Category: Security

47 articles

Security
A Malware Campaign Is Using GitHub Actions to Hunt Unpatched cPanel Servers
by Natalia Nowak · 24 Jul 2026 · 6 min read
A new campaign uses GitHub's own build servers to hunt cPanel and WHM servers still exposed to CVE-2026-41940, and steal their secrets.
Security
A Once-a-Decade WordPress Core Flaw, and the Gap Between Patched and Safe
by Natalia Nowak · 21 Jul 2026 · 5 min read
WordPress did the rare thing and forced a core security fix to millions of sites. Within 72 hours the break-ins started anyway. The gap is the story.
Security
A 16-Year-Old KVM Escape, and OVHcloud’s Week-Long Patch Across a Million VMs
by Natalia Nowak · 21 Jul 2026 · 6 min read
CVE-2026-53359 let a rented VM seize its host. OVHcloud rebooted around a million VMs in a week to patch it, on its own schedule, not yours.
Security
A Critical Nginx Flaw and Who Is Actually Exposed
by Natalia Nowak · 20 Jul 2026 · 3 min read
F5 patched a critical Nginx flaw (CVSS 9.2) latent since 2011. It only hits specific regex-map configs, and a proof-of-concept exploit is due in early August.
Security
An Unauthenticated Path to Code Execution in WordPress Core, Already Being Exploited
by Łukasz Nowak · 18 Jul 2026 · 8 min read
A flaw in WordPress core hands strangers the keys to your site, no password required, and attackers are already walking through the door. It is already being exploited.
Security
Roundcube’s Zero-Click Webmail XSS, and How Fast It Reached cPanel
by Natalia Nowak · 15 Jul 2026 · 4 min read
Roundcube's zero-click webmail XSS (CVSS 7.2) was patched July 5 and shipped in cPanel 134.0.45 on July 14. Here is what shared hosts should check.
Security
A US Sanction, a Montenegrin Domain, and Why Every t.me Link Went Dark
by Natalia Nowak · 14 Jul 2026 · 4 min read
Every t.me link broke worldwide after the .me registry suspended Telegram's domain, a takedown whose trail leads to a US sanction and an American-run ccTLD.
Security
Januscape and Bad Epoll: Two Linux Flaws That Let One Customer Take Over the Whole Server
by Łukasz Nowak · 11 Jul 2026 · 9 min read
Two Linux kernel flaws, patched the same week, break the multi-tenant promise: one escapes a guest VM to the host, the other hands any local user root.
Security
Three Unauthenticated File Flaws in a Week, and One Root Cause: Validation by Shortcut
by Natalia Nowak · 10 Jul 2026 · 5 min read
In one July week, three unauthenticated file-handling flaws surfaced across WordPress plugins and a web FTP client, all rooted in validation by shortcut.
Security
Hostinger Turns On Patchstack npm Scanning for Node.js Apps by Default
by Natalia Nowak · 8 Jul 2026 · 4 min read
Hostinger built Patchstack's npm dependency scanning into its Node.js hosting, on by default, targeting the supply-chain risk of fast-shipped, AI-assisted apps.
📬

Stay in the loop

Weekly digest of the best hosting news, reviews and industry moves.

🚀

Reach hosting professionals

Sponsor webhosting.today and get in front of hosting buyers, founders and engineers.

50k+monthly readers
632articles
Become a sponsor →