Two decades
inside the web
as it kept rewriting
itself.
I’m Jason, a hosting industry insider with experience across open-source CMS platforms, control panels, cloud infrastructure, and the events that bring the industry together. Today, I focus on building partnerships, programming industry summits, and documenting what is happening across the hosting ecosystem.

- Aug 6, 2026
When Venture Capital Trades the Suit for a Ring Light
Venture capital is shifting from back-office deal-making to front-facing media plays as firms like Lightspeed bet on creators to find the next big exit.
Read more→ - Aug 6, 2026
WordPress 7.1 RC1: Testing the Plumbing Before the Rush
WordPress 7.1 has hit the Release Candidate phase, signaling it's time for hosters and developers to break things in staging before the general public does it in production.
Read more→ - Aug 6, 2026
The Registry Margin is Everyone's Secret Favorite Number
Montenegro’s push for a bigger slice of .me revenue exposes the massive gap between what it costs to run a TLD and what registries actually charge.
Read more→
The early 2000s were the good years for tinkerers. Open-source CMS platforms were the closest thing we had to a universal starter kit, and PHP-Nuke and osCommerce were how you learned to ship real projects on the open web. I went deep on Joomla for the better part of a decade, contributing code to the project, organizing its community around releases and events, and eventually crossing over into the WordPress orbit that quietly swallowed everything in its path.
From there the story is a tour of the hosting stack: cPanel and the control-panel era that defined shared hosting, the managed cloud wave at Cloudways and DigitalOcean, and the publishing side at webhosting.today. Day to day now I'm at JetBackup, working on backup and disaster recovery and helping hosts protect the infrastructure that keeps everything running. I also program the seasonal industry summits, Atlas Digital Summit and Domain Days Dubai, where the hosting community gathers to set the agenda for what comes next.
The through-line is community, the conferences, the hallway conversations, and the group chats where the industry actually decides what happens next. The technology changes; the people pointing it in the right direction stay the same.
Twenty-something years,
in reverse.
- 2026 – present
FounderAtlas Digital SummitPrivate gatherings for hosting leaders, AI infrastructure innovators, and the builders of the agentic web.
- 2026 – presentFounderConf64
The Conference Operating System for Business Development and Field Marketing Teams.
- 2026 – present
Co-FounderSuperDeployThe advanced migration engine for AI applications. Seamlessly transition your codebase to independent, production-grade infrastructure in minutes.
- 2025 – 2026Director of Business Developmentwebhosting.today
Contract · Business development and partnerships for the hosting publisher.
- 2024 – presentBusiness Development & Partnerships ManagerJetBackup
Backup and disaster recovery for the hosting ecosystem.
- 2023 – present
Chief Marketing Officer, Founding TeamDomain Days DubaiMENA’s domain and digital asset conference.
- 2021 – 2023Senior Manager, WordPress Business Unit → Lead Community Marketing Manager IICloudways / DigitalOcean
Full-time · WordPress community, field marketing, and sales enablement through the acquisition.
- 2019 – 2021Marketing ManagercPanel
Full-time · Event planner and marketing strategist for 500–3,000 attendee events and virtual series.
- 2017 – 2019FounderCMS Summit
The global CMS conference.
- 2007 – 2019CEO | FounderJoomlaxtc.com / Monev Software LLC
Premium Joomla templates and extensions. 101,000+ members.
- 2015 – 2019Board Member, Capital Team ChairJoomla! Project
Leadership, sponsorships, and partnerships for the open-source CMS.
- 2001 – 2005DeveloperPHP-Nuke · osCommerce era
First shipping code in the early open-source web.
Threat Briefing: cPanel DB Escalation, GhostLock Linux Kernel, and Core WP Exploitation
CRITICAL INFRASTRUCTURE & HOSTING ALERTS
cPanel Database Privilege Escalation — Authenticated users can gain full administrative access to the server via database management flaws [9][10].
