#cybersecurity — Web Hosting News

All web hosting articles tagged #cybersecurity — 35 results.

Other
Automattic Is Not an Owner of the WordPress Marks It Asserted in Court, a Judge Rules
Natalia Nowak · 29 Sep 2026 · 6 min read
#automattic#web-hosting#wordpress
The September 24 order brings back four antitrust claims the same judge had dismissed in an earlier ruling. It also holds that Automattic and Mullenweg are neither owners nor registrants of the WordPress marks, so they cannot assert them in their own right.
Articles tagged #cybersecurity
1–20 of 35
Security
The WordPress 7.1.2 Flaw Was Exploited in Hours. Theme and Host Decide the Damage.
by Natalia Nowak · 30 Sep 2026 · 9 min read
Attackers were writing PHP files through pearcmd.php by the evening of the day WordPress 7.1.2 shipped, and whether a site is reachable at all depends on its theme layout and on register_argc_argv, which is on by default under cPanel below PHP 8.5.
Security
WordPress 7.1.1 Fixes a Comment-Form XSS. The Payload Passes the Sanitizer.
by Natalia Nowak · 22 Sep 2026 · 10 min read
WordPress 7.1.1 fixes CVE-2026-93485, a stored XSS delivered through the ordinary comment form by an anonymous visitor and missed by wp_kses. Two of the other ten fixes came from Anthropic, and three in ten sites run a version 6 branch reached only by a backport.
Security
A Critical libheif Bug Reachable Through WordPress Uploads Still Has No CVE
by Natalia Nowak · 21 Sep 2026 · 8 min read
A researcher uploaded a crafted photo to a clean WordPress site and left a working PHP file on the server. The flaw is in libheif, a system library that arrives with the operating system, and twenty days after the fix shipped it still has no CVE number for patch pipelines to match.
Security
Three LiteSpeed Security Builds in Six Days: Check Which One Your Servers Run
by Natalia Nowak · 18 Sep 2026 · 7 min read
A cPanel advisory of September 14 covers a LiteSpeed Enterprise flaw that lets a hosting account past CageFS to root. LiteSpeed has since shipped 6.3.7 three times in six days, each build with a security change, and a server patched on the day of the advisory is no longer on the latest one.
Security
Acronis cPanel Backup Plugin: Exploited Privilege-Escalation Flaw on CISA’s List
by Natalia Nowak · 17 Sep 2026 · 5 min read
Acronis has patched CVE-2026-87886 in its backup plugin for cPanel and WHM and says it has been used in limited, targeted attacks, based on one customer report. CISA added it to its Known Exploited Vulnerabilities catalog on September 16 with a three-day deadline for US federal civilian agencies.
Partners
Monarx Launches Dark Web Monitoring. One Domain Covers Every Address on It.
by Natalia Nowak · 10 Sep 2026 · 6 min read
Monarx Dark Web Monitoring begins with a domain rather than a list of mailboxes, sells white-label at a suggested $1.99 to $9.99 a month on a 50/50 revenue share, and today shows customers which categories of their data were breached rather than the data itself.
Security
A High-Severity Patch for Five Million WordPress Sites Was Labeled as a Text Fix
by Natalia Nowak · 2 Sep 2026 · 7 min read
Two unauthenticated flaws in plugins on millions of WordPress sites were patched the same day, days before the CVE records went public. The changelogs gave no severity signal, and for anyone running a fleet, that gap is the real story.
Security
An Attacker Hijacked Hetzner IP Space and Poisoned a Virtualizor Update
by Natalia Nowak · 1 Sep 2026 · 6 min read
A BGP hijack of Hetzner address space sent Softaculous traffic to an attacker for two nights. A valid Let's Encrypt certificate hid the diversion, update packages were not cryptographically verified, one malicious Virtualizor update got through, and the countermeasure took about 12 hours to arrive.
Security
The Hypervisor Escape Comes to VMware: CVE-2026-47876 May Let a Guest VM Run Code on the ESX Host
by Natalia Nowak · 14 Aug 2026 · 8 min read
CVE-2026-47876, rated 9.3, may let a guest VM with a VMXNET3 adapter escape to the VMware ESX host. Two vCenter flaws rated 9.8 shipped in the same advisory, and one is already being exploited in the wild.
Security
WordPress 7.0.4 Fixes a PNG That Runs Code. The Flaw Was Almost 10 Years Old.
by Natalia Nowak · 13 Aug 2026 · 6 min read
WordPress 7.0.4 closes CVE-2026-65640, present since version 4.7: a file named .png that hides PostScript could reach ImageMagick and Ghostscript and run code on the server. It needs an author account, but XML-RPC skips the upload check, so multi-author and membership sites should update first.
