Tag: security

50 articles

Security
CVE-2026-41940 Live: cPanel Authentication Bypass, Active Exploitation, and What Comes Next
by Łukasz Nowak · 4 May 2026 · 13 min read
CVE-2026-41940, the cPanel authentication bypass exploited for 64 days before disclosure, is still developing. 44,000 servers likely compromised, a public exploit on GitHub, three active campaigns. This page is updated in real time as new information surfaces.
Security
The cPanel Zero-Day Was Active for 64 Days Before Anyone Knew
by Łukasz Nowak · 3 May 2026 · 9 min read
CVE-2026-41940, the cPanel authentication bypass from April 28, was being exploited since February 23, operated as a zero-day for 64 days, and was added to CISA's Known Exploited Vulnerabilities list with 1.5 million internet-exposed instances counted by Rapid7.
Security
Copy Fail: Any Local User Can Get Root on Nearly Every Linux System Since 2017
by Łukasz Nowak · 1 May 2026 · 4 min read
Copy Fail (CVE-2026-31431) is a Linux kernel privilege escalation giving any unprivileged local user root access, affecting virtually all distributions since 2017, with shared hosting and multi-tenant environments at highest risk.
Security
cPanel Had an Authentication Bypass. Exploits Were Already in the Wild.
by Łukasz Nowak · 29 Apr 2026 · 5 min read
cPanel disclosed a critical authentication bypass on April 28 affecting nearly all versions of cPanel and WHM, with active exploits confirmed in the wild before the patch was released, forcing hosting.com, Namecheap, KnownHost, HostPapa, and InMotion Hosting to take cPanel access offline globally.
Security
Four Tiers of OpenClaw Hosting. Three Have a Security Problem.
by Natalia Nowak · 28 Apr 2026 · 8 min read
OpenClaw has 138 documented security advisories and a market fractured into four tiers, ranging from $3.85 managed VPS to NVIDIA's NemoClaw enterprise stack and Cloudflare's ephemeral-container proof-of-concept.
Security
Flippa Promoted the Plugin Portfolio Sale as a Success Story. It Was a Supply Chain Attack.
by Łukasz Nowak · 17 Apr 2026 · 6 min read
Flippa celebrated the six-figure sale of the Essential Plugin portfolio; eight months later the buyer activated a backdoor across 20,000+ WordPress sites using Googlebot cloaking and a C2 routed through an Ethereum smart contract.
Security
Turning Challenges into Revenue Opportunities: How PRO Hacked Site Repair Services Can Reduce Churn for Agencies and Web Hosts
by Akshay Kumar · 16 Apr 2026 · 6 min read
When a client's website gets compromised, the hosting provider's response in the next few hours determines whether that client is still a customer next month.
Other
Let’s Encrypt Changes Its Root Certificates on May 13. Client Auth Ends July 8
by Natalia Nowak · 15 Apr 2026 · 7 min read
Let's Encrypt replaces its root certificate hierarchy on May 13, closes client authentication support permanently on July 8, and hosting operators have less than four weeks to verify their renewal automation handles the transition.
Security
World Backup Day 2026: The Threat Model Has Changed. The Advice Has Not.
by Łukasz Nowak · 31 Mar 2026 · 7 min read
The 3-2-1 backup rule was designed for hardware failure and accidental deletion, not for an attacker who has your credentials and can authenticate to your backup console before triggering ransomware.
Security
European Commission Confirms AWS Account Breach: A Customer-Side Failure With EU Cloud Sovereignty Implications
by Łukasz Nowak · 30 Mar 2026 · 6 min read
The European Commission confirmed attackers accessed its AWS-hosted Europa.eu infrastructure and took data. AWS says its platform was not the issue, the customer account configuration was.
🚀

Reach hosting professionals

Sponsor webhosting.today and get in front of hosting buyers, founders and engineers.

50k+monthly readers
672articles
Become a sponsor →
📬

Stay in the loop

Weekly digest of the best hosting news, reviews and industry moves.