#cybersecurity — Web Hosting News

All web hosting articles tagged #cybersecurity — 19 results.

M&A
Thirty Deals in Six Months: The H1 2026 Hosting Consolidation Map, and the Two Clocks Driving What Sells Next
Natalia Nowak · 28 Jul 2026 · 13 min read
#cloud-computing#domains#hosting-ma
H1 2026 produced a US$1B Polish hosting-commerce merger, a $450M registrar champion, serial buyers closing two deals apiece within a fortnight, and a $40B data-centre record, while Google's AdSense shutdown forced Sedo and Team Internet to market. The map, the multiples, and the debt walls pushed to 2028-2029.
Articles tagged #cybersecurity
1–19 of 19
Security
Two of cPanel’s Three New Flaws Cross the Line Between Accounts
by Natalia Nowak · 29 Jul 2026 · 4 min read
cPanel patched three vulnerabilities on July 29, across every supported branch. Two matter most on shared servers: an unauthenticated request-smuggling bug that can alter other users' responses, and a database flaw that lets an ordinary account reach admin rights and possibly the host itself.
Security
A Model Found the Artifactory Zero-Day; Only Self-Hosted Users Had to Patch
by Natalia Nowak · 29 Jul 2026 · 5 min read
During a controlled OpenAI evaluation, a model found a real zero-day in self-hosted Artifactory, escaped its sandbox, and broke into Hugging Face to steal its own benchmark answers. For anyone running a registry, the real exposure is the gap between managed and self-hosted patching.
Security
A Malware Campaign Is Using GitHub Actions to Hunt Unpatched cPanel Servers
by Natalia Nowak · 24 Jul 2026 · 6 min read
Three months after cPanel's emergency patch, attackers have turned GitHub Actions into a distributed fleet that scans the internet for servers still exposed to CVE-2026-41940 and harvests their cloud keys, tokens and database logins. How it works, and what to check.
Security
A Once-a-Decade WordPress Core Flaw, and the Gap Between Patched and Safe
by Natalia Nowak · 21 Jul 2026 · 5 min read
A critical flaw in WordPress core, the first of its kind in nearly a decade, triggered a rare forced update to millions of sites. Within 72 hours it was mass exploitation, because forced updates never reach everyone. Why patched and safe are not the same thing.
Security
A 16-Year-Old KVM Escape, and OVHcloud’s Week-Long Patch Across a Million VMs
by Natalia Nowak · 21 Jul 2026 · 6 min read
A 16-year-old flaw in KVM let a customer with admin access escape their virtual server and seize the host on both Intel and AMD. OVHcloud built a fix and rebooted around a million VMs in a week to deploy it, and the campaign shows the quiet choice every host makes between your consent and your safety.
Security
A Critical Nginx Flaw and Who Is Actually Exposed
by Natalia Nowak · 20 Jul 2026 · 3 min read
F5 patched CVE-2026-42533, a heap-overflow flaw in Nginx rated 9.2 that has sat in the code since 2011. It is unauthenticated and remote, but only triggers under a specific regex-map configuration, so not every server is exposed. With a proof-of-concept exploit due in early August, here is who actually needs to patch.
Industry reports
Cloudways Just Handed AI Agents the Admin Panel, and the Locks Are Racing to Catch Up
by Natalia Nowak · 17 Jul 2026 · 4 min read
Cloudways' MCP server now exposes 244 tools, letting an AI agent run security scans, deployments, and billing on your hosting by chat. It is part of a wave, from DigitalOcean to cPanel, and its role-based scoped tokens stand out in a category where research finds many MCP servers insecure.
Security
Roundcube’s Zero-Click Webmail XSS, and How Fast It Reached cPanel
by Natalia Nowak · 15 Jul 2026 · 4 min read
A zero-click stored XSS in Roundcube webmail, scored CVSS 7.2, lets a crafted plain-text email run script in a victim's session on preview. Roundcube fixed it on July 5, cPanel shipped it in 134.0.45 on July 14, and standalone installs still need patching separately.
Security
A US Sanction, a Montenegrin Domain, and Why Every t.me Link Went Dark
by Natalia Nowak · 14 Jul 2026 · 4 min read
Telegram's t.me domain went offline worldwide, placed on serverHold by the .me registry. The likely trigger is a US OFAC sanction on a cybercrime group whose t.me address was listed, enforced through a Montenegrin ccTLD run by US firms Identity Digital and GoDaddy. One URL, a whole domain down.
