#patchstack — Web Hosting News

All web hosting articles tagged #patchstack — 11 results.

Other
Automattic Is Not an Owner of the WordPress Marks It Asserted in Court, a Judge Rules
Natalia Nowak · 29 Sep 2026 · 6 min read
#automattic#web-hosting#wordpress
The September 24 order brings back four antitrust claims the same judge had dismissed in an earlier ruling. It also holds that Automattic and Mullenweg are neither owners nor registrants of the WordPress marks, so they cannot assert them in their own right.
Articles tagged #patchstack
1–11 of 11
Security
WordPress 7.1.1 Fixes a Comment-Form XSS. The Payload Passes the Sanitizer.
by Natalia Nowak · 22 Sep 2026 · 10 min read
WordPress 7.1.1 fixes CVE-2026-93485, a stored XSS delivered through the ordinary comment form by an anonymous visitor and missed by wp_kses. Two of the other ten fixes came from Anthropic, and three in ten sites run a version 6 branch reached only by a backport.
Security
Attacks on the Elementor Pro Flaw Began the Day It Was Disclosed
by Natalia Nowak · 3 Sep 2026 · 6 min read
A critical Elementor Pro flaw was disclosed on August 19 and attacked the same day, with one firewall vendor blocking more than 190,000 attempts. The fix had already shipped, only sites with a published upload form were reachable, and the check for compromise takes one look at a single directory.
Security
A High-Severity Patch for Five Million WordPress Sites Was Labeled as a Text Fix
by Natalia Nowak · 2 Sep 2026 · 7 min read
Two unauthenticated flaws in plugins on millions of WordPress sites were patched the same day, days before the CVE records went public. The changelogs gave no severity signal, and for anyone running a fleet, that gap is the real story.
Security
WordPress 7.0.4 Fixes a PNG That Runs Code. The Flaw Was Almost 10 Years Old.
by Natalia Nowak · 13 Aug 2026 · 6 min read
WordPress 7.0.4 closes CVE-2026-65640, present since version 4.7: a file named .png that hides PostScript could reach ImageMagick and Ghostscript and run code on the server. It needs an author account, but XML-RPC skips the upload check, so multi-author and membership sites should update first.
Security
An AI Model Found the WordPress Flaw in Ten Hours for $25. Attackers Weaponized the Patch in Ninety Minutes.
by Natalia Nowak · 7 Aug 2026 · 8 min read
WordPress shipped its second security release in three weeks. Around the first one, both ends of the vulnerability lifecycle collapsed: an AI model found the critical chain in 10 hours for about $25, and exploitation began 90 minutes after the patch shipped. Hosting companies own the gap in between.
Interviews
10,000 Sites Flagged in Weeks: Patchstack and Hostinger on npm Scanning by Default
by Natalia Nowak · 6 Aug 2026 · 8 min read
A month after Hostinger enabled Patchstack's npm scanning by default, the first numbers are in: vulnerable dependencies on more than 10,000 sites. In a dual Q&A, both companies talk auto-fixes, the limits of scanning, and whether hosts will patch dependencies for everyone.
Security
Hostinger Turns On Patchstack npm Scanning for Node.js Apps by Default
by Natalia Nowak · 8 Jul 2026 · 4 min read
Hostinger has built Patchstack's vulnerability intelligence into its Node.js hosting, scanning npm dependencies by default. It targets the unmonitored supply-chain risk of apps shipped fast with AI help, and fits Patchstack's push to embed its security inside large hosts rather than as an upsell.
Industry reports
Patchstack Now Underpins Most Major Managed WordPress Hosts. GoDaddy Joined the Stack.
by Natalia Nowak · 8 Jun 2026 · 8 min read
Patchstack became the default WordPress vulnerability intelligence and virtual patching layer for managed hosting. GoDaddy joined as a full-integration partner in April 2026; WP Engine, Cloudways, Hostinger, Nexcess, Pantheon and most other major hosts already use Patchstack threat intelligence.
Interviews
The Old Way to Sell Security in Hosting Just Broke – Oliver Sild, CEO of Patchstack
by Konrad Keck · 21 May 2026 · 7 min read
At Hosts Del Mar, Oliver Sild, CEO of Patchstack, explains why the twenty-year-old hosting security model of selling cleanups after the breach no longer works, why hackers got frontier AI first, and why proactive vulnerability protection has changed the math for hosts.
Webhosting.today January 2026 Security Update 
by WebhostingToday Security Team · 9 Feb 2026 · 10 min read
We’re excited to launch the first-ever Monthly Security Update on WebHosting.Today, we couldn’t be more pleased to do it alongside three of the most respected names in hosting and WordPress security, Blackwall
Industry reports
Secure hosting is a myth – real data finally exposes it
by Damian Andruszkiewicz · 27 Jan 2026 · 3 min read
For years, “secure hosting” has been treated as a given in the hosting industry. It appears everywhere: product pages, comparison tables, sales decks. The implicit message is simple - if you host
📬

Stay in the loop

Weekly digest of the best hosting news, reviews and industry moves.