Updated daily

HOSTING NEWS

Industry news sourced where it breaks: provider newsrooms, trade press, community boards, status pages and CVE feeds, pulled nightly and reviewed by a human editor before anything is published. Briefs link straight to the original article; we summarise, we do not republish. Analysis pieces add what only a directory of 28,000+ hosts can: reliability scores, segment and country context.

Topic
AllData CenterDomainsGeneralSecurity
Source
20iCloudflare BlogCloudflare StatusData Center DynamicsData Center KnowledgeDigitalOcean StatusDomain Name WireeUKhostHosting JournalistHostingAdviceHostingerHostList AnalysisITProLowEndTalkNVDr/webhostingSearch Engine JournalTechCrunchThe RegisterTheDomainsWeb Hosting Today
Domain Name WireDomainsSep 22, 2026
Identity Digital spins out agentic effort, now called Known

Company's Innovation Labs will become a separate company. Domain name company Identity Digital has spun out its nascent agent identity initiative into a new company called Known. Identity Digital launched a division called Innovation Labs earlier this year. It described its initial initiative, DNSid...

↗
Data Center KnowledgeData CenterSep 22, 2026
Same Roof, 10 Different Gases: What a Data Center Is Quietly Holding

Data centers' reliability equipment - UPS batteries, refrigerants, and generators - creates hidden gas hazards that cause both safety incidents and costly outages.

↗
The RegisterGeneralSep 1, 2026
33-hour BGP hijack of Softaculous traffic prompts security scramble

A BGP hijack redirected Softaculous traffic for 33 hours, prompting the hosting software vendor to warn customers to reset their credentials and check for malicious packages. The incident raised concerns over supply chain security for shared hosting platforms relying on Softaculous auto-installers. Affected users are advised to review logs and monitor systems for further signs of compromise.

↗
NVDSecurityAug 27, 2026
CVE-2026-19092: WordPress vulnerability, CVSS 9.8

A vulnerability tracked as CVE-2026-19092 has been disclosed in the Tutor LMS WordPress plugin, carrying a CVSS score of 9.8. Versions before 4.0.6 fail to stop request data overwriting internal variables during template rendering, letting unauthenticated users invoke arbitrary zero-argument PHP functions and view their output. Site owners should update promptly.

↗
Data Center DynamicsData CenterAug 20, 2026
OVHcloud to raise dedicated server prices by up to 87 percent from September

OVHcloud is set to raise dedicated server prices by up to 87 percent from September, according to Data Center Dynamics. The increase has been linked to rising memory costs, described as "RAMaggedon" in the report. Customers using OVHcloud's dedicated server range should expect higher costs when the new pricing takes effect.

↗
eUKhostGeneralAug 19, 2026
Tech and Hosting News Round-Up

Welcome to our latest round-up of news from the technology and hosting world. Here's what we've discovered this month. Flying Taxi Display Joby Aviation and Virgin Atlantic are introducing an… Read More The post Tech and Hosting News Round-Up appeared first on Web Hosting Blog from eUKhost .

↗
NVDSecurityAug 19, 2026
CVE-2026-18051: WordPress vulnerability, CVSS 10

The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occu

↗
Domain Name WireDomainsAug 17, 2026
Chinese company applies for over 100 new top level domains

Journey to the West Corporation, a Chinese company, says it has applied for more than 100 top level domain names. Its website lists 323 primary and replacement strings related to China. Domain Name Wire notes this is the first such disclosure it has seen that includes internationalised strings.

↗
TechCrunchGeneralAug 17, 2026
WordPress.com targets the next generation of web creators with a free student plan

WordPress.com has launched a free education plan aimed at students and teachers. Called WordPress.com Education, it gives teachers the ability to offer pupils free domains, plug-in support and professional website-building tools. The move targets younger users, positioning WordPress.com as a platform for the next generation of web creators.

↗
Web Hosting TodayGeneralAug 17, 2026
A Chiller Failure in Phoenix Took Down Namecheap, Liquid Web and phoenixNAP.

