Announcements

It's time to say goodbye to X3

  • 22nd March 2017
Over the past year, we’ve talked prominently about the impending deprecation of X3, the previous generation user interface for cPanel. Today’s the day we are officially announcing a deprecation schedule and its eventual removal from the product. Here’s the schedule: In 11.52… Brand new installations of cPanel & WHM will consider ...
Continue reading

Major Cloudflare bug leaked sensitive data from customers’ websites

  • 25th February 2017
Cloudflare revealed a serious bug in its software today that caused sensitive data like passwords, cookies, authentication tokens to spill in plaintext from its customers’ websites. The announcement is a major blow for the content delivery network, which offers enhanced security and performance for more than 5 million websites. This ...
Continue reading

Content Injection Vulnerability in WordPress

  • 24th February 2017
As part of a vulnerability research project for our Sucuri Firewall (WAF), we have been auditing multiple open source projects looking for security issues. While working on WordPress, we discovered a severe content injection (privilege escalation) vulnerability affecting the REST API. This vulnerability allows an unauthenticated user to modify the ...
Continue reading

Saying Goodbye to PHP 5.6

  • 4th January 2017
We’ll be marking PHP 5.6 as End of Life after December 2016. The PHP development team will no longer provide any active development or security fixes after that date. Continued use of PHP 5.6 brings with it the risk of security vulnerabilities, which compounds as the version goes further and further out of date. We strongly recommend that you ...
Continue reading