security
34 articles tagged security
3 min
Plesk CVE-2026-65646, 65642, and 65647: patch your server
Three critical Plesk flaws expose server files, customer databases, and root access. Check the affected builds and update Plesk plus both extensions.
2026-08-25
5 min
RtabRace (CVE-2026-68138): mitigating the kernel race on CloudLinux
A traffic-control race in the Linux kernel lets any shell user panic a shared server on demand. CloudLinux 8 and 7 Hybrid need the sysctl mitigation today — here's the command and the patch status.
2026-08-18
7 min
CVE-2026-33278: the cpanel-unbound DNSSEC RCE, and how to check for it
A critical Unbound DNSSEC validator bug shipped as cpanel-unbound puts remote code execution one malicious signed zone away, no login required. Patched builds and how to check exposure.
2026-08-17
8 min
Imunify360 vs Wordfence for WordPress hosting providers
A server-wide security suite the host controls vs a per-site plugin the customer buys — how Imunify360 and Wordfence actually differ for a shared WordPress fleet.
2026-08-14
3 min
ImunifyAV vs Imunify360 Unlimited: which one do you need?
We sell two flat-priced Imunify products per server, ImunifyAV and Imunify360 Unlimited, with no account-count tiers. Here is what each one includes and how to pick between them.
2026-08-08
5 min
EasyApache 4 25.69: cPanel patches six Tomcat CVEs in ea-tomcat101
EasyApache 4 25.69 ships Apache Tomcat 10.1.56 in ea-tomcat101, closing six CVEs — an auth-bypass on default servlet constraints among them. Here's what's fixed and how to update.
2026-07-31
7 min
CVE-2026-41940: the cPanel & WHM auth bypass, and how to check for it
A CRLF injection in cpsrvd session handling let unauthenticated attackers write user=root into their own session file. Patched versions, IOCs, and how to check if you were hit.
2026-07-23
6 min
Set up a jailed SSH shell (jailshell) on cPanel & WHM
Give shared-hosting clients SSH without exposing the box — enable cPanel's jailed shell, understand VirtFS, and learn why CageFS should replace it on CloudLinux.
2026-07-17
7 min
Set up the Plesk Firewall extension without locking yourself out
Enable the Plesk Firewall extension, open the right ports, write custom allow/deny rules by IP and country, and use the 60-second rollback so a bad rule never strands you.
2026-07-08
8 min
Softaculous auto-upgrades and backups for hosting fleets
Turn on Softaculous auto-upgrades and automated backups the right way — global admin controls, load thresholds, per-install rollback, remote backup locations, and disk-safe settings.
2026-07-01
6 min
Imunify360 Reputation Management: blacklist monitoring
Imunify360's Reputation Management flags which customer domains have landed on phishing and safe-browsing blacklists — here's how it works, how to read the table, and what to fix.
2026-06-30
6 min
Imunify360 malware cleanup and reinfection workflow
A working runbook for the moment Imunify360 flags malware on a shared box — cleanup vs restore, why quarantine is gone, the CLI commands, and how to stop the reinfection loop.
2026-06-24
8 min
Imunify360 vs BitNinja for hosting server security
Deep CloudLinux-integrated cleanup vs a lightweight honeypot-driven agent — how Imunify360 and BitNinja actually differ on detection, load, and per-server pricing.
2026-06-19
7 min
LiteSpeed anti-DDoS throttling setup on cPanel servers
Configure LiteSpeed's per-client throttling to absorb HTTP floods on cPanel — connection limits, request rates, banned periods, and the Cloudflare real-IP trap.
2026-06-12
7 min
Configure Plesk Fail2Ban jails to stop brute-force attacks
Enable Plesk's Fail2Ban, tune the default jails, whitelist your own IPs, and fix the silent failures where bans show in the panel but never reach iptables.
2026-06-08
8 min
Install Imunify360 on Plesk — what's different from cPanel
Imunify360 on Plesk uses the same agent as the cPanel build, but the install path, ModSecurity handoff, and Fail2Ban interaction are different. Here's the working setup.
2026-05-27
8 min
cPHulk vs CSF/LFD on cPanel — which to run and how they coexist
cPHulk and CSF/LFD overlap on brute-force protection but solve different problems. Here's what each catches, where they fight, and the config to run both cleanly.
