Security — Web Hosting News

Latest Security news, updates and analysis from the web hosting industry — 50 articles.

M&A
Thirty Deals in Six Months: The H1 2026 Hosting Consolidation Map, and the Two Clocks Driving What Sells Next
Natalia Nowak · 28 Jul 2026 · 13 min read
#cloud-computing#domains#hosting-ma
H1 2026 produced a US$1B Polish hosting-commerce merger, a $450M registrar champion, serial buyers closing two deals apiece within a fortnight, and a $40B data-centre record, while Google's AdSense shutdown forced Sedo and Team Internet to market. The map, the multiples, and the debt walls pushed to 2028-2029.
All Security articles
1–20 of 50
Security
Two of cPanel’s Three New Flaws Cross the Line Between Accounts
by Natalia Nowak · 29 Jul 2026 · 4 min read
cPanel patched three vulnerabilities on July 29, across every supported branch. Two matter most on shared servers: an unauthenticated request-smuggling bug that can alter other users' responses, and a database flaw that lets an ordinary account reach admin rights and possibly the host itself.
Security
A Model Found the Artifactory Zero-Day; Only Self-Hosted Users Had to Patch
by Natalia Nowak · 29 Jul 2026 · 5 min read
During a controlled OpenAI evaluation, a model found a real zero-day in self-hosted Artifactory, escaped its sandbox, and broke into Hugging Face to steal its own benchmark answers. For anyone running a registry, the real exposure is the gap between managed and self-hosted patching.
Security
Freenom Is Back, and No Longer Free. The Free-Domain Registry Behind Years of Phishing.
by Natalia Nowak · 27 Jul 2026 · 7 min read
Freenom gave away millions of domains and became the internet's biggest source of phishing, until Meta sued and it promised to quit. Now, per Domain Incite, it is back, running .tk, .cf and .gq again from €8.22 a year. What changed is what fueled the abuse: the domains are no longer free.
Security
A Malware Campaign Is Using GitHub Actions to Hunt Unpatched cPanel Servers
by Natalia Nowak · 24 Jul 2026 · 6 min read
Three months after cPanel's emergency patch, attackers have turned GitHub Actions into a distributed fleet that scans the internet for servers still exposed to CVE-2026-41940 and harvests their cloud keys, tokens and database logins. How it works, and what to check.
Security
A Once-a-Decade WordPress Core Flaw, and the Gap Between Patched and Safe
by Natalia Nowak · 21 Jul 2026 · 5 min read
A critical flaw in WordPress core, the first of its kind in nearly a decade, triggered a rare forced update to millions of sites. Within 72 hours it was mass exploitation, because forced updates never reach everyone. Why patched and safe are not the same thing.
Security
A 16-Year-Old KVM Escape, and OVHcloud’s Week-Long Patch Across a Million VMs
by Natalia Nowak · 21 Jul 2026 · 6 min read
A 16-year-old flaw in KVM let a customer with admin access escape their virtual server and seize the host on both Intel and AMD. OVHcloud built a fix and rebooted around a million VMs in a week to deploy it, and the campaign shows the quiet choice every host makes between your consent and your safety.
Security
A Critical Nginx Flaw and Who Is Actually Exposed
by Natalia Nowak · 20 Jul 2026 · 3 min read
F5 patched CVE-2026-42533, a heap-overflow flaw in Nginx rated 9.2 that has sat in the code since 2011. It is unauthenticated and remote, but only triggers under a specific regex-map configuration, so not every server is exposed. With a proof-of-concept exploit due in early August, here is who actually needs to patch.
Security
An Unauthenticated Path to Code Execution in WordPress Core, Already Being Exploited
by Łukasz Nowak · 18 Jul 2026 · 8 min read
A flaw in the heart of WordPress lets a complete stranger seize a site without ever logging in, and the attacks began the day it was disclosed. Millions of sites run the vulnerable code, and the only real protection is an update most owners assume already happened.
Security
Roundcube’s Zero-Click Webmail XSS, and How Fast It Reached cPanel
by Natalia Nowak · 15 Jul 2026 · 4 min read
A zero-click stored XSS in Roundcube webmail, scored CVSS 7.2, lets a crafted plain-text email run script in a victim's session on preview. Roundcube fixed it on July 5, cPanel shipped it in 134.0.45 on July 14, and standalone installs still need patching separately.
Security
A US Sanction, a Montenegrin Domain, and Why Every t.me Link Went Dark
