Category: Security
58 articles
Security
The Hypervisor Escape Comes to VMware: CVE-2026-47876 May Let a Guest VM Run Code on the ESX Host
A critical VMware flaw may let a guest VM run code on the ESX host, and Broadcom ships no workaround for it.
Security
WordPress 7.0.4 Fixes a PNG That Runs Code. The Flaw Was Almost 10 Years Old.
WordPress 7.0.4 fixes a flaw where an image hiding PostScript runs code on the server. It needs an author account, and multi-author sites should hurry.
Security
Metabase Cloud Customers Were Patched Before They Knew. Self-Hosted Users Had to Do It Themselves.
A CVSS 10 flaw let attackers become Metabase admins without logging in. Cloud instances were patched by the vendor. Self-hosted ones were not.
Security
Cloudflare Reached FedRAMP High Without Building a Separate Government Cloud
Cloudflare for Government reached FedRAMP High on the same public network that serves everyone else. The Class D label is ahead of FedRAMP's calendar.
Security
Zapscape Breaks the Linux KVM Boundary. A Server Without a Single VM Can Still Be in Range.
Zapscape lets one tenant break out and take over the whole Linux server. A box running no VMs at all can still be in range.
Security
Roundcube Shipped Eleven Security Fixes Without a Single CVE Number
Roundcube patched eleven flaws in 1.7.3 and 1.6.18. The notes carry no CVE numbers, and cPanel has not shipped the update yet.
Security
An AI Model Found the WordPress Flaw in Ten Hours for $25. Attackers Weaponized the Patch in Ninety Minutes.
An AI model found the WordPress core flaw in ten hours for about $25. After 7.0.2 shipped, attacks started 90 minutes later. WordPress 7.0.3 is out.
Security
N-able’s First Patch Left the Door Open, and Attackers Walked Back Through It
N-able's first fix missed a second route to the same flaw. Attackers are using it, and the new hotfix does not remove what they left behind.
Security
Two of cPanel’s Three New Flaws Cross the Line Between Accounts
cPanel's July 29 patch fixes three flaws. Two cross the boundary between accounts on a shared server, one without any login at all.
Security
A Model Found the Artifactory Zero-Day; Only Self-Hosted Users Had to Patch
An OpenAI model exploited a real Artifactory zero-day, escaped its eval sandbox, and stole its own benchmark answers from Hugging Face.
Reach hosting professionals
Sponsor webhosting.today and get in front of hosting buyers, founders and engineers.
50k+monthly readers
665articles