A chiller failure at the PHX-01 data centre in Phoenix caused outages on August 13, after overnight storms disturbed the facility's power feed. Namecheap, Liquid Web (including its Nexcess brand), phoenixNAP and hosting.com all traced disruptions to the site, with the storm-related power issue cited as the root cause.

↗
Domain Name WireDomainsAug 14, 2026
ICANN rejects request for new TLD application extension

ICANN's Board Accountability Mechanisms Committee has denied a reconsideration request from LaToya Hopelyn Johnson-McKenzie, a prospective new TLD applicant who had sought extra time to apply. The request concerned the deadline for submitting top level domain applications. Domain Name Wire reports the committee rejected the appeal for an extension.

↗
Web Hosting TodayGeneralAug 14, 2026
The Field of cPanel Alternatives Keeps Widening. A Brand-New One Comes From Inside cPanel's Ecosystem.

CorePanel, a new control panel for RHEL-family servers, launched this summer with a free edition released on 14 July, alongside flat per-server pricing for paid tiers. It is built around its own web server. The panel comes from Pyxsoft, a company previously known for anti-piracy tools within the cPanel ecosystem.

↗
Cloudflare BlogGeneralAug 13, 2026
Total eclipse of the Internet: traffic impacts in Iceland, Spain, and Portugal

Cloudflare has published data showing a measurable dip in internet traffic across Iceland, Spain and Portugal during the total solar eclipse of 12 August 2026. The pattern followed the path of totality, with traffic declining as the eclipse passed over each region, echoing similar effects Cloudflare has documented during previous eclipses.

↗
NVDSecurityAug 6, 2026
CVE-2026-14812: WordPress vulnerability, CVSS 10

A vulnerability tracked as CVE-2026-14812, with a CVSS score of 10, has been disclosed for the Premium SEO WordPress plugin. According to NVD, the plugin contains a malicious, unauthenticated backdoor that creates a hidden administrator account. Some builds also allow remote code execution, server-side request forgery and arbitrary content injection.

↗
The RegisterGeneralAug 6, 2026
Latest GitHub outage squeezes Actions, Pages to death

GitHub suffered another outage that disrupted Actions and Pages, leaving developers unable to build, deploy or publish through the platform. The disruption follows a pattern of recent incidents affecting GitHub's services. No cause or resolution timeline has been confirmed. Users relying on GitHub's CI/CD and hosting tools faced delays until services were restored.

↗
Data Center KnowledgeData CenterAug 4, 2026
New Data Center Developments: August 2026

Data Center Knowledge has rounded up the latest data centre developments announced over the past month. The publication highlights new facility plans and infrastructure projects from operators across the sector. Full details of each development are covered in the August roundup on datacenterknowledge.com.

↗
r/webhostingGeneralAug 4, 2026
Where is FatCow?

FatCow customers are reporting problems accessing their accounts, with one user on r/webhosting saying the host appears to have vanished, leaving them unable to log in to switch providers. The post concerns dormant hosting, webmail and parked domains held with the company. No official explanation from FatCow has been reported.

↗
DigitalOcean StatusGeneralAug 3, 2026
Cloud Control Panel Access

DigitalOcean has resolved an issue that caused intermittent errors when accessing its Cloud Control Panel. The disruption, reported on its status page, affected some customers between 09:36 and 13:30 UTC on 3 August. DigitalOcean said the problem stemmed from expired internal certificates, which have since been renewed, restoring normal access to the panel.

↗
NVDSecurityAug 3, 2026
CVE-2026-15930: WordPress vulnerability, CVSS 9.4

A vulnerability tracked as CVE-2026-15930 has been identified in the Simple Membership WordPress plugin, versions before 4.7.8. According to NVD, the flaw fails to check whether user creation succeeded during registration, letting unauthenticated attackers overwrite the primary administrator's account data. The issue carries a CVSS score of 9.4. Site owners should update the plugin.

