Industry news sourced where it breaks: provider newsrooms, trade press, community boards, status pages and CVE feeds, pulled nightly and reviewed by a human editor before anything is published. Briefs link straight to the original article; we summarise, we do not republish. Analysis pieces add what only a directory of 28,000+ hosts can: reliability scores, segment and country context.
The W3 Total Cache WordPress plugin before 2.10.5 does not properly validate the request path it uses to build cache file names, allowing unauthenticated attackers to write a file into any existing directory on the server, inside or outside the web root, overwriting whatever occu
A vulnerability tracked as CVE-2026-14812, with a CVSS score of 10, has been disclosed for the Premium SEO WordPress plugin. According to NVD, the plugin contains a malicious, unauthenticated backdoor that creates a hidden administrator account. Some builds also allow remote code execution, server-side request forgery and arbitrary content injection.
The news index is populated nightly from primary sources: provider newsrooms and blogs, independent trade press, community boards, provider status pages and vulnerability feeds. Briefs are drafted with AI assistance and every item is reviewed, edited and approved by a human editor before publication; nothing is published automatically. Briefs link out, so the original publisher gets the click and the credit, and no affiliate revenue is attached to news links. Syndication and partner sources receive no ranking consideration: the news layer and the HostList Reliability Index never touch. See About HostList for the editorial independence statement, or subscribe to the RSS feed.
A vulnerability tracked as CVE-2026-15930 has been identified in the Simple Membership WordPress plugin, versions before 4.7.8. According to NVD, the flaw fails to check whether user creation succeeded during registration, letting unauthenticated attackers overwrite the primary administrator's account data. The issue carries a CVSS score of 9.4. Site owners should update the plugin.
A vulnerability tracked as CVE-2026-12965 has been disclosed in the Super Store Finder WordPress plugin, affecting versions through 7.8. The flaw stems from an unsanitised parameter in an unauthenticated AJAX action, allowing attackers to perform SQL injection and extract database data without needing to log in. The issue carries a CVSS score of 9.1.
Four unauthenticated takeover flaws in WordPress plugins landed in 48 hours, all CVSS 9.8. What the pattern means for hosts and site owners.
Orange has outlined plans for a joint venture aimed at building a sovereign data centre platform, backed by a β¬3 billion investment. The venture will fold in Orange's existing data centre portfolio and target a planned capacity of 400 MW, reinforcing the company's position in European sovereign cloud infrastructure.
A vulnerability tracked as CVE-2026-15014, with a CVSS score of 9.8, has been identified in the SMS Alert plugin for WooCommerce, covering order notifications and abandoned cart recovery for WordPress. All versions up to and including 3.9.7 are affected, allowing authentication bypass and account takeover via the billing_phone parameter, according to NVD.
A vulnerability in the TrueBooker WordPress plugin, tracked as CVE-2026-14545 with a CVSS score of 9.8, has been disclosed via NVD. Versions before 1.2.4 fail to validate account ownership during password resets, letting unauthenticated attackers set arbitrary passwords, including for administrator accounts, potentially leading to full site takeover.
A critical vulnerability, CVE-2026-13714, has been identified in the Realtyna Organic IDX plugin and WPL Real Estate WordPress plugin, versions before 5.3.0. The flaw stems from unvalidated file uploads and an API secured with hardcoded credentials shared across installations. NVD rates it CVSS 9.8. Site owners should update affected plugins promptly.
A critical vulnerability, CVE-2026-12394, has been identified in the MemberGlut WordPress plugin. Versions before 1.1.5 fail to validate the role selected during front-end registration, letting unauthenticated users register accounts with any role, including administrator. This can result in full site compromise. The flaw carries a CVSS score of 9.8. Users should update the plugin promptly.
UAT-11795 is weaponizing legitimate software such as WebEx and Zoom to dupe victims
The move by Airbus comes amidst growing concerns about digital sovereignty and the influence of US-based hyperscalers
The shift to passkeys for Microsoft Entra ID comes amidst growing concerns over AI-powered phishing and identity theft
Battle over acquisition and subsequent partnership and licensing changes continues
The deal expands BarracudaONE with new identity and access management capabilities tailored to the needs of MSPs
Researchers at Nebula said the GhostLock exploit is 97% reliable and can escape containers
Malicious repositories can trick advanced AI agents into silently breaking out of their workspace sandboxes
The tie-up includes a new model of industrialized ransomware deployment that significantly lowers the barrier to entry for cyber crime
CISA has added a critical cPanel bug to its known-exploited list, confirming that attackers are already poking holes in one of the internet's most widely used hosting stacks. The vulnerability, tracked as CVE-2026-41940, carries a near-worst-case CVSS score of 9.8 and affects all supported versions ...
The US Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that hackers are exploiting a max-severity remote code execution (RCE) vulnerability in workflow automation platform n8n. The bug was first disclosed in December, and vendors such as Resecurity said that of n8n's roughly 23...
Bug of the year (so far): Nasty cPanel vulnerability probably exploited as a 0-day. Emergency patches out now for those managing the millions of
GoDaddy's analysis of 1.1 million infected websites revealed that malware and malicious redirects dominated the threat landscape, accounting for
cPanel released another security update on May 13, 2026, addressing five additional vulnerabilities: CVE-2026-29205, CVE-2026-29206, CVE-2026-