#security — Web Hosting News

All web hosting articles tagged #security — 47 results.

M&A
Thirty Deals in Six Months: The H1 2026 Hosting Consolidation Map, and the Two Clocks Driving What Sells Next
Natalia Nowak · 28 Jul 2026 · 13 min read
#cloud-computing#domains#hosting-ma
H1 2026 produced a US$1B Polish hosting-commerce merger, a $450M registrar champion, serial buyers closing two deals apiece within a fortnight, and a $40B data-centre record, while Google's AdSense shutdown forced Sedo and Team Internet to market. The map, the multiples, and the debt walls pushed to 2028-2029.
Articles tagged #security
21–40 of 47
Security
Nginx Just Patched old Rewrite Module Flaw. RCE Was Possible With a Single HTTP Request.
by Łukasz Nowak · 14 May 2026 · 6 min read
A flaw sitting in nginx since 2008 was patched on May 13, 2026. CVSS 9.2, unauthenticated, and present in the default rewrite module.
Security
cPanel Patched Five More CVEs. One Fix Is Already Reported Incomplete.
by Natalia Nowak · 14 May 2026 · 9 min read
cPanel's May 13 patch covers five new CVEs, but security researcher Shubham Shah reported within hours that the fix for CVE-2026-29205 is incomplete and all cPanel instances remain exploitable until a working patch lands.
Security
Three cPanel Patches and DirtyFrag Fixes in One Day. Here Is Where Things Stand.
by Natalia Nowak · 13 May 2026 · 6 min read
On May 8, cPanel closed three new vulnerabilities and Linux distributions shipped DirtyFrag kernel fixes. Two weeks of disclosures left providers with three separate patch tracks. Here is the complete status and the confirmations every shared hosting customer should request.
Security
A Compromised Server Is the Beginning. Here Is What Breach Law Requires Next.
by Łukasz Nowak · 13 May 2026 · 35 min read
Change Healthcare's $3.1 billion in breach costs is the new normal of what a serious compromise sets in motion: parallel notification clocks across GDPR, NIS2, DORA, and HIPAA; personal liability for CISOs and boards; and a cyber insurance market with conditions that can deny coverage at the worst moment.
Security
cPanel Is Patching Three New CVEs Today. Technical Details Come With the Fix.
by Łukasz Nowak · 8 May 2026 · 3 min read
Three new cPanel vulnerabilities, CVE-2026-29201, CVE-2026-29202, and CVE-2026-29203, are being patched today at 12:00pm EST, with technical details withheld until the fix is live.
Security
DirtyFrag: Any User Account Can Become Root on Most Linux Servers. The Exploit Is Public. There Is No Patch.
by Łukasz Nowak · 8 May 2026 · 7 min read
DirtyFrag, a Linux kernel local privilege escalation that gives any local user root access on Ubuntu, RHEL, Fedora, CentOS Stream, AlmaLinux, and openSUSE Tumbleweed, went fully public on May 8 after an embargo break, with no CVE assigned and no patches available for any affected distribution.
Security
Apache 2.4.67 Patches 11 CVEs. One Is RCE. One Hits Shared Hosting.
by Natalia Nowak · 5 May 2026 · 5 min read
Apache 2.4.67, released May 4, patches 11 CVEs including a CVSS 8.8 HTTP/2 remote code execution flaw and a shared hosting privilege escalation that lets customers read each other's files.
Security
CVE-2026-41940 Live: cPanel Authentication Bypass, Active Exploitation, and What Comes Next
by Łukasz Nowak · 4 May 2026 · 13 min read
CVE-2026-41940, the cPanel authentication bypass exploited for 64 days before disclosure, is still developing. 44,000 servers likely compromised, a public exploit on GitHub, three active campaigns. This page is updated in real time as new information surfaces.
Security
The cPanel Zero-Day Was Active for 64 Days Before Anyone Knew
by Łukasz Nowak · 3 May 2026 · 9 min read
CVE-2026-41940, the cPanel authentication bypass from April 28, was being exploited since February 23, operated as a zero-day for 64 days, and was added to CISA's Known Exploited Vulnerabilities list with 1.5 million internet-exposed instances counted by Rapid7.
Security
Copy Fail: Any Local User Can Get Root on Nearly Every Linux System Since 2017
by Łukasz Nowak · 1 May 2026 · 4 min read
Copy Fail (CVE-2026-31431) is a Linux kernel privilege escalation giving any unprivileged local user root access, affecting virtually all distributions since 2017, with shared hosting and multi-tenant environments at highest risk.
Security
cPanel Had an Authentication Bypass. Exploits Were Already in the Wild.
