Security — Web Hosting News

Latest Security news, updates and analysis from the web hosting industry — 79 articles.

Other
Automattic Is Not an Owner of the WordPress Marks It Asserted in Court, a Judge Rules
Natalia Nowak · 29 Sep 2026 · 6 min read
#automattic#web-hosting#wordpress
The September 24 order brings back four antitrust claims the same judge had dismissed in an earlier ruling. It also holds that Automattic and Mullenweg are neither owners nor registrants of the WordPress marks, so they cannot assert them in their own right.
All Security articles
61–79 of 79
Security
cPanel Is Patching Three New CVEs Today. Technical Details Come With the Fix.
by Łukasz Nowak · 8 May 2026 · 3 min read
Three new cPanel vulnerabilities, CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203, are being patched today at 12:00pm EST, with technical details withheld until the fix is live.
Security
DirtyFrag: Any User Account Can Become Root on Most Linux Servers. The Exploit Is Public. There Is No Patch.
by Łukasz Nowak · 8 May 2026 · 7 min read
DirtyFrag, a Linux kernel local privilege escalation that gives any local user root access on Ubuntu, RHEL, Fedora, CentOS Stream, AlmaLinux, and openSUSE Tumbleweed, went fully public on May 8 after an embargo break, with no CVE assigned and no patches available for any affected distribution.
Security
Apache 2.4.67 Patches 11 CVEs. One Is RCE. One Hits Shared Hosting.
by Natalia Nowak · 5 May 2026 · 5 min read
Apache 2.4.67, released May 4, patches 11 CVEs including a CVSS 8.8 HTTP/2 remote code execution flaw and a shared hosting privilege escalation that lets customers read each other's files.
Security
CVE-2026-41940 Live: cPanel Authentication Bypass, Active Exploitation, and What Comes Next
by Łukasz Nowak · 4 May 2026 · 13 min read
CVE-2026-41940, the cPanel authentication bypass exploited for 64 days before disclosure, is still developing. 44,000 servers likely compromised, a public exploit on GitHub, three active campaigns. This page is updated in real time as new information surfaces.
Security
The cPanel Zero-Day Was Active for 64 Days Before Anyone Knew
by Łukasz Nowak · 3 May 2026 · 9 min read
CVE-2026-41940, the cPanel authentication bypass from April 28, was being exploited since February 23, operated as a zero-day for 64 days, and was added to CISA's Known Exploited Vulnerabilities list with 1.5 million internet-exposed instances counted by Rapid7.
Security
Copy Fail: Any Local User Can Get Root on Nearly Every Linux System Since 2017
by Łukasz Nowak · 1 May 2026 · 4 min read
Copy Fail (CVE-2026-31431) is a Linux kernel privilege escalation giving any unprivileged local user root access, affecting virtually all distributions since 2017, with shared hosting and multi-tenant environments at highest risk.
Security
cPanel Had an Authentication Bypass. Exploits Were Already in the Wild.
by Łukasz Nowak · 29 Apr 2026 · 5 min read
cPanel disclosed a critical authentication bypass on April 28 affecting nearly all versions of cPanel and WHM, with active exploits confirmed in the wild before the patch was released, forcing hosting.com, Namecheap, KnownHost, HostPapa, and InMotion Hosting to take cPanel access offline globally.
Security
Four Tiers of OpenClaw Hosting. Three Have a Security Problem.
by Natalia Nowak · 28 Apr 2026 · 8 min read
The market for running OpenClaw splits cleanly into providers that have made it accessible and providers that have made it secure, and those are currently different products at different price points.
Security
Vercel Confirmed Unauthorized Access to Its Internal Systems. A Threat Actor Is Offering the Stolen Data for $2 Million.
by Łukasz Nowak · 19 Apr 2026 · 5 min read
Vercel confirmed unauthorized access to its internal systems on April 19, 2026, while a threat actor claiming affiliation with ShinyHunters posted on BreachForums offering to sell the alleged dataset including GitHub tokens, NPM tokens, API keys, and source code for $2 million.
Security
Flippa Promoted the Plugin Portfolio Sale as a Success Story. It Was a Supply Chain Attack.
by Łukasz Nowak · 17 Apr 2026 · 6 min read
Flippa celebrated the six-figure sale of the Essential Plugin portfolio; eight months later the buyer activated a backdoor across 20,000+ WordPress sites using Googlebot cloaking and a C2 routed through an Ethereum smart contract.
