Join our Beta Program today

HostSecure.org - Industry News

HSC Industry Digest - May 28, 2026
May 28, 2026

Critical LiteSpeed cPanel Vulnerability (CVSS 10.0) Actively Exploited; Batch Inference and AI Infrastructure Reshape Cloud Landscape

Industry News - May 28, 2026
Executive Summary
A critical zero-day vulnerability in LiteSpeed's cPanel plugin (CVE-2026-48172, CVSS 10.0) is being actively exploited, allowing unprivileged users to gain root access on shared hosting servers—an existential threat to providers running this stack. Meanwhile, cloud infrastructure is rapidly consolidating around AI workloads, with DigitalOcean introducing Batch Inference, Snowflake committing $6B to AWS Graviton acceleration, and major power-grid repurposing projects underway to support AI campuses.
Key Themes
Critical Security Incident:: LiteSpeed cPanel root escalation vulnerability poses immediate threat to shared hosting ecosystem and provider infrastructure.
AI Infrastructure Convergence:: Cloud platforms pivoting decisively toward AI inference and acceleration, with major investments in specialized hardware and batch processing.
Power & Sustainability:: Data centers and AI campuses being built around dedicated energy grids and transmission corridors, driven by computational demand.
Supply Chain Security:: Multiple malware and extortion campaigns targeting developers and infrastructure operators via npm, GitHub, and physical office intrusions.
Regional Internet Governance:: ICANN intervention in AFRINIC dispute and Iran's partial internet restoration signal geopolitical shifts in DNS and infrastructure control.
Notable Players
LiteSpeed Technologies:

Critical vulnerability (CVE-2026-48172) in cPanel plugin allowing full root compromise; actively being exploited in the wild

DigitalOcean:

Launched Batch Inference on AI-Native Cloud platform for high-volume asynchronous AI workloads

Snowflake:

Committing $6B to AWS Graviton CPUs and AI accelerators for data warehouse optimization

TeraWulf & Schneider Electric:

Operating 500 MW AI campus in Buffalo repurposed from former coal plant infrastructure

AWS:

Releasing Graviton-powered Redshift instances claiming 7x speed improvement for data warehouse queries

Top Stories

CVE-2026-48172: LiteSpeed cPanel Plugin Root Privilege Escalation, CVSS 10.0, Actively Exploited

Perfect-score CVSS 10.0 vulnerability in LiteSpeed cPanel plugin allows unprivileged users to escalate to root. Active exploitation reported; all shared hosting providers using this stack are at critical risk.

Scalable, Cost-Efficient AI: Introducing Unified Batch Inference on DigitalOcean

DigitalOcean's Inference Engine now supports Batch Inference for high-volume asynchronous workloads. Part of broader AI-Native Cloud strategy announced at Deploy 2026.

Snowflake to burn $6B on AWS Graviton CPUs and AI accelerators

Snowflake committing $6B to AWS Graviton infrastructure and AI accelerators for enhanced data warehouse performance. Major bet on custom silicon and AI-optimized compute.

AWS whips out Graviton-powered Redshift instances, claims 7x speed for data warehouse

AWS launching Graviton-based Redshift instances delivering 7x performance gains. AI-driven query patterns driving need for specialized hardware.

How a Coal Plant in Buffalo Became TeraWulf's 500 MW AI Campus

Repurposed coal plant infrastructure now powers TeraWulf's 500 MW AI campus in partnership with Schneider Electric. Infrastructure-first approach to AI compute scaling.

Security & Compliance

CVE-2026-48172: LiteSpeed cPanel Plugin Root Privilege Escalation, CVSS 10.0, Actively Exploited

Perfect-score CVSS 10.0 vulnerability in LiteSpeed cPanel plugin allows unprivileged users to escalate to root. Active exploitation reported; all shared hosting providers using this stack are at critical risk.

How the EPA's New Rules Could Spark Backlash for Data Centers

EPA fast-tracks data center construction permitting but risks legal battles over environmental concerns. Policy shift creates regulatory uncertainty for infrastructure operators.

How to guarantee a speaker gig: Hack the system. Literally

Pretalx call-for-proposal systems vulnerable to XSS attacks, enabling speaker slot hijacking. Conference infrastructure remains exposed to basic web vulnerabilities.

India's cyber agency sets clock at 12 hours to tackle exploited bugs as AI turns up the heat

India's CERT-In mandates 12-hour patching window for internet-facing systems as AI-accelerated attacks proliferate. Aggressive response to threat acceleration.

Malware dev tries to steal Claude users' secrets, writes npm slop, leaks own GitHub private token

Attacker targeting Claude users via malicious npm packages; accidentally exposed own GitHub credentials. Supply chain targeting increasingly common across package ecosystems.

CrowdStrike, Google shatter Glassworm botnet

CrowdStrike and Google disrupted Glassworm developer-targeting botnet infrastructure. Coordinated takedown reflects escalating supply-chain threat landscape.

