Join our Beta Program today

HostSecure.org - Industry News

HSC Industry Digest - June 01, 2026
June 1, 2026

Critical LiteSpeed cPanel Flaw (CVSS 10.0) Actively Exploited; Home.pl Database Breach Alleged

Industry News - June 1, 2026
Executive Summary
A critical privilege escalation vulnerability in LiteSpeed's cPanel plugin (CVE-2026-48172, CVSS 10.0) is actively being exploited, allowing shared hosting customers to take complete control of servers. Separately, a database allegedly from Home.pl appeared on a cybercrime forum, raising broader security concerns across the hosting industry. Meanwhile, DigitalOcean continues expanding its AI-native cloud infrastructure with new GPU offerings and unified batch inference capabilities.
Key Themes
Critical Security Vulnerabilities:: Multiple high-severity kernel exploits (Copy Fail, Dirty Frag, CIFSwitch) and the LiteSpeed cPanel plugin flaw dominate the threat landscape, affecting shared hosting providers and Linux-based systems.
AI Infrastructure Expansion:: DigitalOcean, Cloudflare, and datacenter operators are racing to scale AI compute with new GPU options (NVIDIA H200, AMD MI325X), batch inference, and unified cloud platforms.
Industry Consolidation:: Strategic mergers (CyberFolks/Shoper €1B, OpusDNS/fruits.co) and major acquisitions signal market maturation and the pursuit of domain/e-commerce synergies.
Meta's Cloud Ambitions:: Zuckerberg signals Meta could enter cloud computing if AI infrastructure buildout proceeds, potentially disrupting VPS providers.
Performance & Caching Innovations:: CloudLinux's MAx Cache delivers 3x WordPress speed gains; Cloudflare's Gen 13 servers double edge compute throughput.
Notable Players
LiteSpeed Technologies:

Critical root privilege escalation in cPanel plugin (CVE-2026-48172, CVSS 10.0) actively exploited in the wild

DigitalOcean:

Launched Gradient AI cloud platform (GA), added NVIDIA H200 and AMD MI325X GPU Droplets, introduced batch inference and per-second billing

CyberFolks & Shoper:

Announced merger to create €1 billion listed entity combining hosting and e-commerce platforms

Cloudflare:

Released Gen 13 servers with AMD EPYC Turin processors, doubling edge compute performance and moving to 100 GbE networking

CloudLinux:

Released MAx Cache stable version for Apache/Nginx delivering 3x WordPress performance gains and patched multiple kernel CVEs

Top Stories

CVE-2026-48172: LiteSpeed cPanel Plugin Root Privilege Escalation, CVSS 10.0, Actively Exploited

A critical zero-day in LiteSpeed's cPanel plugin allows any shared hosting customer to gain root access and compromise the entire server. The vulnerability is currently being actively exploited in the wild.

A Database Allegedly From Home.pl Is Being Advertised on a Cybercrime Forum.

An alleged Home.pl customer database surfaced on cybercrime forums, though Home.pl has not confirmed the breach and no independent verification exists. Polish authorities have issued no advisory.

Mark Zuckerberg Just Put Every VPS Provider on Notice

Zuckerberg signaled Meta's cloud computing business is "definitely on the table" if AI infrastructure buildout continues, potentially entering direct competition with VPS and cloud providers.

CyberFolks and Shoper Agree to Merge Into a Single Listed Entity Valued at €1 Billion

CyberFolks and Shoper announced a merger creating a €1 billion combined entity, merging hosting and e-commerce capabilities through a share-based transaction under Polish law.

Launching Cloudflare's Gen 13 servers: trading cache for cores for 2x edge compute performance

Cloudflare's Gen 13 servers double compute throughput using high-core AMD EPYC Turin CPUs and a new Rust-based FL2 stack optimized for edge workloads. Migration from cache-focused to compute-focused architecture.

Security & Compliance

CVE-2026-48172: LiteSpeed cPanel Plugin Root Privilege Escalation, CVSS 10.0, Actively Exploited

A critical zero-day in LiteSpeed's cPanel plugin allows any shared hosting customer to gain root access and compromise the entire server. The vulnerability is currently being actively exploited in the wild.

A Database Allegedly From Home.pl Is Being Advertised on a Cybercrime Forum.

An alleged Home.pl customer database surfaced on cybercrime forums, though Home.pl has not confirmed the breach and no independent verification exists. Polish authorities have issued no advisory.

CIFSwitch (cifs.spnego LPE): Mitigation and Kernel Update on CloudLinux

CIFSwitch, a Linux kernel local privilege escalation in the CIFS/SMB client's SPNEGO upcall path, latent since 2007, disclosed by researcher Asim Manizada. CloudLinux released mitigation and kernel updates.

Dutch Authorities Dismantle Stark Industries. The Rebrand Didn't Save It.

Dutch financial crime investigators (FIOD) raided data centers in Dronten and Schiphol-Rijk on May 22, seizing 800 servers and equipment. The rebrand of the compromised operation failed to shield it from enforcement.

Dirty Frag (CVE-2026-43284, CVE-2026-43500): Mitigation and Kernel Update on CloudLinux

Researcher Hyunwoo Kim disclosed Dirty Frag, a second Linux kernel local privilege escalation in the IPsec ESP and rxrpc areas, following Copy Fail. CloudLinux issued mitigation and kernel updates.

Copy Fail (CVE-2026-31431): Patching kernels without rebooting

Copy Fail (CVE-2026-31431) breaks the typical kernel CVE patching rhythm, requiring mitigation strategies that don't necessitate server reboots during maintenance windows.

