Tag: security

50 articles

Security
Hostinger Turns On Patchstack npm Scanning for Node.js Apps by Default
by Natalia Nowak · 8 Jul 2026 · 4 min read
Hostinger built Patchstack's npm dependency scanning into its Node.js hosting, on by default, targeting the supply-chain risk of fast-shipped, AI-assisted apps.
Security
An Attacker Sent a Ransom Email From Blesta’s Own Servers
by Łukasz Nowak · 26 Jun 2026 · 9 min read
An extortion email demanding Blesta pay up passed SPF, DKIM and DMARC from Blesta's own servers, pointing to a real compromise. Blesta has not confirmed one.
Industry reports
The File Nobody Watches: llms.txt Is the Hosting Industry’s Newest Attack Surface
by Łukasz Nowak · 22 Jun 2026 · 17 min read
Anyone can slip a fake support line or rogue download into a hosting firm's llms.txt, and AI agents repeat it as fact. Nothing on the domain is watching.
Security
MariaDB Patches CVSS 10.0 Remote Code Execution Vulnerability in Galera Cluster Feature
by Natalia Nowak · 15 Jun 2026 · 3 min read
CVE-2026-49261 scores CVSS 10.0 and allows unauthenticated RCE in MariaDB Galera Cluster deployments. Standalone installations are not affected. Patches shipped May 27.
Other
Protect The Shire: WordPress Adds a 24-Hour Default Delay to Plugin Auto-Updates
by Natalia Nowak · 8 Jun 2026 · 9 min read
WordPress.org made the 24-hour plugin auto-update delay default for every new release on June 5, 2026. Mullenweg calls it Protect The Shire.
Security
HTTP/2 Bomb: One Connection Crashes Web Servers. nginx Is Patched, Apache Is Not.
by Natalia Nowak · 3 Jun 2026 · 6 min read
Single-connection HTTP/2 attack crashes web servers. nginx is patched today; Apache's fix has not reached distribution package managers.
Security
A Database Allegedly From Home.pl Is Being Advertised on a Cybercrime Forum.
by Łukasz Nowak · 29 May 2026 · 8 min read
A dataset allegedly from Home.pl, Poland's largest hosting provider, is being advertised on a cybercrime forum. We analyze the schema and what it means for 300,000+ customers.
Security
The Exploit Record: How Government Networks Keep Getting Breached
by Natalia Nowak · 29 May 2026 · 14 min read
A cPanel zero-day hit Guam. CISA got breached through Ivanti. Salt Typhoon accessed US wiretap systems. The case file of government breaches.
Security
CVE-2026-48172: LiteSpeed cPanel Plugin Root Privilege Escalation, CVSS 10.0, Actively Exploited
by Natalia Nowak · 27 May 2026 · 3 min read
LiteSpeed cPanel Plugin CVE-2026-48172 (CVSS 10.0) lets any cPanel user execute scripts as root. Actively exploited. Patch to 2.4.7 now.
Security
FunnelKit Plugin Flaw Actively Exploited to Skim Credit Cards From WooCommerce Checkout Pages
by Natalia Nowak · 18 May 2026 · 4 min read
A FunnelKit vulnerability is being actively exploited to steal card data from WooCommerce checkouts. Every customer who paid on a compromised store is affected. Patch to 3.15.0.3 now.
🚀

Reach hosting professionals

Sponsor webhosting.today and get in front of hosting buyers, founders and engineers.

50k+monthly readers
672articles
Become a sponsor →
📬

Stay in the loop

Weekly digest of the best hosting news, reviews and industry moves.