by Łukasz Nowak · 29 Apr 2026 · 5 min read
cPanel disclosed a critical authentication bypass on April 28 affecting nearly all versions of cPanel and WHM, with active exploits confirmed in the wild before the patch was released, forcing hosting.com, Namecheap, KnownHost, HostPapa, and InMotion Hosting to take cPanel access offline globally.
Security
Four Tiers of OpenClaw Hosting. Three Have a Security Problem.
by Natalia Nowak · 28 Apr 2026 · 8 min read
The market for running OpenClaw splits cleanly into providers that have made it accessible and providers that have made it secure, and those are currently different products at different price points.
Security
Flippa Promoted the Plugin Portfolio Sale as a Success Story. It Was a Supply Chain Attack.
by Łukasz Nowak · 17 Apr 2026 · 6 min read
Flippa celebrated the six-figure sale of the Essential Plugin portfolio; eight months later the buyer activated a backdoor across 20,000+ WordPress sites using Googlebot cloaking and a C2 routed through an Ethereum smart contract.
Security
Turning Challenges into Revenue Opportunities: How PRO Hacked Site Repair Services Can Reduce Churn for Agencies and Web Hosts
by Akshay Kumar · 16 Apr 2026 · 6 min read
Website hacks are no longer rare incidents. They are a growing operational challenge for web hosts and digital agencies. When a client’s site gets compromised, the immediate expectation is clear: fast resolution
Other
Let’s Encrypt Changes Its Root Certificates on May 13. Client Auth Ends July 8
by Natalia Nowak · 15 Apr 2026 · 7 min read
Let's Encrypt issues approximately ten million certificates per day and is closing in on protecting one billion websites, making its May 13 root certificate switch a change that affects the majority of SSL certificates in any hosting provider's customer base. The two deadlines that require immediate action are May 13, when renewal automation must be verified to handle future shorter lifetimes correctly, and July 8, when client authentication certificates issued by Let's Encrypt stop working entirely. Providers whose automation relies on acme.sh face an additional gap: acme.sh does not yet support ACME Renewal Information (RFC 9773), the mechanism that lets Let's Encrypt communicate renewal windows directly to clients.
Security
World Backup Day 2026: The Threat Model Has Changed. The Advice Has Not.
by Łukasz Nowak · 31 Mar 2026 · 7 min read
Cloudflare's 2026 Threat Report describes attackers who log in rather than break in, using stolen session tokens that bypass MFA entirely. On World Backup Day, the question worth asking is not whether you have a backup, but whether the attacker who logged into your environment three weeks ago has already found it.
Security
European Commission Confirms AWS Account Breach: A Customer-Side Failure With EU Cloud Sovereignty Implications
by Łukasz Nowak · 30 Mar 2026 · 6 min read
The European Commission confirmed attackers accessed its AWS-hosted Europa.eu infrastructure and took data. AWS says its platform was not the issue, the customer account configuration was.
Expert's Voice
How to Sell Security in Hosting (Without Scaring Your Customers)
by Kamil Kołosowski · 25 Mar 2026 · 5 min read
There’s a moment in the hosting sales flow where everything can quietly fall apart. The customer has picked a plan, they’re ready to buy, and mentally they’re already there. It should be
Expert's Voice
Is the hosting industry stuck in the past? The problem of legacy security
by Kamil Kołosowski · 23 Mar 2026 · 4 min read
The hosting industry has gone through a major transformation in recent years. Infrastructure is faster, tools are more mature, and automation keeps improving. AI is also starting to reshape how services are built and managed.
Security
New Cybersecurity Laws Across Asia: What Hosting Providers Must Do to Stay Compliant in 2026
by Łukasz Nowak · 18 Mar 2026 · 8 min read
China's amended Cybersecurity Law, Hong Kong's first critical infrastructure statute, and Singapore's expanded compliance framework have all taken effect. For hosting businesses operating in the region, the compliance cost of inaction is now measured in millions.
🚀

Reach hosting professionals

Sponsor webhosting.today and get in front of hosting buyers, founders and engineers.

50k+monthly readers
643articles
Become a sponsor →
Page 2 of 3