Security
Metabase Cloud Customers Were Patched Before They Knew. Self-Hosted Users Had to Do It Themselves.
by Natalia Nowak · 12 Aug 2026 · 5 min read
Metabase's cloud service was breached through a zero-day, and the vendor patched every hosted instance before most customers heard. Self-hosted operators had to find out, patch by hand and hunt for evidence. Five customers came forward in four days, and about 2,500 instances remain visible online.
Security
Zapscape Breaks the Linux KVM Boundary. A Server Without a Single VM Can Still Be in Range.
by Natalia Nowak · 10 Aug 2026 · 12 min read
Zapscape lets an attacker who controls a guest climb out and seize the Linux host as root. Wherever /dev/kvm is open to ordinary users, a plain shared-hosting box is in range too, because a local user can spin up their own guest. Exploit code is public; patched kernels are rolling out.
Security
Roundcube Shipped Eleven Security Fixes Without a Single CVE Number
by Natalia Nowak · 10 Aug 2026 · 5 min read
Roundcube shipped eleven security fixes across its current and LTS branches, including an IMAP command injection and a conditional code execution flaw. The notes name no CVE identifiers, so version-matching scanners stay quiet, and cPanel has historically taken five to nine days to follow.
Security
An AI Model Found the WordPress Flaw in Ten Hours for $25. Attackers Weaponized the Patch in Ninety Minutes.
by Natalia Nowak · 7 Aug 2026 · 8 min read
WordPress shipped its second security release in three weeks. Around the first one, both ends of the vulnerability lifecycle collapsed: an AI model found the critical chain in 10 hours for about $25, and exploitation began 90 minutes after the patch shipped. Hosting companies own the gap in between.
Interviews
10,000 Sites Flagged in Weeks: Patchstack and Hostinger on npm Scanning by Default
by Natalia Nowak · 6 Aug 2026 · 8 min read
A month after Hostinger enabled Patchstack's npm scanning by default, the first numbers are in: vulnerable dependencies on more than 10,000 sites. In a dual Q&A, both companies talk auto-fixes, the limits of scanning, and whether hosts will patch dependencies for everyone.
Security
N-able’s First Patch Left the Door Open, and Attackers Walked Back Through It
by Natalia Nowak · 3 Aug 2026 · 4 min read
A second CVE in N-able N-central exists because the first patch was incomplete, and it is being exploited to take over MSP consoles and reach every machine they manage. The August 2 hotfix closes the way in, but no vendor statement says it removes the attackers' persistence.
Security
Two of cPanel’s Three New Flaws Cross the Line Between Accounts
by Natalia Nowak · 29 Jul 2026 · 4 min read
cPanel patched three vulnerabilities on July 29, across every supported branch. Two matter most on shared servers: an unauthenticated request-smuggling bug that can alter other users' responses, and a database flaw that lets an ordinary account reach admin rights and possibly the host itself.
Security
A Model Found the Artifactory Zero-Day; Only Self-Hosted Users Had to Patch
by Natalia Nowak · 29 Jul 2026 · 5 min read
During a controlled OpenAI evaluation, a model found a real zero-day in self-hosted Artifactory, escaped its sandbox, and broke into Hugging Face to steal its own benchmark answers. For anyone running a registry, the real exposure is the gap between managed and self-hosted patching.
Security
A Malware Campaign Is Using GitHub Actions to Hunt Unpatched cPanel Servers
by Natalia Nowak · 24 Jul 2026 · 6 min read
Three months after cPanel's emergency patch, attackers have turned GitHub Actions into a distributed fleet that scans the internet for servers still exposed to CVE-2026-41940 and harvests their cloud keys, tokens and database logins. How it works, and what to check.
Security
A Once-a-Decade WordPress Core Flaw, and the Gap Between Patched and Safe
by Natalia Nowak · 21 Jul 2026 · 5 min read
A critical flaw in WordPress core, the first of its kind in nearly a decade, triggered a rare forced update to millions of sites. Within 72 hours it was mass exploitation, because forced updates never reach everyone. Why patched and safe are not the same thing.
📬

Stay in the loop

Weekly digest of the best hosting news, reviews and industry moves.

Page 1 of 2