Acquires Zanode, Its Second South African Deal in Nine Days

HOSTAFRICA announced the acquisition of Zanode on May 14, 2026, nine days after acquiring Evoweb's hosting division, adding a South African git-driven deployment platform to its African hosting portfolio.

A Compromised Server Is the Beginning. Here Is What Breach Law Requires Next.

Change Healthcare's $3.1 billion in breach costs is the new normal of what a serious compromise sets in motion: parallel notification clocks across GDPR, NIS2, DORA, and HIPAA; personal liability for CISOs and boards; and a cyber insurance market with conditions that can deny coverage at the worst moment.

cPanel Is Patching Three New CVEs Today. Technical Details Come With the Fix.

Three new cPanel vulnerabilities, CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203, are being patched today at 12:00pm EST, with technical details withheld until the fix is live.

DirtyFrag: Any User Account Can Become Root on Most Linux Servers. The Exploit Is Public. There Is No Patch.

DirtyFrag, a Linux kernel local privilege escalation that gives any local user root access on Ubuntu, RHEL, Fedora, CentOS Stream, AlmaLinux, and openSUSE Tumbleweed, went fully public on May 8 after an embargo break, with no CVE assigned and no patches available for any affected distribution.

CVE-2026-41940 Live: cPanel Authentication Bypass, Active Exploitation, and What Comes Next

CVE-2026-41940, the cPanel authentication bypass exploited for 64 days before disclosure, is still developing. 44,000 servers likely compromised, a public exploit on GitHub, three active campaigns. This page is updated in real time as new information surfaces.

The cPanel Zero-Day Was Active for 64 Days Before Anyone Knew

CVE-2026-41940, the cPanel authentication bypass from April 28, was being exploited since February 23, operated as a zero-day for 64 days, and was added to CISA's Known Exploited Vulnerabilities list with 1.5 million internet-exposed instances counted by Rapid7.

Copy Fail: Any Local User Can Get Root on Nearly Every Linux System Since 2017

Copy Fail (CVE-2026-31431) is a Linux kernel privilege escalation giving any unprivileged local user root access, affecting virtually all distributions since 2017, with shared hosting and multi-tenant environments at highest risk.

Mullenweg Calls WordPress “Mediocre Crap” and Overrules Core Committers on 7.0

Matt Mullenweg called WordPress development "boring or mediocre crap," then overruled core committers to add Akismet to the WordPress 7.0 Connectors screen, weeks before the May 20 release.

HostPapa Acquires Hostwinds, Adding Seattle and Amsterdam Infrastructure in Its Second Acquisition This Month

HostPapa acquired Hostwinds on April 29, adding self-owned data centers in Seattle and Amsterdam and a developer and reseller customer base to its portfolio, twelve days after acquiring Tailor Made Servers in Dallas.