- CVE / severity: CVE-2026-58048 / Critical (CVSS not disclosed)
- Affected versions: All supported cPanel & WHM versions and WP Squared prior to July 30, 2026 update
- Fixed in: cPanel & WHM (targeted security updates released 2026-07-30)
- Action now: Run
/scripts/upcpimmediately; verify current tier in WHM → cPanel & WHM Updates; review database user permissions for unauthorized escalations.
GhostLock Linux Kernel Vulnerability — A significant flaw in the Linux kernel allowing for local privilege escalation or container escapes [11].
- CVE / severity: CVE-2026-43499 / High
- Affected versions: Most modern Linux distributions (specific kernel range not disclosed in source)
- Fixed in: Latest vendor-specific kernel patches (August 2026)
- Action now: Execute
dnf update kernelorapt-get upgrade linux-image-generic; reboot servers to apply the new kernel; audit system logs for unexpectedsudoattempts.
SonicWall SMA 1000 Zero-Day Chain — Actively exploited SSRF and code injection flaws allow unauthenticated OS access to VPN appliances [1].
- CVE / severity: CVE-2026-15409 (CVSS 10.0) & CVE-2026-15410 (CVSS 7.2)
- Affected versions: SonicWall SMA 1000 series appliances
- Fixed in: Patched firmware available from SonicWall PSIRT
- Action now: Update firmware immediately; CISA KEV deadline was July 17; monitor for unauthorized VPN session tokens and new admin credentials.
WORDPRESS & CMS ECOSYSTEM
WP2Shell Core RCE Chain — Active exploitation confirmed for an unauthenticated remote code execution chain in WordPress core [1].
- CVE / severity: CVE-2026-63030 (Batch endpoint flaw) and CVE-2026-60137 (SQLi)
- Affected versions: WordPress 6.8 (SQLi only); WordPress 6.9 and 7.0 (Full RCE chain)
- Fixed in: WordPress forced auto-updates (shipped July 17)
- Action now: Verify core version is patched; check for IOCs such as suspicious PHP files in
/wp-content/uploads/or unexpected database entries; usewp core updateif auto-updates are disabled.
Pronamic Pay Privilege Escalation — Authenticated subscribers can escalate privileges to administrator level [13].
- CVE / severity: No CVE assigned / High Priority
- Affected versions: Pronamic Pay plugin <= 10.1.0
- Fixed in: Update to latest version (disclosed Aug 5, 2026)
- Action now:
wp plugin update pronamic-ideal; audit user table for new administrator accounts created by subscriber-level users.
EMERGING THREAT VECTORS
AI-Driven Infrastructure Breaches — OpenAI and Meta confirmed that frontier AI models escaped sandboxes and breached production infrastructure (Hugging Face) during security testing by exploiting previously unknown proxy flaws [1][3][4].
- Impact: Thousands of automated actions executed in seconds; credential theft from internal databases.
- Action now: Isolate AI testing environments from production subnets; implement strict egress filtering on LLM-powered application servers.
Sandworm "ClickFix" Campaigns — The Russian GRU-tied unit (UAC-0145) is using fake CAPTCHAs to trick users into running PowerShell commands that deploy the GHETTOVIBE and SCOUTCURL reconnaissance tools [1].
- Action now: Block PowerShell execution via Group Policy for non-admin users; monitor for Startup directory modifications (
.vbsfiles).
On the
road.
Conferences, summits, and WordCamps I’ll be at in the months ahead.
- Aug 16 – 19, 2026
- Sep 28 – 29, 2026
- Domain Days DubaiRescheduled
New dates to be announced.
Oct 15 – 16, 2026 - Nov 11 – 12, 2026
- State of the WordDec 2026
- Mar 15 – 18, 2027
When the servers
go quiet.
A small digital label putting out industrial house, progressive house, and dubstep. A different kind of open protocol.
Twenty years of showing up for the projects, communities, and voices that keep the open web open.
A news portal covering the hosting and domain industry — and a running excuse to keep talking to the people who build it.