Extortion crews are visiting law firms pretending to be tech support, FBI warns

FBI warns of physical office intrusions where extortion crews pose as tech support to steal data via USB devices. Low-tech approach remains disturbingly effective.

California may let Linux bypass age check

California amendment proposes exemption allowing open-source software to bypass age verification requirements. Regulatory relief for non-commercial projects.

Cloud & Infrastructure

Scalable, Cost-Efficient AI: Introducing Unified Batch Inference on DigitalOcean

DigitalOcean's Inference Engine now supports Batch Inference for high-volume asynchronous workloads. Part of broader AI-Native Cloud strategy announced at Deploy 2026.

How a Coal Plant in Buffalo Became TeraWulf's 500 MW AI Campus

Repurposed coal plant infrastructure now powers TeraWulf's 500 MW AI campus in partnership with Schneider Electric. Infrastructure-first approach to AI compute scaling.

Stratos and the New AI Campus Math: Building Around the Grid

Utah's proposed 9 GW Stratos campus exemplifies trend of AI infrastructure built around dedicated energy systems. Power availability increasingly drives data center site selection.

Texas May Have Accidentally Built the Perfect Grid for AI

CREZ transmission corridors built for wind now attract hyperscale AI infrastructure seeking reliable power. Accidental alignment of energy and compute infrastructure.

Broadcom and FuriosaAI Bet on Ethernet AI Fabrics

Broadcom and FuriosaAI developing rack-scale inference platform using Ethernet fabrics and chiplets. Focus on power-efficient token generation and distributed inference.

AWS whips out Graviton-powered Redshift instances, claims 7x speed for data warehouse

AWS launching Graviton-based Redshift instances delivering 7x performance gains. AI-driven query patterns driving need for specialized hardware.

GitHub Actions outage told devs 'your account is suspended'

GitHub Actions outage produced false account suspension warnings to developers. Service reliability issues persist despite platform growth.

Snowflake to burn $6B on AWS Graviton CPUs and AI accelerators

Snowflake committing $6B to AWS Graviton infrastructure and AI accelerators for enhanced data warehouse performance. Major bet on custom silicon and AI-optimized compute.

Iran's Internet is partially restored, Cloudflare Radar data shows

Cloudflare Radar confirms partial internet restoration in Iran after nearly three months of shutdown. Traffic and DNS activity rising but network coverage remains limited.

Human-Centered AI Will Define the Future of Cloud Infrastructure (Video)

AI transitioning from isolated applications to coordinating infrastructure and logistics. Next-generation systems will operate autonomously across cloud resources.

Iran slowly reconnects to the global internet

Iran traffic gradually returning to baseline after extended outage; authorities provided no explanation. Geopolitical implications for global connectivity remain unclear.

Explainer: Edge AI

Edge AI deployment requires specialized infrastructure supporting distributed inference. Feasibility depends on device capabilities and network latency requirements.

Argonne flexes spare supercompute to build private AI inference service

Argonne National Lab leveraging spare supercomputer capacity for private AI inference service ('ChatDoE'). Government computing infrastructure monetizing excess capacity.

Cisco making SONiC available to all customers – not just hyperscalers

Cisco hardening open-source SONiC network OS for Nexus 9000 availability beyond hyperscale operators. Democratizing enterprise-grade network automation.

Technology & Tools

Introducing CloudLinux 9.8 Stable Release

CloudLinux 9.8 GA released, tracking AlmaLinux 9.8 with kernel 5.14, Python 3.14, MariaDB 11.8, PostgreSQL updates. Regular cadence of OS stability improvements.

Stratora - Self-hosted infrastructure monitoring with automated topology mapping, IPAM, and alert escalation

New self-hosted monitoring platform combining topology mapping, IPAM, and alert escalation. Consolidates fragmented infrastructure management tooling.

Google's coming change to app sideloading is threatening the Selfhosted ecosystem.

Android sideloading restrictions threaten self-hosted application deployments. Google's closed ecosystem policies conflict with open-source software freedoms.

Domains & DNS

ICANN again intervenes to defend AFRINIC

ICANN continues defending Africa's regional registry in ongoing dispute with long-time antagonist. Multiple fronts open in governance and control battles.

Community & Events

Nordic Domain Days 2026: What Stockholm Told the Hosting Industry

Nordic Domain Days 2026 concluded in Stockholm with 450 attendees and ICANN keynote sessions. Event solidifying position as largest independent B2B domain industry conference.

How do you actually verify your host's uptime claims?

Community discussion challenges veracity of advertised uptime percentages (99.9%, 99.95%) against actual measured performance. Transparency gap between marketing and reality.

Other News

Self-Hosting a Production Website or Ecommerce Store: Control, Responsibility, and Risk

Analysis of self-hosting trade-offs: greater control and privacy offset by responsibility for security, uptime, and bandwidth management. Risk calculus varies by business model.

Found the kryptonite for AI SEO slop posters

Community identifies strategies to combat AI-generated SEO spam leveraging Reddit's search ranking advantage. Arms race between content spam and detection methods.