#security — Web Hosting News

All web hosting articles tagged #security — 47 results.

M&A
Thirty Deals in Six Months: The H1 2026 Hosting Consolidation Map, and the Two Clocks Driving What Sells Next
Natalia Nowak · 28 Jul 2026 · 13 min read
#cloud-computing#domains#hosting-ma
H1 2026 produced a US$1B Polish hosting-commerce merger, a $450M registrar champion, serial buyers closing two deals apiece within a fortnight, and a $40B data-centre record, while Google's AdSense shutdown forced Sedo and Team Internet to market. The map, the multiples, and the debt walls pushed to 2028-2029.
Articles tagged #security
1–20 of 47
Security
Freenom Is Back, and No Longer Free. The Free-Domain Registry Behind Years of Phishing.
by Natalia Nowak · 27 Jul 2026 · 7 min read
Freenom gave away millions of domains and became the internet's biggest source of phishing, until Meta sued and it promised to quit. Now, per Domain Incite, it is back, running .tk, .cf and .gq again from €8.22 a year. What changed is what fueled the abuse: the domains are no longer free.
Security
A Once-a-Decade WordPress Core Flaw, and the Gap Between Patched and Safe
by Natalia Nowak · 21 Jul 2026 · 5 min read
A critical flaw in WordPress core, the first of its kind in nearly a decade, triggered a rare forced update to millions of sites. Within 72 hours it was mass exploitation, because forced updates never reach everyone. Why patched and safe are not the same thing.
Security
A Critical Nginx Flaw and Who Is Actually Exposed
by Natalia Nowak · 20 Jul 2026 · 3 min read
F5 patched CVE-2026-42533, a heap-overflow flaw in Nginx rated 9.2 that has sat in the code since 2011. It is unauthenticated and remote, but only triggers under a specific regex-map configuration, so not every server is exposed. With a proof-of-concept exploit due in early August, here is who actually needs to patch.
Security
An Unauthenticated Path to Code Execution in WordPress Core, Already Being Exploited
by Łukasz Nowak · 18 Jul 2026 · 8 min read
A flaw in the heart of WordPress lets a complete stranger seize a site without ever logging in, and the attacks began the day it was disclosed. Millions of sites run the vulnerable code, and the only real protection is an update most owners assume already happened.
Industry reports
Cloudways Just Handed AI Agents the Admin Panel, and the Locks Are Racing to Catch Up
by Natalia Nowak · 17 Jul 2026 · 4 min read
Cloudways' MCP server now exposes 244 tools, letting an AI agent run security scans, deployments, and billing on your hosting by chat. It is part of a wave, from DigitalOcean to cPanel, and its role-based scoped tokens stand out in a category where research finds many MCP servers insecure.
Security
Januscape and Bad Epoll: Two Linux Flaws That Let One Customer Take Over the Whole Server
by Łukasz Nowak · 11 Jul 2026 · 9 min read
Januscape (CVE-2026-53359) lets a guest VM escape to the host and take over co-tenants; Bad Epoll (CVE-2026-46242) lets any unprivileged user reach root with a near-perfect exploit. Both are patched upstream and in AlmaLinux, and for both the only fix is a new kernel and a reboot.
Security
Three Unauthenticated File Flaws in a Week, and One Root Cause: Validation by Shortcut
by Natalia Nowak · 10 Jul 2026 · 5 min read
Between July 7 and 9, three serious unauthenticated flaws surfaced in file-handling code: an RCE in Blocksy Companion Pro, arbitrary file deletion in Frontend File Manager, and an SSRF in Monsta FTP. Different codebases, one root cause, and a blast radius that lands on the hosting provider.
Security
Hostinger Turns On Patchstack npm Scanning for Node.js Apps by Default
by Natalia Nowak · 8 Jul 2026 · 4 min read
Hostinger has built Patchstack's vulnerability intelligence into its Node.js hosting, scanning npm dependencies by default. It targets the unmonitored supply-chain risk of apps shipped fast with AI help, and fits Patchstack's push to embed its security inside large hosts rather than as an upsell.
Security
An Attacker Sent a Ransom Email From Blesta’s Own Servers
by Łukasz Nowak · 26 Jun 2026 · 9 min read
An extortion email demanding Blesta pay up passed SPF, DKIM and DMARC from Blesta's own servers, pointing to a real compromise. Blesta has not confirmed one.
Industry reports
The File Nobody Watches: llms.txt Is the Hosting Industry’s Newest Attack Surface
