#security — Web Hosting News

All web hosting articles tagged #security — 62 results.

Other
Automattic Is Not an Owner of the WordPress Marks It Asserted in Court, a Judge Rules
Natalia Nowak · 29 Sep 2026 · 6 min read
#automattic#web-hosting#wordpress
The September 24 order brings back four antitrust claims the same judge had dismissed in an earlier ruling. It also holds that Automattic and Mullenweg are neither owners nor registrants of the WordPress marks, so they cannot assert them in their own right.
Articles tagged #security
1–20 of 62
Security
Ten IP Addresses Sent at Least 94,000 Attempts to Exploit a WooCommerce Plugin.
by Natalia Nowak · 15 Sep 2026 · 5 min read
A critical file-upload flaw in a paid WooCommerce extension was disclosed in February, and Wordfence has since blocked more than 100,000 attempts to exploit it. The largest published spike came on August 30, and ten source addresses account for at least 94,490 of the blocked requests.
Security
EU Software Makers Now Have 24 Hours to Report an Exploited Flaw.
by Natalia Nowak · 14 Sep 2026 · 5 min read
Article 14 of the Cyber Resilience Act took effect on September 11, giving manufacturers 24 hours to file an early warning on an actively exploited flaw. License is not the test, monetization is, and the equivalent duty for open-source stewards does not begin until December 2027.
Security
A cPanel Account With Mail Privileges Could Reach Root. Every Supported Version Was Affected.
by Natalia Nowak · 9 Sep 2026 · 4 min read
cPanel has patched CVE-2026-67401. An authenticated account with mail-related privileges could create files through EmailTrack and reach code execution as root. All supported versions were affected, and the CVE record scores the flaw 9.9 out of 10, critical.
Industry reports
Non-Developers Are Building Whole Websites With AI. 20i’s Survey Says Only 31.5% Get a Developer’s Review.
by Natalia Nowak · 8 Sep 2026 · 8 min read
A survey of 600 US non-developers who use AI to write code found 16.3 percent building entire websites, 61 percent testing the results themselves and 31.5 percent having a developer review the code. Separate laboratory testing puts the flaw rate near half.
Security
A Magento Zero-Day Is Being Exploited Now. The First Known Victim Was Fully Patched.
by Natalia Nowak · 7 Sep 2026 · 7 min read
Attackers are running code on Magento and Adobe Commerce stores through an unpatched flaw Sansec calls StyleSmuggler. There is no patch and no CVE, the first known victim had a clean patch status, and the backdoor installs in the site user's home directory rather than the web root.
Security
WHMCS Has an Unauthenticated RCE. The Fix Exists Only for 9.0.8 and 8.13.7.
by Natalia Nowak · 4 Sep 2026 · 5 min read
Two WHMCS advisories on September 3: an unauthenticated remote code execution flaw affecting every build since 8.0, and a 2CheckOut gateway flaw exposing client data in versions from 4.5. Both are fixed in 9.0.8 and 8.13.7, and nothing older gets a patch.
Partners
1,000+ Junk Emails a Day, Brought Under Control by One DNS Change
by Natalia Nowak · 4 Sep 2026 · 5 min read
HeroicGuard filters mail before Google, Microsoft or any other provider receives it. Setup is one MX change, pricing is per domain with unlimited mailboxes, and NameHero's founder tells how it rescued a company address taking a thousand junk messages a day.
Security
cPanel Patches a Root-Level Flaw in Domain Parking: One Customer Account With Domain Permissions Was Enough
by Natalia Nowak · 28 Aug 2026 · 3 min read
cPanel patched CVE-2026-65643: an account holder able to add parked or addon domains could create arbitrary files and reach root, taking every site on the server. All supported versions were affected. No CVE record, no CVSS and no exploitation status published so far.
Security
InMotion Rolls Out Monarx ThreatShield Inside the PHP Engine Across Its Fleet
by Natalia Nowak · 26 Aug 2026 · 7 min read
InMotion is switching on Monarx ThreatShield fleet-wide, blocking attacks inside the PHP runtime rather than filtering requests in front of it. Its own July incident report, with two sites taken over in under half a minute each, documents the problem this product class targets.
Security
Plesk Patches Three Flaws That Start From an Ordinary Customer Account
by Natalia Nowak · 26 Aug 2026 · 5 min read
