Flippa Promoted the Plugin Portfolio Sale as a Success Story. It Was a Supply Chain Attack.

Flippa celebrated the six-figure sale of the Essential Plugin portfolio; eight months later the buyer activated a backdoor across 20,000+ WordPress sites using Googlebot cloaking and a C2 routed through an Ethereum smart contract.

How to Sell Security in Hosting (Without Scaring Your Customers)

There’s a moment in the hosting sales flow where everything can quietly fall apart. The customer has picked a plan, they’re ready to buy, and...

Critical Grafana Enterprise SCIM Flaw Hits Hosting Providers: Why Staying Updated Matters

Grafana has released a set of emergency security patches after discovering a critical vulnerability in its Enterprise editions. The flaw, tracked as CVE-2025-41115, carries the maximum CVSS score of 10.0 and affects environments where the SCIM feature is enabled and used for automated user provisioning.

CentralNic Reseller Announces Auth-Code Rotation After Suspicious Activity

A recent message from CentralNic Reseller addressed to its customers reveals that the company has observed “activity outside our operational systems that we are investigating” and is taking precautionary measures. The announcement states that while there is no confirmed impact on operational systems or customer data.