What happened An attacker hijacked Hetzner IP space for roughly 33 hours across late August, poisoning a Softaculous update to target hosting providers and their customers.
Why it matters to hosts If you use Softaculous for app auto-installation on your servers, you may have installed a backdoored update during the window. The attack bypassed DNS entirely by rerouting traffic at the BGP layer—a vulnerability no hosting provider can defend against alone.
What to do Reset all credentials for any account that accessed Softaculous during late August, audit your servers for unauthorized packages, and check whether your Softaculous installation came from the compromised window (Softaculous has published exact timestamps).
My view To me, this is a reminder that app distribution is now a critical supply chain risk for hosting providers. Softaculous sits deep in your stack—if an attacker poisons it, they own the customer install base. The BGP hijack is the scary part because it shows how network-layer attacks can bypass all the usual safeguards. Hetzner and Softaculous both moved quickly to remediate, but the incident exposes a real gap: there's no way for a hosting provider to guarantee the integrity of third-party packages at install time without running your own mirror or air-gapping new servers.
Are you already mirroring Softaculous or other critical app installers internally, or do you rely on pulling from the official source each time?
Update distribution poisoned by BGP hijack; vendor issued guidance for credential resets and malicious package audits
Market cap now exceeds GoDaddy, reflecting investor appetite for pure-play cloud infrastructure over legacy hosting portfolios
Report being overwhelmed by AI-discovered CVEs, with vulnerability count approaching 2,000 per release
IP space hijacked for 33 hours via BGP attack; coordinated rapid remediation with Softaculous
Unauthenticated CVE allowing admin token minting actively exploited in the wild
For 33 hours, attackers rerouted traffic destined for Softaculous infrastructure via BGP hijack, allowing injection of malicious packages into app installer updates. You need to audit servers updated during late August and reset credentials immediately.
DigitalOcean's valuation now exceeds GoDaddy's, revealing investor preference for cloud infrastructure over traditional hosting. Market multiples show how pure-play cloud providers command different valuations than diversified hosting conglomerates.
Unauthenticated intruders can mint admin tokens on exposed Artifactory instances and are actively exploiting the vulnerability. If you use Artifactory for package management, verify your instance is patched and access controls are enforced.
AI-assisted vulnerability research is flooding kernel maintainers with ~2,000 CVEs per release, many low-priority but all requiring triage. Patch management just became exponentially harder for hosters running large server fleets.
A judge blocked a 330 MW data center project pending full environmental review of power, water, battery, and generation infrastructure. Regulatory scrutiny of data center expansion is tightening in key AI compute markets.
Hosting software vendor coordinated rapid response after BGP hijack poisoned package distribution. Check your update windows and audit for malicious Softaculous packages installed during the compromise window.
WordPress launched a security initiative to scale defenses as AI makes vulnerability discovery easier for attackers. WordPress hosting providers should monitor this initiative for guidance on hosting-level security hardening.
Self-hosters shared automation strategies for SSL certificate management ahead of upcoming certificate lifetime changes. Relevant if you manage customer SSL workflows or self-hosted infrastructure at scale.
AWS and Microsoft launched private 100 Gbps cross-cloud links, eliminating months of networking setup. Multicloud customers now have a direct path between platforms without public internet routing.
AWS acquired DuckLab and positioned DuckDB as a unified data interface across hybrid cloud environments. DuckDB's in-process OLAP design could reshape how hosters and MSPs approach multi-cloud data pipelines.
VMware announced strategies to extract more density from DRAM through tiered memory approaches. Relevant if you're experiencing margin pressure from rising RAM costs in your VPS or reseller hosting business.
Data center infrastructure must be fundamentally reimagined to support AI workloads. Power, cooling, and site selection strategies are shifting dramatically as AI demand outpaces traditional capacity planning.
Proxy advisers oppose Arm's CEO pay proposal tied to a $2 trillion valuation milestone. Reflects broader shareholder scrutiny of executive compensation as chip designer expands market reach.
Chinese court froze $318 million in Nexperia assets amid ownership dispute; Wingtech's H1 2026 revenue fell 90% year over year. Watch for supply chain implications if the dispute disrupts semiconductor manufacturing.
Cloudflare prototyped compression inside cache infrastructure to increase effective storage capacity with existing hardware. Cache efficiency techniques like this can reduce infrastructure costs for hosters running CDN or edge services.
Chevereto released a major update to its self-hosted image platform. Relevant for hosters offering managed self-hosted services or media-focused VPS packages.
Media over QUIC (MoQ) relays are now deployable without compiling research code. Hosters offering self-hosted streaming infrastructure can now support MoQ as an alternative to WebRTC and HLS.
Community curated a list of self-hosted applications with free SSO/OIDC support. Useful reference if you're building managed hosting portfolios or advising customers on authentication infrastructure.
User shared experience deploying Reitti location tracking and Immich photo management on self-hosted infrastructure. Demonstrates the expanding ecosystem of self-hosted applications customers want to run on VPS and dedicated servers.
AI is reshaping data center design and construction workflows. AEC leaders discussed applying AI to design, logistics, safety, and operations while addressing data standards and change management challenges.
LTO tape shipments declined 16 exabytes in 2025, but industry confidence remains that this is temporary. If you rely on tape for long-term backup retention, monitor whether the capacity glitch affects supply chains.
BT is liquidating 200,000 tons of copper from legacy network infrastructure as it transitions to fiber, generating potential $2.7 billion in recycling revenue. Illustrates the massive infrastructure refresh underway to support AI compute demand.
CloudFest surveyed hosters and MSPs on industry sentiment, finding concern around AI hype fatigue and margin pressure. Offers a benchmark for understanding operator sentiment heading into Q4 2026.
Samsung detailed a three-phase HBM roadmap that progressively integrates compute and logic into memory, culminating in direct DRAM-on-processor stacking. AI infrastructure providers should track this for future GPU/accelerator architecture shifts.
CXMT is sampling HBM3E memory with Alibaba and Cambricon, signaling potential mass production in 2027. Emerging Chinese DRAM capacity could reshape AI accelerator sourcing and cost structures for hosters.
Nvidia invested $3.5 billion in MediaTek to expand NVLink Fusion adoption in custom AI accelerators. Move signals Nvidia's strategy to deepen ecosystem lock-in across smartphone and infrastructure AI compute.
Anthropic announced zero-retention option for API calls, making the platform more compliance-friendly. Hosters offering managed AI services or integrating LLM APIs should understand the audit and verification requirements.
Anthropic announced new safety commitments and requested partner collaboration on model alignment. Relevant if you're integrating Claude into hosted services or advising customers on LLM deployment risk.
Email hosting promotional offer with quarantine management features. Niche offering in the redundant email market segment.
Anniversary promotional pricing on shared, reseller, and VPS hosting. Budget hosting segment continues to compete aggressively on price. --- #HostSecure