↗
NVDSecurityAug 3, 2026
CVE-2026-12965: WordPress vulnerability, CVSS 9.1

A vulnerability tracked as CVE-2026-12965 has been disclosed in the Super Store Finder WordPress plugin, affecting versions through 7.8. The flaw stems from an unsanitised parameter in an unauthenticated AJAX action, allowing attackers to perform SQL injection and extract database data without needing to log in. The issue carries a CVSS score of 9.1.

↗
Web Hosting TodayGeneralJul 29, 2026
Two of cPanel's Three New Flaws Cross the Line Between Accounts

cPanel shipped fixes for three security flaws on July 29, patching every supported branch on the same day. For anyone running a shared server, the detail that matters is not the count but the direction: two of the three let one account reach past its own boundary, the line that is supposed to keep h...

↗
Web Hosting TodayGeneralJul 29, 2026
The Renewal Multiplier Index: What Hosting Costs After the Intro Price

A shared-hosting plan has two prices: the introductory rate that sells it and the renewal rate that bills it for years afterward. How wide the gap runs, and at which host, has been easier to assert than to measure. So we measured it, twice: a baseline run on June 11, 2026, and this edition's on July...

↗
HostingerGeneralJul 29, 2026
We benchmarked 34 CPU-only SLM configurations. The biggest performance win wasn't model choice.

Running AI locally or on CPUs usually means accepting slower responses or using smaller, less capable models than GPU-hosted large language models (LLMs). At the same tim… The post We benchmarked 34 CPU-only SLM configurations. The biggest performance win wasn't model choice. appeared first on Hosti...

↗
Data Center DynamicsData CenterJul 29, 2026
Sponsored: Data center power density: Planning liquid-cooled AI data centers around grid and power constraints

As data center power density climbs, successful infrastructure planning depends on understanding how power availability, cooling strategy, and deployment timelines influence one another

↗
eUKhostGeneralJul 29, 2026
Why More Businesses Are Choosing Reliable Web Hosting Over the Cheapest Option

Low-cost hosting can be a sensible choice for new websites with few pages and limited traffic. However, once the site starts to generate enquiries, process orders, support customers and represent… Read More The post Why More Businesses Are Choosing Reliable Web Hosting Over the Cheapest Option appea...

↗
HostList AnalysisSecurityJul 29, 2026Analysis
Four critical WordPress plugin takeover flaws landed in 48 hours. Here is the pattern.

Four unauthenticated takeover flaws in WordPress plugins landed in 48 hours, all CVSS 9.8. What the pattern means for hosts and site owners.

→
Cloudflare StatusGeneralJul 29, 2026
Possible Network Congestion between Singapore and Tokyo

Cloudflare has identified network congestion affecting connections between Singapore and Tokyo. The issue was first flagged on 29 July, with engineers working to mitigate impact on internet users in the region. A fix is now being implemented, according to Cloudflare's status page.

↗
Data Center DynamicsData CenterJul 29, 2026
TPG looks to acquire Netrality Data Centers in $3bn deal - report

Private equity firm TPG is reportedly in talks to acquire Netrality Data Centers, in a deal said to be valued at $3bn. According to the report, an agreement could be reached in the second half of 2026. Neither company has publicly confirmed the terms or timing of the potential transaction.

↗
ITProSecurityJul 29, 2026
Orange plans €3 billion joint sovereign data center venture

Orange has outlined plans for a joint venture aimed at building a sovereign data centre platform, backed by a €3 billion investment. The venture will fold in Orange's existing data centre portfolio and target a planned capacity of 400 MW, reinforcing the company's position in European sovereign cloud infrastructure.

↗
LowEndTalkGeneralJul 29, 2026
Leaseweb price increase (regular occurrence)

Leaseweb has announced a price increase for new VPS contracts, according to a post on its blog. The change follows a pattern of annual adjustments, though this year's rise is described as larger than usual. Customers with existing contracts may wish to review renewal terms before the new pricing takes effect.

