Security — Web Hosting News

Latest Security news, updates and analysis from the web hosting industry — 79 articles.

Other
Automattic Is Not an Owner of the WordPress Marks It Asserted in Court, a Judge Rules
Natalia Nowak · 29 Sep 2026 · 6 min read
#automattic#web-hosting#wordpress
The September 24 order brings back four antitrust claims the same judge had dismissed in an earlier ruling. It also holds that Automattic and Mullenweg are neither owners nor registrants of the WordPress marks, so they cannot assert them in their own right.
All Security articles
41–60 of 79
Security
Three Unauthenticated File Flaws in a Week, and One Root Cause: Validation by Shortcut
by Natalia Nowak · 10 Jul 2026 · 5 min read
Between July 7 and 9, three serious unauthenticated flaws surfaced in file-handling code: an RCE in Blocksy Companion Pro, arbitrary file deletion in Frontend File Manager, and an SSRF in Monsta FTP. Different codebases, one root cause, and a blast radius that lands on the hosting provider.
Security
Hostinger Turns On Patchstack npm Scanning for Node.js Apps by Default
by Natalia Nowak · 8 Jul 2026 · 4 min read
Hostinger has built Patchstack's vulnerability intelligence into its Node.js hosting, scanning npm dependencies by default. It targets the unmonitored supply-chain risk of apps shipped fast with AI help, and fits Patchstack's push to embed its security inside large hosts rather than as an upsell.
Security
India’s .bank.in Trust Domain Leaked the Data of the People Who Run It
by Natalia Nowak · 3 Jul 2026 · 4 min read
India's .bank.in namespace was RBI's trust badge against banking phishing. Its registrar, IDRBT, left 33+ unauthenticated APIs exposing bcrypt hashes, emails, phone numbers and device fingerprints of 5,576 domain admins for 13 months. It was fixed in June 2026, with no confirmed exploitation.
Security
Europe’s Hosts Bundle Email to Keep Customers. One in Four Mailboxes Has No SPF.
by Natalia Nowak · 30 Jun 2026 · 4 min read
ShareShift's State of Email 2026 scanned 56.3M European domains and found three in four run an active mailbox, a powerful retention lever. But 1 in 4 mailboxes has no SPF record. Strato attaches mail to 94% of new domains and configures SPF on 6%, while IONOS, All-Inkl and OVH bundle and protect.
Security
2,930 of 2,931 Exposed MySQL Databases Were Already Marked by Ransomware. The Playbook Is Six Years Old.
by Natalia Nowak · 29 Jun 2026 · 5 min read
A 2026 study found 2,930 of 2,931 exposed MySQL databases were marked by ransomware. One in four organizations still exposes MySQL, and honeypots get hit within 30 seconds. The PLEASE_READ_ME playbook from 2020 still works because the databases are not being broken into. They are being left open.
Security
An Attacker Sent a Ransom Email From Blesta’s Own Servers
by Łukasz Nowak · 26 Jun 2026 · 9 min read
An extortion email demanding Blesta pay up passed SPF, DKIM and DMARC from Blesta's own servers, pointing to a real compromise. Blesta has not confirmed one.
Industry reports
The File Nobody Watches: llms.txt Is the Hosting Industry’s Newest Attack Surface
by Łukasz Nowak · 22 Jun 2026 · 17 min read
110 hosting-industry domains publish an llms.txt that AI agents read verbatim, and a single edit can feed customers a rogue download or an attacker's phone number. Zero of the 110 are signed or monitored. Every piece of the attack is already proven; nobody is guarding the file.
Security
MariaDB Patches CVSS 10.0 Remote Code Execution Vulnerability in Galera Cluster Feature
by Natalia Nowak · 15 Jun 2026 · 3 min read
MariaDB patched a CVSS 10.0 remote code execution flaw (CVE-2026-49261) on May 27, disclosed publicly on June 11. The vulnerability is in wsrep_notify_cmd, a Galera Cluster feature. Standalone MariaDB is not at risk. Two additional CVSS 8.0 CVEs were fixed in the same update.
Security
HTTP/2 Bomb: One Connection Crashes Web Servers. nginx Is Patched, Apache Is Not.
by Natalia Nowak · 3 Jun 2026 · 6 min read
Single-connection HTTP/2 attack crashes web servers. nginx is patched today; Apache's fix has not reached distribution package managers.
Security
A Database Allegedly From Home.pl Is Being Advertised on a Cybercrime Forum.
by Łukasz Nowak · 29 May 2026 · 8 min read