Security
Turning Challenges into Revenue Opportunities: How PRO Hacked Site Repair Services Can Reduce Churn for Agencies and Web Hosts
by Akshay Kumar · 16 Apr 2026 · 6 min read
Website hacks are no longer rare incidents. They are a growing operational challenge for web hosts and digital agencies. When a client’s site gets compromised, the immediate expectation is clear: fast resolution
Other
Let’s Encrypt Changes Its Root Certificates on May 13. Client Auth Ends July 8
by Natalia Nowak · 15 Apr 2026 · 7 min read
Let's Encrypt issues approximately ten million certificates per day and is closing in on protecting one billion websites, making its May 13 root certificate switch a change that affects the majority of SSL certificates in any hosting provider's customer base. The two deadlines that require immediate action are May 13, when renewal automation must be verified to handle future shorter lifetimes correctly, and July 8, when client authentication certificates issued by Let's Encrypt stop working entirely. Providers whose automation relies on acme.sh face an additional gap: acme.sh does not yet support ACME Renewal Information (RFC 9773), the mechanism that lets Let's Encrypt communicate renewal windows directly to clients.
Security
World Backup Day 2026: The Threat Model Has Changed. The Advice Has Not.
by Łukasz Nowak · 31 Mar 2026 · 7 min read
Cloudflare's 2026 Threat Report describes attackers who log in rather than break in, using stolen session tokens that bypass MFA entirely. On World Backup Day, the question worth asking is not whether you have a backup, but whether the attacker who logged into your environment three weeks ago has already found it.
Security
European Commission Confirms AWS Account Breach: A Customer-Side Failure With EU Cloud Sovereignty Implications
by Łukasz Nowak · 30 Mar 2026 · 6 min read
The European Commission confirmed attackers accessed its AWS-hosted Europa.eu infrastructure and took data. AWS says its platform was not the issue, the customer account configuration was.
Security
AI Crawlers Are Eating Your Bandwidth: How Hosting Companies Are Fighting Back
by Łukasz Nowak · 20 Mar 2026 · 13 min read
Cloudflare blocks AI bots by default and is testing a pay-per-crawl model. SiteGround silently filters training crawlers at the server level. IONOS rate-limits AI agents on shared hosting. As AI crawler traffic surges, hosting providers are splitting into those who have acted and those who have not - and the gap is becoming a competitive differentiator.
#ai
Security
New Cybersecurity Laws Across Asia: What Hosting Providers Must Do to Stay Compliant in 2026
by Łukasz Nowak · 18 Mar 2026 · 8 min read
China's amended Cybersecurity Law, Hong Kong's first critical infrastructure statute, and Singapore's expanded compliance framework have all taken effect. For hosting businesses operating in the region, the compliance cost of inaction is now measured in millions.
Security
Ransomware, Source Code Leaks, and the SOC Outsourcing Wave: Asia’s Hosting Security Landscape in Early 2026
by Łukasz Nowak · 17 Mar 2026 · 5 min read
High-profile breaches in South Korea, a near-universal shift toward outsourced security operations in Vietnam, and an evolving ransomware threat profile are defining the security reality for Asian hosting providers this quarter.
Security
Webhosting.Today February 2026 Security Update
by WebhostingToday Security Team · 6 Mar 2026 · 3 min read
Security doesn’t stand still, and neither should the hosting industry. Welcome to the February 2026 WebHosting.Today Monthly Security Update, created in partnership with our trusted security sponsors, Monarx and Patchstack. Together, we’re
#
Other
Is PrestaShop’s February 2026 security alert linked to over 21 million records allegedly leaked from the Addons Marketplace?
by Damian Andruszkiewicz · 23 Feb 2026 · 4 min read
A community-led forensic investigation links the attacks to a reported breach of 21 million records from PrestaShop's own Addons Marketplace.  PrestaShop has not confirmed or denied the connection, only issued a security
🚀

Reach hosting professionals

Sponsor webhosting.today and get in front of hosting buyers, founders and engineers.

50k+monthly readers
742articles
Become a sponsor →
📬

Stay in the loop

Weekly digest of the best hosting news, reviews and industry moves.

Page 4 of 4