Tag: security
50 articles
Security
Hostinger Turns On Patchstack npm Scanning for Node.js Apps by Default
Hostinger built Patchstack's npm dependency scanning into its Node.js hosting, on by default, targeting the supply-chain risk of fast-shipped, AI-assisted apps.
Security
An Attacker Sent a Ransom Email From Blesta’s Own Servers
An extortion email demanding Blesta pay up passed SPF, DKIM and DMARC from Blesta's own servers, pointing to a real compromise. Blesta has not confirmed one.
Industry reports
The File Nobody Watches: llms.txt Is the Hosting Industry’s Newest Attack Surface
Anyone can slip a fake support line or rogue download into a hosting firm's llms.txt, and AI agents repeat it as fact. Nothing on the domain is watching.
Security
MariaDB Patches CVSS 10.0 Remote Code Execution Vulnerability in Galera Cluster Feature
CVE-2026-49261 scores CVSS 10.0 and allows unauthenticated RCE in MariaDB Galera Cluster deployments. Standalone installations are not affected. Patches shipped May 27.
Other
Protect The Shire: WordPress Adds a 24-Hour Default Delay to Plugin Auto-Updates
WordPress.org made the 24-hour plugin auto-update delay default for every new release on June 5, 2026. Mullenweg calls it Protect The Shire.
Security
HTTP/2 Bomb: One Connection Crashes Web Servers. nginx Is Patched, Apache Is Not.
Single-connection HTTP/2 attack crashes web servers. nginx is patched today; Apache's fix has not reached distribution package managers.
Security
A Database Allegedly From Home.pl Is Being Advertised on a Cybercrime Forum.
A dataset allegedly from Home.pl, Poland's largest hosting provider, is being advertised on a cybercrime forum. We analyze the schema and what it means for 300,000+ customers.
Security
The Exploit Record: How Government Networks Keep Getting Breached
A cPanel zero-day hit Guam. CISA got breached through Ivanti. Salt Typhoon accessed US wiretap systems. The case file of government breaches.
Security
CVE-2026-48172: LiteSpeed cPanel Plugin Root Privilege Escalation, CVSS 10.0, Actively Exploited
LiteSpeed cPanel Plugin CVE-2026-48172 (CVSS 10.0) lets any cPanel user execute scripts as root. Actively exploited. Patch to 2.4.7 now.
Security
FunnelKit Plugin Flaw Actively Exploited to Skim Credit Cards From WooCommerce Checkout Pages
A FunnelKit vulnerability is being actively exploited to steal card data from WooCommerce checkouts. Every customer who paid on a compromised store is affected. Patch to 3.15.0.3 now.
Reach hosting professionals
Sponsor webhosting.today and get in front of hosting buyers, founders and engineers.
50k+monthly readers
672articles