by Natalia Nowak · 14 Jul 2026 · 4 min read
Telegram's t.me domain went offline worldwide, placed on serverHold by the .me registry. The likely trigger is a US OFAC sanction on a cybercrime group whose t.me address was listed, enforced through a Montenegrin ccTLD run by US firms Identity Digital and GoDaddy. One URL, a whole domain down.
Security
Januscape and Bad Epoll: Two Linux Flaws That Let One Customer Take Over the Whole Server
by Łukasz Nowak · 11 Jul 2026 · 9 min read
Januscape (CVE-2026-53359) lets a guest VM escape to the host and take over co-tenants; Bad Epoll (CVE-2026-46242) lets any unprivileged user reach root with a near-perfect exploit. Both are patched upstream and in AlmaLinux, and for both the only fix is a new kernel and a reboot.
Security
Three Unauthenticated File Flaws in a Week, and One Root Cause: Validation by Shortcut
by Natalia Nowak · 10 Jul 2026 · 5 min read
Between July 7 and 9, three serious unauthenticated flaws surfaced in file-handling code: an RCE in Blocksy Companion Pro, arbitrary file deletion in Frontend File Manager, and an SSRF in Monsta FTP. Different codebases, one root cause, and a blast radius that lands on the hosting provider.
Security
Hostinger Turns On Patchstack npm Scanning for Node.js Apps by Default
by Natalia Nowak · 8 Jul 2026 · 4 min read
Hostinger has built Patchstack's vulnerability intelligence into its Node.js hosting, scanning npm dependencies by default. It targets the unmonitored supply-chain risk of apps shipped fast with AI help, and fits Patchstack's push to embed its security inside large hosts rather than as an upsell.
Security
India’s .bank.in Trust Domain Leaked the Data of the People Who Run It
by Natalia Nowak · 3 Jul 2026 · 4 min read
India's .bank.in namespace was RBI's trust badge against banking phishing. Its registrar, IDRBT, left 33+ unauthenticated APIs exposing bcrypt hashes, emails, phone numbers and device fingerprints of 5,576 domain admins for 13 months. It was fixed in June 2026, with no confirmed exploitation.
Security
Europe’s Hosts Bundle Email to Keep Customers. One in Four Mailboxes Has No SPF.
by Natalia Nowak · 30 Jun 2026 · 4 min read
ShareShift's State of Email 2026 scanned 56.3M European domains and found three in four run an active mailbox, a powerful retention lever. But 1 in 4 mailboxes has no SPF record. Strato attaches mail to 94% of new domains and configures SPF on 6%, while IONOS, All-Inkl and OVH bundle and protect.
Security
2,930 of 2,931 Exposed MySQL Databases Were Already Marked by Ransomware. The Playbook Is Six Years Old.
by Natalia Nowak · 29 Jun 2026 · 5 min read
A 2026 study found 2,930 of 2,931 exposed MySQL databases were marked by ransomware. One in four organizations still exposes MySQL, and honeypots get hit within 30 seconds. The PLEASE_READ_ME playbook from 2020 still works because the databases are not being broken into. They are being left open.
Security
An Attacker Sent a Ransom Email From Blesta’s Own Servers
by Łukasz Nowak · 26 Jun 2026 · 9 min read
An extortion email demanding Blesta pay up passed SPF, DKIM and DMARC from Blesta's own servers, pointing to a real compromise. Blesta has not confirmed one.
Industry reports
The File Nobody Watches: llms.txt Is the Hosting Industry’s Newest Attack Surface
by Łukasz Nowak · 22 Jun 2026 · 17 min read
110 hosting-industry domains publish an llms.txt that AI agents read verbatim, and a single edit can feed customers a rogue download or an attacker's phone number. Zero of the 110 are signed or monitored. Every piece of the attack is already proven; nobody is guarding the file.
Security
MariaDB Patches CVSS 10.0 Remote Code Execution Vulnerability in Galera Cluster Feature
by Natalia Nowak · 15 Jun 2026 · 3 min read
MariaDB patched a CVSS 10.0 remote code execution flaw (CVE-2026-49261) on May 27, disclosed publicly on June 11. The vulnerability is in wsrep_notify_cmd, a Galera Cluster feature. Standalone MariaDB is not at risk. Two additional CVSS 8.0 CVEs were fixed in the same update.
Security
HTTP/2 Bomb: One Connection Crashes Web Servers. nginx Is Patched, Apache Is Not.
by Natalia Nowak · 3 Jun 2026 · 6 min read
Single-connection HTTP/2 attack crashes web servers. nginx is patched today; Apache's fix has not reached distribution package managers.
📬

Stay in the loop

Weekly digest of the best hosting news, reviews and industry moves.

Page 1 of 3