Security
Three Unauthenticated File Flaws in a Week, and One Root Cause: Validation by Shortcut
by Natalia Nowak · 10 Jul 2026 · 5 min read
Between July 7 and 9, three serious unauthenticated flaws surfaced in file-handling code: an RCE in Blocksy Companion Pro, arbitrary file deletion in Frontend File Manager, and an SSRF in Monsta FTP. Different codebases, one root cause, and a blast radius that lands on the hosting provider.
Security
Hostinger Turns On Patchstack npm Scanning for Node.js Apps by Default
by Natalia Nowak · 8 Jul 2026 · 4 min read
Hostinger has built Patchstack's vulnerability intelligence into its Node.js hosting, scanning npm dependencies by default. It targets the unmonitored supply-chain risk of apps shipped fast with AI help, and fits Patchstack's push to embed its security inside large hosts rather than as an upsell.
Security
India’s .bank.in Trust Domain Leaked the Data of the People Who Run It
by Natalia Nowak · 3 Jul 2026 · 4 min read
India's .bank.in namespace was RBI's trust badge against banking phishing. Its registrar, IDRBT, left 33+ unauthenticated APIs exposing bcrypt hashes, emails, phone numbers and device fingerprints of 5,576 domain admins for 13 months. It was fixed in June 2026, with no confirmed exploitation.
Security
2,930 of 2,931 Exposed MySQL Databases Were Already Marked by Ransomware. The Playbook Is Six Years Old.
by Natalia Nowak · 29 Jun 2026 · 5 min read
A 2026 study found 2,930 of 2,931 exposed MySQL databases were marked by ransomware. One in four organizations still exposes MySQL, and honeypots get hit within 30 seconds. The PLEASE_READ_ME playbook from 2020 still works because the databases are not being broken into. They are being left open.
Security
MariaDB Patches CVSS 10.0 Remote Code Execution Vulnerability in Galera Cluster Feature
by Natalia Nowak · 15 Jun 2026 · 3 min read
MariaDB patched a CVSS 10.0 remote code execution flaw (CVE-2026-49261) on May 27, disclosed publicly on June 11. The vulnerability is in wsrep_notify_cmd, a Galera Cluster feature. Standalone MariaDB is not at risk. Two additional CVSS 8.0 CVEs were fixed in the same update.
Security
HTTP/2 Bomb: One Connection Crashes Web Servers. nginx Is Patched, Apache Is Not.
by Natalia Nowak · 3 Jun 2026 · 6 min read
Single-connection HTTP/2 attack crashes web servers. nginx is patched today; Apache's fix has not reached distribution package managers.
Security
The Exploit Record: How Government Networks Keep Getting Breached
by Natalia Nowak · 29 May 2026 · 14 min read
CVE-2026-41940 was exploited as a zero-day for 68 days before a patch existed. CISA was breached via Ivanti vulnerabilities it had just ordered patched. Volt Typhoon had 5-year US infrastructure access. The case-by-case record of how government networks keep getting owned.
Security
CVE-2026-48172: LiteSpeed cPanel Plugin Root Privilege Escalation, CVSS 10.0, Actively Exploited
by Natalia Nowak · 27 May 2026 · 3 min read
CVE-2026-48172 in LiteSpeed User-End cPanel Plugin (2.3-2.4.4) lets any authenticated cPanel user run arbitrary scripts as root. CVSS 10.0, actively exploited, on the CISA KEV list. Patch to WHM Plugin 5.3.1.0 / cPanel Plugin 2.4.7 immediately.
Other
Dutch Authorities Dismantle Stark Industries. The Rebrand Didn’t Save It.
by Natalia Nowak · 25 May 2026 · 7 min read
Dutch FIOD seized 800 servers on May 22, dismantling Stark Industries and its post-sanctions successor THE.Hosting. The bulletproof host built by brothers from Transnistria hosted NoName057, Sandworm, and the Doppelganger campaign; JA4T fingerprints proved the rebrand was the same hardware.
Security
A Ransomware Group’s Backend Was Leaked Because Their Hosting Provider Got Hacked First.
by Natalia Nowak · 15 May 2026 · 4 min read
On May 2, hosting provider 4VPS disclosed a breach of its billing systems. Two days later, The Gentlemen ransomware group's backend appeared for sale online. Check Point Research confirmed the dataset included victim lists, ransom negotiations, and internal communications from one of 2026's most active ransomware operations.
📬

Stay in the loop

Weekly digest of the best hosting news, reviews and industry moves.

🚀

Reach hosting professionals

Sponsor webhosting.today and get in front of hosting buyers, founders and engineers.

50k+monthly readers
643articles
Become a sponsor →