Category: Security
67 articles
Security
Nearly Two-Thirds of All-in-One WP Migration Installs Remain Unpatched Two Weeks Later
Only 35 percent of All-in-One WP Migration installs run the 7.110 fix. About 3.2 million sites are on a vulnerable version as the exploit chain goes public.
Security
Attacks on the Elementor Pro Flaw Began the Day It Was Disclosed
Exploit attempts against the Elementor Pro file upload flaw began the day it was disclosed, and one firewall alone blocked over 190,000 of them.
Security
A High-Severity Patch for Five Million WordPress Sites Was Labeled as a Text Fix
High-severity fixes for All-in-One WP Migration and Gravity Forms shipped August 20. One changelog called it a text fix, the other used a stock phrase.
Security
An Attacker Hijacked Hetzner IP Space and Poisoned a Virtualizor Update
An attacker hijacked routes to Softaculous servers for two nights, got a valid TLS certificate, and delivered a malicious update to some Virtualizor installs.
Security
cPanel Patches a Root-Level Flaw in Domain Parking: One Customer Account With Domain Permissions Was Enough
A cPanel customer able to add parked domains could gain root on the whole server. CVE-2026-65643 affects all supported versions; patches are out.
Security
InMotion Rolls Out Monarx ThreatShield Inside the PHP Engine Across Its Fleet
InMotion is deploying Monarx ThreatShield across its server fleet, moving attack blocking into the PHP engine itself.
Security
Plesk Patches Three Flaws That Start From an Ordinary Customer Account
Plesk has patched three flaws reachable from an ordinary customer account. The worst can end at root, and its fix ships outside the core update.
Security
Researchers Found Six Major CDNs Vulnerable to New HTTP/3 Attacks. Two Deployed Mitigations.
ix major CDNs amplify attacker traffic toward the sites they front. Two have deployed mitigations, four are still discussing it.
Security
Forminator’s 9.8 Flaw, and Eleven More Fixes in Nineteen Days
Forminator's 9.8 file upload flaw was patched seventeen days before it went public, and the changelog shows eleven more fixes around it.
Security
The Hypervisor Escape Comes to VMware: CVE-2026-47876 May Let a Guest VM Run Code on the ESX Host
A critical VMware flaw may let a guest VM run code on the ESX host, and Broadcom ships no workaround for it.
Reach hosting professionals
Sponsor webhosting.today and get in front of hosting buyers, founders and engineers.
50k+monthly readers
698articles