Category: Security
47 articles
Security
A Malware Campaign Is Using GitHub Actions to Hunt Unpatched cPanel Servers
A new campaign uses GitHub's own build servers to hunt cPanel and WHM servers still exposed to CVE-2026-41940, and steal their secrets.
Security
A Once-a-Decade WordPress Core Flaw, and the Gap Between Patched and Safe
WordPress did the rare thing and forced a core security fix to millions of sites. Within 72 hours the break-ins started anyway. The gap is the story.
Security
A 16-Year-Old KVM Escape, and OVHcloud’s Week-Long Patch Across a Million VMs
CVE-2026-53359 let a rented VM seize its host. OVHcloud rebooted around a million VMs in a week to patch it, on its own schedule, not yours.
Security
A Critical Nginx Flaw and Who Is Actually Exposed
F5 patched a critical Nginx flaw (CVSS 9.2) latent since 2011. It only hits specific regex-map configs, and a proof-of-concept exploit is due in early August.
Security
An Unauthenticated Path to Code Execution in WordPress Core, Already Being Exploited
A flaw in WordPress core hands strangers the keys to your site, no password required, and attackers are already walking through the door. It is already being exploited.
Security
Roundcube’s Zero-Click Webmail XSS, and How Fast It Reached cPanel
Roundcube's zero-click webmail XSS (CVSS 7.2) was patched July 5 and shipped in cPanel 134.0.45 on July 14. Here is what shared hosts should check.
Security
A US Sanction, a Montenegrin Domain, and Why Every t.me Link Went Dark
Every t.me link broke worldwide after the .me registry suspended Telegram's domain, a takedown whose trail leads to a US sanction and an American-run ccTLD.
Security
Januscape and Bad Epoll: Two Linux Flaws That Let One Customer Take Over the Whole Server
Two Linux kernel flaws, patched the same week, break the multi-tenant promise: one escapes a guest VM to the host, the other hands any local user root.
Security
Three Unauthenticated File Flaws in a Week, and One Root Cause: Validation by Shortcut
In one July week, three unauthenticated file-handling flaws surfaced across WordPress plugins and a web FTP client, all rooted in validation by shortcut.
Security
Hostinger Turns On Patchstack npm Scanning for Node.js Apps by Default
Hostinger built Patchstack's npm dependency scanning into its Node.js hosting, on by default, targeting the supply-chain risk of fast-shipped, AI-assisted apps.
Reach hosting professionals
Sponsor webhosting.today and get in front of hosting buyers, founders and engineers.
50k+monthly readers
632articles