Author: Łukasz Nowak

82 articles
Nearly two decades in IT. A decade in web hosting - and still in the trenches. Writing about the infrastructure that runs the internet from the inside.

Industry reports
ICANN Meets June 8. One Proposal Could Force Registrars to Investigate Every Customer Tied to a Single Abuse Report.
by Łukasz Nowak · 4 Jun 2026 · 7 min read
ICANN is debating a rule that would require registrars to investigate every domain from a customer when one is flagged for abuse. Seville (June 8-11) is where that debate begins in earnest. The gTLD window closes August 12.
Other
SoftBank Pledged €75 Billion to Build AI Data Centers in France.
by Łukasz Nowak · 4 Jun 2026 · 9 min read
SoftBank's €45B firm commitment and €75B ceiling for AI data centers in France drove Choose France 2026 to a record €93B total. France's nuclear grid is the structural advantage. SoftBank's balance sheet is the open question.
Security
A Database Allegedly From Home.pl Is Being Advertised on a Cybercrime Forum.
by Łukasz Nowak · 29 May 2026 · 8 min read
A dataset allegedly from Home.pl, Poland's largest hosting provider, is being advertised on a cybercrime forum. We analyze the schema and what it means for 300,000+ customers.
M&A
your.online Acquires Sansec, Adding E-Commerce Security to a 60-Acquisition Group
by Łukasz Nowak · 14 May 2026 · 3 min read
your.online has acquired Sansec, a Magento and WooCommerce security company, marking the Dutch hosting group's first move into specialist e-commerce security tooling.
Security
Fragnesia: A New Linux Kernel Privilege Escalation That Emerged From Prior Kernel Patches
by Łukasz Nowak · 14 May 2026 · 3 min read
William Bowling of V12 Security disclosed Fragnesia on May 13, 2026, a Linux kernel privilege escalation that allows an unprivileged local attacker to reach root by corrupting the kernel page cache through the XFRM ESP-in-TCP subsystem.
Security
Nginx Just Patched old Rewrite Module Flaw. RCE Was Possible With a Single HTTP Request.
by Łukasz Nowak · 14 May 2026 · 6 min read
A flaw sitting in nginx since 2008 was patched on May 13, 2026. CVSS 9.2, unauthenticated, and present in the default rewrite module.
M&A
HOSTAFRICA Acquires Zanode, Its Second South African Deal in Nine Days
by Łukasz Nowak · 14 May 2026 · 3 min read
HOSTAFRICA announced the acquisition of Zanode on May 14, 2026, nine days after acquiring Evoweb's hosting division, adding a South African git-driven deployment platform to its African hosting portfolio.
Security
A Compromised Server Is the Beginning. Here Is What Breach Law Requires Next.
by Łukasz Nowak · 13 May 2026 · 35 min read
Change Healthcare's $3.1 billion in breach costs is the new normal of what a serious compromise sets in motion: parallel notification clocks across GDPR, NIS2, DORA, and HIPAA; personal liability for CISOs and boards; and a cyber insurance market with conditions that can deny coverage at the worst moment.
Security
cPanel Is Patching Three New CVEs Today. Technical Details Come With the Fix.
by Łukasz Nowak · 8 May 2026 · 3 min read
Three new cPanel vulnerabilities, CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203, are being patched today at 12:00pm EST, with technical details withheld until the fix is live.
Security
DirtyFrag: Any User Account Can Become Root on Most Linux Servers. The Exploit Is Public. There Is No Patch.
by Łukasz Nowak · 8 May 2026 · 7 min read
DirtyFrag, a Linux kernel local privilege escalation that gives any local user root access on Ubuntu, RHEL, Fedora, CentOS Stream, AlmaLinux, and openSUSE Tumbleweed, went fully public on May 8 after an embargo break, with no CVE assigned and no patches available for any affected distribution.
📬

Stay in the loop

Weekly digest of the best hosting news, reviews and industry moves.

🚀

Reach hosting professionals

Sponsor webhosting.today and get in front of hosting buyers, founders and engineers.

50k+monthly readers
745articles
Become a sponsor →