Plesk's August 25 advisories cover three flaws reachable from an ordinary customer account: arbitrary file reads, cross-tenant database access, and root through two extensions. The extension fixes ship separately, and administrators report the Migrator update is not arriving.
Security
Researchers Found Six Major CDNs Vulnerable to New HTTP/3 Attacks. Two Deployed Mitigations.
by Natalia Nowak · 21 Aug 2026 · 7 min read
New research turns a CDN against the site behind it by exploiting the gap between HTTP/3 at the front and HTTP/1.1 at the back. All six CDNs tested were vulnerable, only Baidu and Tencent have deployed mitigations, and every proposed fix sits at the CDN rather than at the site.
Security
Forminator’s 9.8 Flaw, and Eleven More Fixes in Nineteen Days
by Natalia Nowak · 20 Aug 2026 · 7 min read
Forminator's file upload flaw scores 9.8 and needs no authentication, but it takes a form with both an upload and a select field, and the default .htaccess meant to stop execution does nothing on NGINX. The changelog records twelve security releases in nineteen days.
Security
WordPress 7.0.4 Fixes a PNG That Runs Code. The Flaw Was Almost 10 Years Old.
by Natalia Nowak · 13 Aug 2026 · 6 min read
WordPress 7.0.4 closes CVE-2026-65640, present since version 4.7: a file named .png that hides PostScript could reach ImageMagick and Ghostscript and run code on the server. It needs an author account, but XML-RPC skips the upload check, so multi-author and membership sites should update first.
Security
Cloudflare Reached FedRAMP High Without Building a Separate Government Cloud
by Natalia Nowak · 11 Aug 2026 · 7 min read
Cloudflare reached FedRAMP High without a separate gov cloud: one network, U.S.-only processing, 22 agencies on board. One catch: it brands the milestone Class D, a certification FedRAMP's roadmap only pilots next fiscal year. The Pentagon's IL4 is the next target.
Security
N-able’s First Patch Left the Door Open, and Attackers Walked Back Through It
by Natalia Nowak · 3 Aug 2026 · 4 min read
A second CVE in N-able N-central exists because the first patch was incomplete, and it is being exploited to take over MSP consoles and reach every machine they manage. The August 2 hotfix closes the way in, but no vendor statement says it removes the attackers' persistence.
Security
Freenom Is Back, and No Longer Free. The Free-Domain Registry Behind Years of Phishing.
by Natalia Nowak · 27 Jul 2026 · 7 min read
Freenom gave away millions of domains and became the internet's biggest source of phishing, until Meta sued and it promised to quit. Now, per Domain Incite, it is back, running .tk, .cf and .gq again from €8.22 a year. What changed is what fueled the abuse: the domains are no longer free.
Security
A Once-a-Decade WordPress Core Flaw, and the Gap Between Patched and Safe
by Natalia Nowak · 21 Jul 2026 · 5 min read
A critical flaw in WordPress core, the first of its kind in nearly a decade, triggered a rare forced update to millions of sites. Within 72 hours it was mass exploitation, because forced updates never reach everyone. Why patched and safe are not the same thing.
Security
A Critical Nginx Flaw and Who Is Actually Exposed
by Natalia Nowak · 20 Jul 2026 · 3 min read
F5 patched CVE-2026-42533, a heap-overflow flaw in Nginx rated 9.2 that has sat in the code since 2011. It is unauthenticated and remote, but only triggers under a specific regex-map configuration, so not every server is exposed. With a proof-of-concept exploit due in early August, here is who actually needs to patch.
Security
An Unauthenticated Path to Code Execution in WordPress Core, Already Being Exploited
by Łukasz Nowak · 18 Jul 2026 · 8 min read
A flaw in the heart of WordPress lets a complete stranger seize a site without ever logging in, and the attacks began the day it was disclosed. Millions of sites run the vulnerable code, and the only real protection is an update most owners assume already happened.
Industry reports
Cloudways Just Handed AI Agents the Admin Panel, and the Locks Are Racing to Catch Up
by Natalia Nowak · 17 Jul 2026 · 4 min read
Cloudways' MCP server now exposes 244 tools, letting an AI agent run security scans, deployments, and billing on your hosting by chat. It is part of a wave, from DigitalOcean to cPanel, and its role-based scoped tokens stand out in a category where research finds many MCP servers insecure.
📬

Stay in the loop

Weekly digest of the best hosting news, reviews and industry moves.

Page 1 of 4