Author: Natalia Nowak
209 articles
Exploring the web hosting industry through writing - panels, providers, and everything that runs behind the scenes.
Security
cPanel Patches a Root Escalation That Starts From an Ordinary Hosting Account
An authenticated cPanel account holder could run code as root through CalDAV and CardDAV. Three builds carry the fix, dated September 22.
Industry reports
ICANN Confirms 1,616 gTLD Applications Proceed. Reveal Day Expected by October 14.
ICANN confirms 1,616 of 1,663 gTLD applications proceed after payment, with Reveal Day due by October 14 and the exact date still a week away.
Software reviews
Ask nginx Which Config It Is Running. Not Every Build Will Answer.
nginx 1.31.5 adds a REST interface that reads the running config and grades every reload. Whether a server has it is settled at build time.
Other
GitHub, Salesforce and SharePoint Went Down in Four Days. Nobody Attacked Them.
GitHub, Salesforce and SharePoint each lost core functions in four days, and each company's own account blames an internal change, not an attack.
Security
WordPress 7.1.1 Fixes a Comment-Form XSS. The Payload Passes the Sanitizer.
WordPress 7.1.1 was planned as bug-fix only and shipped with 11 security fixes, one an anonymous comment XSS the sanitizer does not catch.
Security
A Critical libheif Bug Reachable Through WordPress Uploads Still Has No CVE
A CVSS 9.8 flaw sits under WordPress photo uploads, in a system library the host has to patch. Twenty days after the fix, it has no CVE number.
Security
Three LiteSpeed Security Builds in Six Days: Check Which One Your Servers Run
LiteSpeed Enterprise 6.3.7 shipped three security builds in six days, after a cPanel advisory on a root path from a hosting account. Build 2 is the one to run.
Industry reports
AWS Cannot Restore Access to Data Kept Only in Bahrain or One UAE Zone
AWS cannot restore access to data hosted exclusively in its Bahrain region, or in one of three UAE zones. Most customers had already moved out.
Security
Acronis cPanel Backup Plugin: Exploited Privilege-Escalation Flaw on CISA’s List
Acronis patched a privilege-escalation flaw in its cPanel backup plugin and reports limited attacks. CISA listed it with a September 19 deadline.
M&A
Before the Press Release: What We See in Hosting M&A
Many owners asking what their hosting business is worth have not decided to sell. The busier part of the market comes before any deal is announced.
Reach hosting professionals
Sponsor webhosting.today and get in front of hosting buyers, founders and engineers.
50k+monthly readers
731articles