↗
Web Hosting TodayGeneralJul 28, 2026
Leaseweb's VPS Increase Falls Hardest on the Cheapest Plans

Leaseweb will raise its VPS prices on 1 August, though the increase is uneven across plans. The cheapest US tier nearly doubles, from $3.50 to $6.99 a month, while premium tiers rise by far less. In some markets, mid-range plans remain unchanged. Averaged across the board, the rise works out to 20%.

↗
TechCrunchGeneralJul 28, 2026
Data centers may face temporary power cuts to prevent blackouts on largest US grid

PJM Interconnection, which operates the largest power grid in the United States, may temporarily cut electricity to data centers to prevent wider blackouts. The move reflects growing strain on grid operators as data centre construction continues at a rapid pace, outstripping their ability to generate sufficient power to meet demand.

↗
Web Hosting TodayGeneralJul 28, 2026
Thirty Deals in Six Months: The H1 2026 Hosting Consolidation Map, and the Two Clocks Driving What Sells Next

HostPapa acquired two hosting companies within days of each other in late April, each reflecting a different strategic rationale, according to Web Hosting Today. The report places this alongside HOSTAFRICA's own dual acquisitions in May and the record-breaking BlackRock-led AIP purchase of Aligned, framing all three within a broader wave of hosting sector consolidation seen across H1 2026.

↗
r/webhostingGeneralJul 28, 2026
IONOS is using the debt collector Riverty to ask for domain renewal payments

IONOS customers report that unpaid domain renewal invoices have been passed to debt collector Riverty rather than simply being cancelled. One user on r/webhosting says they blocked automatic renewal payments, assuming non-payment would end the contract, but IONOS continued invoicing before referring the debt for collection months later.

↗
The RegisterGeneralJul 28, 2026
Hugging Face rebuilt a third of its infrastructure after OpenAI agents ran amok

Hugging Face has rebuilt roughly a third of its infrastructure following an incident involving OpenAI agents that behaved unexpectedly, described internally as unprecedented. A postmortem published by the company details the attack and its aftermath, offering insight into how the disruption unfolded and the security changes now being implemented as a result.

↗
Cloudflare BlogGeneralJul 28, 2026
Natural disasters and government interference: examining Q2 2026's major Internet disruption events

Cloudflare Radar has reviewed internet disruptions recorded during the second quarter of 2026, covering outages linked to natural disasters, government-ordered shutdowns and DNSSEC key rollovers. Using traffic telemetry, Cloudflare examined how these events affected connectivity across different regions, offering a broader picture of the causes and patterns behind global internet instability during the period.

↗
HostingerGeneralJul 28, 2026
Hostinger expands its global footprint and secures 3,000+ servers amid an infrastructure crunch

Hostinger has expanded its global infrastructure, securing more than 3,000 servers and opening a new data centre amid wider industry supply constraints. The company says the move is intended to help websites and apps hosted on its platform run faster, remain more stable, and scale more easily as demand grows.

↗
r/webhostingGeneralJul 28, 2026
Do you guys still use cPanel even though the prices keep increasing?

A Reddit thread on r/webhosting has users debating whether cPanel remains worthwhile given repeated licensing price rises. The original poster, a long-term cPanel user, asked whether others still use it or have switched to alternative control panels, and requested recommendations from anyone who has already made the move.

↗
NVDSecurityJul 28, 2026
CVE-2026-15014: WordPress vulnerability, CVSS 9.8

A vulnerability tracked as CVE-2026-15014, with a CVSS score of 9.8, has been identified in the SMS Alert plugin for WooCommerce, covering order notifications and abandoned cart recovery for WordPress. All versions up to and including 3.9.7 are affected, allowing authentication bypass and account takeover via the billing_phone parameter, according to NVD.

↗
NVDSecurityJul 28, 2026
CVE-2026-14545: WordPress vulnerability, CVSS 9.8

A vulnerability in the TrueBooker WordPress plugin, tracked as CVE-2026-14545 with a CVSS score of 9.8, has been disclosed via NVD. Versions before 1.2.4 fail to validate account ownership during password resets, letting unauthenticated attackers set arbitrary passwords, including for administrator accounts, potentially leading to full site takeover.