2026-05-26
7 min
CloudLinux SecureLinks: stop symlink attacks on shared cPanel hosting
Configure CloudLinux SecureLinks to block cross-account symlink and hardlink attacks on shared cPanel servers — kernel sysctls, Apache directives, and verification.
2026-05-19
8 min
Install ConfigServer CSF on cPanel and tune the defaults
Install ConfigServer Security & Firewall on cPanel/WHM in under 10 minutes — including the csf.conf defaults every host should change before leaving TESTING mode.
2026-05-18
8 min
WHM two-factor authentication: enforce TOTP for root and resellers
Turn on WHM two-factor authentication, enrol root and reseller accounts, audit who has it active, and close the gaps cPanel's built-in 2FA leaves behind — API tokens, SSH, and lost devices.
2026-05-17
9 min
Migrate from CyberPanel to cPanel: a step-by-step playbook
A field-tested migration off CyberPanel onto cPanel — inventory the source, prep the destination, move sites, mail, and DNS with a 30-minute cutover window per site.
2026-05-17
10 min
Imunify AV vs AV+ vs Imunify360: which tier your fleet needs
TuxCare ships three Imunify SKUs at very different price points. Most of the protection lives in only one of them — here's the line and which tier you can skip.
2026-05-17
8 min
Enable DNSSEC for cPanel-hosted zones without breaking resolution
A working DNSSEC rollout for cPanel — enable per-zone signing, publish the DS record at your registrar, verify with dig, and survive the first key rollover without going dark.
2026-05-17
6 min
Tune WHM cPHulk brute force protection without lockouts
A working cPHulk configuration for shared cPanel servers — whitelist, thresholds, country blocking, notifications, and the CLI commands that get you back in when you lock yourself out.
2026-05-16
8 min
Create and scope WHM API tokens for safe automation
WHM API tokens replace root passwords for billing scripts, monitoring agents, and Blesta or WHMCS integrations — here's how to scope them tightly and rotate them safely.
2026-05-16
4 min
Whitelist Plesk ModSecurity rules without breaking ruleset updates
Surgical fixes for Plesk ModSecurity false positives — by rule ID, by IP, per-domain, and per-directory — with snippets that survive ruleset updates.
2026-05-16
10 min
ModSecurity rule sets on cPanel: OWASP CRS vs Comodo cWAF
A practical look at the four ModSecurity rule sets that ship with WHM — OWASP CRS, Comodo cWAF, Atomicorp Basic, and Imunify360 — and when each one is the right pick.
2026-05-16
5 min
Live patching options for hosting fleets compared
KernelCare, Oracle Ksplice, and scheduled reboot windows compared for hosting fleets on coverage, cost, and operational fit.
2026-05-16
8 min
KernelCare live patching on cPanel: zero-reboot kernel CVEs
How to install KernelCare on a cPanel server so kernel CVEs patch live without a reboot — verification commands, rollback steps, and the userspace caveat.
2026-05-16
7 min
Cracked cPanel licenses — why they're cheap and what they cost you
A frank look at the cracked-cPanel-license market — how the bypass works, why cPanel can't kill it, and the real operational and legal cost of running one in production.
2026-05-16
8 min
Set up cPanel Team Manager for delegated account access
Replace shared cPanel passwords with scoped, auditable team users — roles, role limits, 2FA, password expiry, and the WHM toggles you need to flip first.
2026-05-16
8 min
CloudLinux Hardened PHP: legacy PHP without the CVE risk
Backported security fixes for PHP 5.6 through 8.1 let you keep legacy WordPress and Magento customers running on the version their plugins actually need, without the CVE backlog.
2026-05-16
3 min
NGINX Rift (CVE-2026-42945) — what hosting operators need to do
An 18-year-old heap overflow in NGINX's rewrite module — CVSS 9.2, unauthenticated, exploitable from the internet. Here's the patched versions, the config workaround, and how it affects Plesk and cPanel stacks.
2026-05-15
7 min
Install Imunify360 on a cPanel and CloudLinux server
A 20-minute install of Imunify360 on a cPanel + CloudLinux node — license activation, the installer, Proactive Defense, and the three default settings to change before letting customers log in.
2026-05-15