Released patches for three security flaws on July 29, including two that allow privilege escalation between accounts on shared servers.
Swiss privacy-first hosting and cloud provider went public on July 29, maintaining founder control while raising capital as an alternative to American hyperscalers.
Migrated cdnjs (9 billion requests/day) onto its Developer Platform; announced new AI crawler defaults affecting site owners.
Warned memory supply crunch will persist through 2028 as company reports 19-fold profit increase, keeping hardware costs elevated.
Facing renewed questions over Galera's open-source future as MySQL build support ends in September and company develops separate premium replication tech.
Account isolation breaks on shared servers; two of three patched flaws allow privilege escalation between customer accounts. Patch all supported branches immediately and validate isolation in staging.
Swiss privacy-first hosting and cloud provider went public July 29 while founder retains control, signaling investor appetite for European alternatives to hyperscalers. This shifts competitive dynamics for US-based hosts marketing privacy.
MySQL build support ends September as MariaDB develops separate premium replication tech, threatening Galera's open-source status. Operators relying on Galera for cluster replication should audit alternatives now.
Cloudflare moved cdnjs (9 billion daily requests) entirely to its Developer Platform, demonstrating its infrastructure maturity to customers running massive open-source projects. Validates Cloudflare's stack for edge workloads at scale.
Memory supply constraints will persist through 2028 while Samsung reports record profits, keeping hardware costs elevated for independent hosts. Expect no relief on server build costs for the next two years.
Sapphire Sleet crew exploited social engineering to compromise npm maintainer accounts and publish malicious updates across four packages. Operators shipping Node.js workloads should audit dependencies and maintainer hygiene in their supply chains.
Threat actors adapted Zimbra zero-click exploit to Outlook, embedding browser implant that survives password changes and device rebuilds. Affects both on-prem and cloud email deployments; monitor inbound email logs for anomalies.
Majority of corporate workloads now run off-premises, crossing a historic inflection point. Reflects sustained shift toward cloud and SaaS, sustaining demand for independent hosting and managed services.
NOAA migrated from HPE Cray supercomputers to Google Cloud H4D VMs for weather prediction, signaling enterprise acceptance of cloud HPC. Validates cloud-native compute for mission-critical workloads previously locked to on-prem.
Cisco exiting Azure Local after Microsoft tightened hardware lock-in requirements, highlighting friction between vendor lock-in and open infrastructure. Shows hyperscaler control tightening on hybrid platforms.
Qualcomm dropping datacenter ambitions but pivoting toward AI accelerators post-Apple decline. Signals consolidation of compute chip suppliers around AI workloads.
Practical strategies for responding to climbing costs and whether to pass them to customers. Covers decision framework and execution for independent hosts managing margin pressure.
Analysis of gaps between introductory and renewal rates across hosting providers, with data on which hosts maintain the widest multipliers. Benchmark your renewal pricing against transparent peer comparisons.
Microsoft reported strong cloud revenue despite modest AI-specific returns, signaling capex spending continues without yet translating to AI product revenue. Shows hyperscalers investing heavily in infrastructure ahead of proven AI monetization.
> ## My Take — by Kerry Allan > > **What happened:** cPanel released fixes for three security flaws on July 29, with two of them allowing privilege escalation between separate hosting accounts on shared servers. > > **Why it matters to hosts:** If you run shared hosting, account-isolation breaches mean one customer can compromise another—that's your liability, your support burden, and potentially your reputation in a single exploit. > > **What to do:** Patch all supported cPanel branches immediately and test account isolation on a staging environment before rolling to production. > > **My view:** This is exactly the kind of flaw that makes shared hosting operators nervous: it's not exotic, it's not theoretical, and it hits the core promise of your product. The fact that cPanel shipped fixes the same day they disclosed the issue is good practice, but the real test is how fast you deploy. Don't let this sit in your backlog. > > *How many of your shared servers are still running pre-patch builds, and how confident are you in your process to confirm the fixes actually took?*
Veeam expanded backup support to six additional hypervisors, facilitating VMware migrations away from Broadcom. Relevant for operators evaluating hypervisor refresh or migration strategies.
Proprietary AI models declined to help debug a Linux kernel issue, while open-source models proved effective. Demonstrates practical value of open-source models for infrastructure and operations work.
Hyperscalers shifting from GPU procurement to in-house chip design and custom infrastructure, prioritizing deployment pace over supply. Increases competition for independent operators as hyperscalers internalize competitive advantages.
Alleged attacks on AWS facilities prompt security review of perimeter defenses, raising questions about counter-drone measures. Signals emerging physical security threat requiring operators to audit site vulnerabilities.
Georgia power utility acquiring 30 homes for grid expansion, with local reports linking project to data center power demand. Illustrates infrastructure buildout and community friction around high-power hosting clusters.
Seagate's 50TB HAMR drives begin qualification late 2027, but current inventory sold out through 2028 due to AI-driven storage demand. Plan storage refresh cycles now; expect tight HDD availability and pricing for the next 18 months.
Cloudflare clarified AI crawler defaults and opt-out mechanisms for site owners concerned about training data use. Helps hosting providers educate customers on crawler behavior and compliance options.
Google could exceed Nvidia's 2028 AI accelerator production if manufacturing capacity targets are met, potentially using Intel Foundry Services. Signals competition accelerating beyond software to custom silicon manufacturing.
US government invested $300M in GlobalFoundries for silicon photonics development with minority stake. Indicates public sector backing for alternative semiconductor and interconnect technologies competing with hyperscaler dominance.
Databricks survey finds certified professionals boost partner delivery capacity and AI readiness. Relevant for hosting operators building AI services and training MSP teams.
M4 Max demonstrates competitive local AI inference performance against specialized silicon, broadening where customers can deploy AI workloads. Affects demand for dedicated AI accelerator hosting versus commodity compute.
Google's AI Overviews data in Search Console shows inflated metrics (impressions without clicks, position-one illusions) that can mask real traffic losses. Warns hosting customers managing SEO that Google's AI metrics may understate declining organic visibility.
CloudFest video series featuring sales strategy insights from industry leaders. Community-focused content for hosting operators monitoring peer perspectives.
Security lesson: comprehensive camera coverage defeats targeted vandalism. Tangential reminder for operators securing on-prem facilities.