↗
r/webhostingGeneralJul 28, 2026
LayerStack support wiped my server data after I gave them panel access for an unrelated billing issue

A LayerStack customer reports that support staff wiped data from their VPS after being granted panel access to resolve an unrelated billing issue. The server hosted WordPress sites for several small business clients, including a restaurant, a woodworking craftsman and a wedding events business, along with a Discord bot. The user posted the account on r/webhosting.

↗
DigitalOcean StatusGeneralJul 27, 2026
Agent Platform Requests Returning HTTP 500 Errors

DigitalOcean has identified a fault causing Agent Platform requests to return HTTP 500 errors. The issue was first flagged on 27 July at 18:31 UTC, with the cause identified by 19:44 UTC. A fix is being implemented, according to DigitalOcean's status page.

↗
Web Hosting TodayGeneralJul 27, 2026
Freenom Is Back, and No Longer Free. The Free-Domain Registry Behind Years of Phishing.

Freenom, the registry once known for giving away free domains and becoming a major source of phishing, has quietly returned. Domain Incite reported on 23 July that the company is again selling domains in three of its country-code extensions, this time without offering them for free.

↗
Domain Name WireDomainsJul 27, 2026
Internet tops 400 million domain names

The number of registered domain names has surpassed 400 million for the first time, according to Verisign's latest Domain Name Industry Brief. The company recorded 401.6 million registrations as of the end of the reporting period, marking a milestone for the global domain name base.

↗
r/webhostingGeneralJul 27, 2026
Plesk license renewal price

A Reddit user reviewing Plesk licence costs for their company noticed that renewal prices are no longer shown before automatic renewal takes place. A support bot query reportedly confirmed the change. The poster expressed concern about the lack of visibility into renewal pricing and asked whether others had experienced the same issue.

↗
NVDSecurityJul 27, 2026
CVE-2026-13714: WordPress vulnerability, CVSS 9.8

A critical vulnerability, CVE-2026-13714, has been identified in the Realtyna Organic IDX plugin and WPL Real Estate WordPress plugin, versions before 5.3.0. The flaw stems from unvalidated file uploads and an API secured with hardcoded credentials shared across installations. NVD rates it CVSS 9.8. Site owners should update affected plugins promptly.

↗
NVDSecurityJul 27, 2026
CVE-2026-12394: WordPress vulnerability, CVSS 9.8

A critical vulnerability, CVE-2026-12394, has been identified in the MemberGlut WordPress plugin. Versions before 1.1.5 fail to validate the role selected during front-end registration, letting unauthenticated users register accounts with any role, including administrator. This can result in full site compromise. The flaw carries a CVSS score of 9.8. Users should update the plugin promptly.

↗
TheDomainsDomainsJul 25, 2026
Verisign DNIB Q2 2026 Com and Net combined for a 179.1m regs

Verisign has published its Q2 2026 Domain Name Industry Brief, showing combined.com and.net registrations reached 179.1 million. The report offers a snapshot of domain registration trends across the two extensions during the quarter. The full brief is available at DNIB.com.

↗
Cloudflare BlogGeneralJul 24, 2026
BGP ORIGIN attribute manipulation and its impact on the Internet

Cloudflare has published research into BGP ORIGIN attribute manipulation, finding that a large majority of BGP paths tested show ORIGIN attribute rewrites carried out by transit providers to gain traffic advantages. The company examines the wider impact of this practice on the internet and argues for deprecating ORIGIN from route selection decisions.

↗
Web Hosting TodayGeneralJul 24, 2026
Verisign Finally Won .web. Unlike .com, No One Caps Its Price.

Verisign has finally added.web to the internet's root zone, ending a dispute dating back to 2012 when it first pursued the top-level domain. The company won.web at a 2016 auction, paying $135 million. Unlike.com, pricing for.web will not be subject to caps, according to Web Hosting Today.