A dataset allegedly from Home.pl, Poland's largest hosting provider, is being advertised on a cybercrime forum. We analyze the schema and what it means for 300,000+ customers.
Security
The Exploit Record: How Government Networks Keep Getting Breached
by Natalia Nowak · 29 May 2026 · 14 min read
CVE-2026-41940 was exploited as a zero-day for 68 days before a patch existed. CISA was breached via Ivanti vulnerabilities it had just ordered patched. Volt Typhoon had 5-year US infrastructure access. The case-by-case record of how government networks keep getting owned.
Security
CVE-2026-48172: LiteSpeed cPanel Plugin Root Privilege Escalation, CVSS 10.0, Actively Exploited
by Natalia Nowak · 27 May 2026 · 3 min read
CVE-2026-48172 in LiteSpeed User-End cPanel Plugin (2.3-2.4.4) lets any authenticated cPanel user run arbitrary scripts as root. CVSS 10.0, actively exploited, on the CISA KEV list. Patch to WHM Plugin 5.3.1.0 / cPanel Plugin 2.4.7 immediately.
Security
FunnelKit Plugin Flaw Actively Exploited to Skim Credit Cards From WooCommerce Checkout Pages
by Natalia Nowak · 18 May 2026 · 4 min read
Every customer who checked out on a WooCommerce store running an unpatched FunnelKit plugin may have had their card number, CVV, and billing address stolen. The attack is active across more than 40,000 sites. Patch to version 3.15.0.3, released May 14, 2026, and assess breach notification obligations.
Security
A Ransomware Group’s Backend Was Leaked Because Their Hosting Provider Got Hacked First.
by Natalia Nowak · 15 May 2026 · 4 min read
On May 2, hosting provider 4VPS disclosed a breach of its billing systems. Two days later, The Gentlemen ransomware group's backend appeared for sale online. Check Point Research confirmed the dataset included victim lists, ransom negotiations, and internal communications from one of 2026's most active ransomware operations.
Security
Skynethosting Took Its Entire cPanel Fleet Offline on May 1. Two Weeks Later, Some Are Still Down.
by Natalia Nowak · 15 May 2026 · 10 min read
Skynethosting took its entire cPanel fleet offline on May 1 in response to CVE-2026-41940, and as of May 14 some customer servers had been down for nearly two weeks, with one reseller publicly reporting a 30 percent client loss during the outage.
Security
Fragnesia: A New Linux Kernel Privilege Escalation That Emerged From Prior Kernel Patches
by Łukasz Nowak · 14 May 2026 · 3 min read
William Bowling of V12 Security disclosed Fragnesia on May 13, 2026, a Linux kernel privilege escalation that allows an unprivileged local attacker to reach root by corrupting the kernel page cache through the XFRM ESP-in-TCP subsystem.
Security
Nginx Just Patched old Rewrite Module Flaw. RCE Was Possible With a Single HTTP Request.
by Łukasz Nowak · 14 May 2026 · 6 min read
A flaw sitting in nginx since 2008 was patched on May 13, 2026. CVSS 9.2, unauthenticated, and present in the default rewrite module.
Security
cPanel Patched Five More CVEs. One Fix Is Already Reported Incomplete.
by Natalia Nowak · 14 May 2026 · 9 min read
cPanel's May 13 patch covers five new CVEs, but security researcher Shubham Shah reported within hours that the fix for CVE-2026-29205 is incomplete and all cPanel instances remain exploitable until a working patch lands.
Security
Three cPanel Patches and DirtyFrag Fixes in One Day. Here Is Where Things Stand.
by Natalia Nowak · 13 May 2026 · 6 min read
On May 8, cPanel closed three new vulnerabilities and Linux distributions shipped DirtyFrag kernel fixes. Two weeks of disclosures left providers with three separate patch tracks. Here is the complete status and the confirmations every shared hosting customer should request.
Security
A Compromised Server Is the Beginning. Here Is What Breach Law Requires Next.
by Łukasz Nowak · 13 May 2026 · 35 min read
Change Healthcare's $3.1 billion in breach costs is the new normal of what a serious compromise sets in motion: parallel notification clocks across GDPR, NIS2, DORA, and HIPAA; personal liability for CISOs and boards; and a cyber insurance market with conditions that can deny coverage at the worst moment.
📬

Stay in the loop

Weekly digest of the best hosting news, reviews and industry moves.

Page 3 of 4