CVE-2026-31431 (Copy Fail): Kernel Update on CloudLinux

CVE-2026-31431 (Copy Fail) is a Linux kernel LPE vulnerability in the algif_aead module exploitable via a 732-byte Python script by any unprivileged local user to gain root access.

New NGINX Zero-Day Report Raises Concern After Recent Security Patch

A reported NGINX zero-day (nginx-poolslip) affecting version 1.31.0 involves request memory pool handling issues, raising concerns shortly after the Rift patch.

Cloud & Infrastructure

Introducing GPU Droplets accelerated by NVIDIA HGX H200

NVIDIA HGX H200 GPU Droplets now available on DigitalOcean, delivering up to 2x faster performance for AI and compute-intensive workloads on-demand.

Elevate Your AI Workloads: AMD Instinct™ MI325X GPU Droplets are Now Available on DigitalOcean

DigitalOcean launched AMD Instinct MI325X GPU Droplets, expanding GPU options for developers and enterprises building AI applications with powerful, accessible infrastructure.

Introducing Gradient: DigitalOcean's Unified AI Cloud

Gradient is DigitalOcean's unified AI cloud platform designed for digital native enterprises to build and scale AI applications with simplified infrastructure.

DigitalOcean Gradient Platform is now Generally Available

Gradient Platform (formerly GenAI Platform) reached GA, offering fully managed AI app building with agents, serverless inference, and new external model integration features.

NextEra-Dominion Merger: A $67B Bet on AI Power Demand

A historic $67B NextEra-Dominion merger positions America's largest regulated utility at the center of AI data center power infrastructure demand.

Pricing & Business

Free CDN included with Canadian Web Hosting plans

Web Hosting Canada (WHC) now includes a free CDN with all web hosting and managed WordPress plans, improving load times for visitors worldwide.

Announcing per-sec billing, new Droplet plans, BYOIP, and NAT gateway to reduce scaling costs

DigitalOcean introduced per-second billing, new Droplet tiers, BYOIP, and NAT gateway features to help customers cut cloud spending from over-provisioning.

Control Panels

Plesk Obsidian 18.0.77 Is Here: Significant Accessibility Developments and New ACME SSL Support

Plesk Obsidian 18.0.77 brings major accessibility improvements and native ACME protocol support for streamlined SSL certificate management.

Plesk Obsidian 18.0.75: What's New

Plesk Obsidian 18.0.75, the first 2025 release, strengthens SSL/TLS management, expands development stack support, and improves accessibility.

Plesk Obsidian 18.0.74 Release

Plesk Obsidian 18.0.74 adds powerful features, improved security, and expanded platform support for smoother and safer server management.

Acquisitions & Market

CyberFolks and Shoper Agree to Merge Into a Single Listed Entity Valued at €1 Billion

CyberFolks and Shoper announced a merger creating a €1 billion combined entity, merging hosting and e-commerce capabilities through a share-based transaction under Polish law.

Mark Zuckerberg Just Put Every VPS Provider on Notice

Zuckerberg signaled Meta's cloud computing business is "definitely on the table" if AI infrastructure buildout continues, potentially entering direct competition with VPS and cloud providers.

OpusDNS Acquires fruits.co, Adding Domain Monetization to Its Wholesale Registrar Platform

OpusDNS, launched October 2025, acquired fruits.co, a European domain monetization and aftermarket sales platform, expanding its wholesale registrar ecosystem.

NextEra-Dominion Merger: A $67B Bet on AI Power Demand

A historic $67B NextEra-Dominion merger positions America's largest regulated utility at the center of AI data center power infrastructure demand.

Technology & Tools

Scalable, Cost-Efficient AI: Introducing Unified Batch Inference on DigitalOcean

DigitalOcean's Batch Inference on the Inference Engine enables high-volume asynchronous AI workloads, part of the new AI-Native Cloud architecture.

Other News

MAx Cache Stable Release: 3x Faster WordPress Page Loads on Apache and Nginx

CloudLinux released MAx Cache GA, a native web server module for Apache/Nginx that serves cached WordPress pages directly without PHP, delivering 3x performance gains.

Introducing .htaccess Caching in MAx Cache: 20% Faster Apache Page Loads

MAx Cache's .htaccess caching feature achieves 20% faster Apache page loads by compiling .htaccess files into memory, eliminating per-request disk lookups.

MAx Cache Now Available for Nginx: Server-Level WordPress Caching, Completely Bypassing PHP

MAx Cache extended to Nginx with native module serving cached WordPress pages directly from the web server without PHP invocation, achieving greater performance.

Microsoft takes up residence next to OpenAI, Oracle at Crusoe's 900 MW Texas datacenter expansion

Crusoe revealed plans to expand its Abilene Texas datacenter campus by 900 MW with on-site power generation to support Microsoft's AI infrastructure.

Crusoe Expands Abilene AI Campus With New 900 MW 'AI Factory' for Microsoft

Crusoe expanded its Abilene Texas data center campus with 900 MW new capacity powered by on-site generation to support Microsoft's AI infrastructure needs.

Arm Enters Data Center Chip Race With AGI CPU for AI Infrastructure

Meta and Arm co-developed the AGI CPU, the first Arm-designed data center chip built to meet surging AI data center processor demand.

Launching Cloudflare's Gen 13 servers: trading cache for cores for 2x edge compute performance

Cloudflare's Gen 13 servers double compute throughput using high-core AMD EPYC Turin CPUs and a new Rust-based FL2 stack optimized for edge workloads.

Inside Gen 13: how we built our most powerful server yet

Technical deep dive into Cloudflare's Gen 13 architecture featuring AMD EPYC Turin 9965 processors and 100 GbE networking for growing traffic demands.