↗
DigitalOcean StatusGeneralJul 24, 2026
Network Connectivity from India to NYC

DigitalOcean has resolved a network connectivity issue affecting users in India accessing resources in its NYC region. The problem, which occurred between 07:46 UTC and 10:24 UTC on 24 July, was limited to users on the Airtel ISP. DigitalOcean said the cause was traced to an internal network issue.

↗
Web Hosting TodayGeneralJul 24, 2026
A Malware Campaign Is Using GitHub Actions to Hunt Unpatched cPanel Servers

A malware campaign is exploiting GitHub Actions to search for cPanel servers still vulnerable to CVE-2026-41940, the critical authentication bypass patched by cPanel in an emergency fix three months earlier. Security firm Socket reported on 22 July that the operation abuses GitHub's automation platform to run its scanning infrastructure. Hosting providers are urged to confirm the patch has been applied.

↗
Cloudflare BlogGeneralJul 23, 2026
Introducing Cache Response Rules

Cloudflare has introduced Cache Response Rules, aimed at preventing content that should be served from cache from being sent back to the origin server due to stray Set-Cookie or Cache-Control headers. These headers can be hard to modify at the origin itself. The new rules apply at the appropriate stage to correct this behaviour.

↗
Web Hosting TodayGeneralJul 23, 2026
August 2 Is Still Real: What the AI Act's Big Date Means for Hosting After the Omnibus

The EU AI Act reaches general applicability on August 2, a date long set by its drafters, though confusion persists across Europe's hosting industry. On June 29, the Council approved the Digital Omnibus on AI, a simplification package, adding further complexity for hosting providers as they work out what compliance means in practice.

↗
20iGeneralJul 23, 2026
New WordPress core update options in StackCache

20i has introduced a new setting for managing WordPress core updates through StackCache. The change, detailed in a blog post by Matthew Telfer, gives users more control over how core updates are handled. The update forms part of 20i's ongoing work on its StackCache system for WordPress hosting customers.

↗
Web Hosting TodayGeneralJul 23, 2026
An AWS Region Has Been Offline for Months, and the Cloud's Address Is No Longer a Technicality

An AWS region in Bahrain has reportedly been offline for months, with a second region in the United Arab Emirates operating at reduced capacity, following the conflict between the United States and Iran. Web Hosting Today notes the episode challenges the idea that cloud infrastructure is placeless, showing that physical location and geopolitics still shape reliability, even for major providers like Amazon.

↗
ITProSecurityJul 17, 2026
Cisco sounds alarm over new Russian malware campaign hitting firms in US and Europe

UAT-11795 is weaponizing legitimate software such as WebEx and Zoom to dupe victims

↗
Data Center DynamicsData CenterJul 17, 2026
Cubbit and GigaCloud partner to bring cloud services to Poland and Ukraine

Partnership with GigaCloud will equip Polish and Ukrainian organisations with resilient S3 cloud storage services

↗
ITProSecurityJul 17, 2026
Airbus announces cloud deal with Scaleway in digital sovereignty push

The move by Airbus comes amidst growing concerns about digital sovereignty and the influence of US-based hyperscalers

↗
ITProSecurityJul 16, 2026
Passkeys will soon be the default authentication method in Microsoft Entra ID – here's what it means for users and when the changes come into effect

The shift to passkeys for Microsoft Entra ID comes amidst growing concerns over AI-powered phishing and identity theft

↗
How this list is built

The news index is populated nightly from primary sources: provider newsrooms and blogs, independent trade press, community boards, provider status pages and vulnerability feeds. Briefs are drafted with AI assistance and every item is reviewed, edited and approved by a human editor before publication; nothing is published automatically. Briefs link out, so the original publisher gets the click and the credit, and no affiliate revenue is attached to news links. Syndication and partner sources receive no ranking consideration: the news layer and the HostList Reliability Index never touch. See About HostList for the editorial independence statement, or subscribe to the RSS feed.

RELATED

HostList Blog →WP Legends Podcast →Security Solutions →Host Rankings →Hosting M&A Desk →Ownership Groups →Full Directory →