by Łukasz Nowak · 22 Jun 2026 · 17 min read
110 hosting-industry domains publish an llms.txt that AI agents read verbatim, and a single edit can feed customers a rogue download or an attacker's phone number. Zero of the 110 are signed or monitored. Every piece of the attack is already proven; nobody is guarding the file.
Security
MariaDB Patches CVSS 10.0 Remote Code Execution Vulnerability in Galera Cluster Feature
by Natalia Nowak · 15 Jun 2026 · 3 min read
MariaDB patched a CVSS 10.0 remote code execution flaw (CVE-2026-49261) on May 27, disclosed publicly on June 11. The vulnerability is in wsrep_notify_cmd, a Galera Cluster feature. Standalone MariaDB is not at risk. Two additional CVSS 8.0 CVEs were fixed in the same update.
Other
Protect The Shire: WordPress Adds a 24-Hour Default Delay to Plugin Auto-Updates
by Natalia Nowak · 8 Jun 2026 · 9 min read
Matt Mullenweg announced Protect The Shire on June 5, 2026: a 24-hour default delay before every WordPress plugin release reaches auto-updates. The infrastructure has existed as opt-in since August 2025. The shift cites AI-accelerated supply chain risk after Mythos and Essential Plugins.
Security
HTTP/2 Bomb: One Connection Crashes Web Servers. nginx Is Patched, Apache Is Not.
by Natalia Nowak · 3 Jun 2026 · 6 min read
Single-connection HTTP/2 attack crashes web servers. nginx is patched today; Apache's fix has not reached distribution package managers.
Security
A Database Allegedly From Home.pl Is Being Advertised on a Cybercrime Forum.
by Łukasz Nowak · 29 May 2026 · 8 min read
A dataset allegedly from Home.pl, Poland's largest hosting provider, is being advertised on a cybercrime forum. We analyze the schema and what it means for 300,000+ customers.
Security
The Exploit Record: How Government Networks Keep Getting Breached
by Natalia Nowak · 29 May 2026 · 14 min read
CVE-2026-41940 was exploited as a zero-day for 68 days before a patch existed. CISA was breached via Ivanti vulnerabilities it had just ordered patched. Volt Typhoon had 5-year US infrastructure access. The case-by-case record of how government networks keep getting owned.
Security
CVE-2026-48172: LiteSpeed cPanel Plugin Root Privilege Escalation, CVSS 10.0, Actively Exploited
by Natalia Nowak · 27 May 2026 · 3 min read
CVE-2026-48172 in LiteSpeed User-End cPanel Plugin (2.3-2.4.4) lets any authenticated cPanel user run arbitrary scripts as root. CVSS 10.0, actively exploited, on the CISA KEV list. Patch to WHM Plugin 5.3.1.0 / cPanel Plugin 2.4.7 immediately.
Security
FunnelKit Plugin Flaw Actively Exploited to Skim Credit Cards From WooCommerce Checkout Pages
by Natalia Nowak · 18 May 2026 · 4 min read
Every customer who checked out on a WooCommerce store running an unpatched FunnelKit plugin may have had their card number, CVV, and billing address stolen. The attack is active across more than 40,000 sites. Patch to version 3.15.0.3, released May 14, 2026, and assess breach notification obligations.
Security
A Ransomware Group’s Backend Was Leaked Because Their Hosting Provider Got Hacked First.
by Natalia Nowak · 15 May 2026 · 4 min read
On May 2, hosting provider 4VPS disclosed a breach of its billing systems. Two days later, The Gentlemen ransomware group's backend appeared for sale online. Check Point Research confirmed the dataset included victim lists, ransom negotiations, and internal communications from one of 2026's most active ransomware operations.
Security
Skynethosting Took Its Entire cPanel Fleet Offline on May 1. Two Weeks Later, Some Are Still Down.
by Natalia Nowak · 15 May 2026 · 10 min read
Skynethosting took its entire cPanel fleet offline on May 1 in response to CVE-2026-41940, and as of May 14 some customer servers had been down for nearly two weeks, with one reseller publicly reporting a 30 percent client loss during the outage.
Security
Fragnesia: A New Linux Kernel Privilege Escalation That Emerged From Prior Kernel Patches
by Łukasz Nowak · 14 May 2026 · 3 min read
William Bowling of V12 Security disclosed Fragnesia on May 13, 2026, a Linux kernel privilege escalation that allows an unprivileged local attacker to reach root by corrupting the kernel page cache through the XFRM ESP-in-TCP subsystem.
📬

Stay in the loop

Weekly digest of the best hosting news, reviews and industry moves.

Page 1 of 3