Jason Nickerson — Hosting Industry InsiderTwo decades
inside the web
as it kept rewriting
itself.
I’m Jason, a hosting industry insider with experience across open-source CMS platforms, control panels, cloud infrastructure, and the events that bring the industry together. Today, I focus on building partnerships, programming industry summits, and documenting what is happening across the hosting ecosystem.

- Sep 3, 2026
Palo Alto Networks and the $500M Bet on Boring Automation
Palo Alto Networks has acquired Console for half a billion dollars, signaling a massive shift in how AI-driven IT operations will be handled at the enterprise level.
Read article: Palo Alto Networks and the $500M Bet on Boring Automation→ - Sep 3, 2026
Zero-Day Response is the New Minimum Requirement
Attack data reveals that hackers were hunting for the recent Elementor Pro file upload flaw the same day it hit the public record, leaving no room for late-week patching.
Read article: Zero-Day Response is the New Minimum Requirement→ - Sep 2, 2026
When the AI starts picking locks
OpenAI is preparing to release Astra, a model with a specialized talent for finding vulnerabilities, forcing the hosting industry to rethink its defensive perimeter.
Read article: When the AI starts picking locks→
The early 2000s were the good years for tinkerers. Open-source CMS platforms were the closest thing we had to a universal starter kit, and PHP-Nuke and osCommerce were how you learned to ship real projects on the open web. I went deep on Joomla for the better part of a decade, contributing code to the project, organizing its community around releases and events, and eventually crossing over into the WordPress orbit that quietly swallowed everything in its path.
From there the story is a tour of the hosting stack: cPanel and the control-panel era that defined shared hosting, the managed cloud wave at Cloudways and DigitalOcean, and the publishing side at webhosting.today. Day to day now I'm at JetBackup, working on backup and disaster recovery and helping hosts protect the infrastructure that keeps everything running. I also program the seasonal industry summits, Atlas Digital Summit and Domain Days Dubai, where the hosting community gathers to set the agenda for what comes next.
The through-line is community, the conferences, the hallway conversations, and the group chats where the industry actually decides what happens next. The technology changes; the people pointing it in the right direction stay the same.
Twenty-something years,
in reverse.
- 2026 – present
FounderAtlas Digital SummitPrivate gatherings for hosting leaders, AI infrastructure innovators, and the builders of the agentic web.
- 2026 – presentFounderConf64
The Conference Operating System for Business Development and Field Marketing Teams.
- 2026 – present
Co-FounderSuperDeployThe advanced migration engine for AI applications. Seamlessly transition your codebase to independent, production-grade infrastructure in minutes.
- 2025 – 2026Director of Business Developmentwebhosting.today
Contract · Business development and partnerships for the hosting publisher.
- 2024 – presentBusiness Development & Partnerships ManagerJetBackup
Backup and disaster recovery for the hosting ecosystem.
- 2023 – present
Chief Marketing Officer, Founding TeamDomain Days DubaiMENA’s domain and digital asset conference.
- 2021 – 2023Senior Manager, WordPress Business Unit → Lead Community Marketing Manager IICloudways / DigitalOcean
Full-time · WordPress community, field marketing, and sales enablement through the acquisition.
- 2019 – 2021Marketing ManagercPanel
Full-time · Event planner and marketing strategist for 500–3,000 attendee events and virtual series.
- 2017 – 2019FounderCMS Summit
The global CMS conference.
- 2007 – 2019CEO | FounderJoomlaxtc.com / Monev Software LLC
Premium Joomla templates and extensions. 101,000+ members.
- 2015 – 2019Board Member, Capital Team ChairJoomla! Project
Leadership, sponsorships, and partnerships for the open-source CMS.
- 2001 – 2005DeveloperPHP-Nuke · osCommerce era
First shipping code in the early open-source web.
Threat Briefing: Virtualizor BGP Hijack, Backup Plugin Takeover & SonicWall Zero-Days
Infrastructure & Hosting Alerts
Malicious Virtualizor Update Served via BGP Hijacking — Attackers diverted internet traffic to serve malicious updates to the Virtualizor VPS control panel [9].
- CVE / severity: No CVE assigned (Supply chain / BGP Hijack)
- Affected versions: All Virtualizor installations attempting updates between September 1–2, 2026.
- Fixed in: Clean update repository restored by vendor.
- Action now:
- Inspect
/usr/local/virtualizorfor unauthorized file modifications. - Force a clean update using
/usr/local/virtualizor/scripts/update.shnow that BGP routes have stabilized. - Check system logs for unauthorized SSH keys or new root users added during the 48-hour hijack window.
- Inspect
SonicWall SMA 1000 Series Under Active Exploit — Two critical flaws are being leveraged in the wild to compromise VPN appliances [13].
- CVE / severity: CVE-2026-9001 & CVE-2026-9002 (CVSS 9.8)
- Affected versions: SMA 1000 Series (6200, 6210, 7200, 7210, 8000v).
- Fixed in: Firmware versions released September 2, 2026.
- Action now:
- Apply firmware updates immediately via the SonicWall support portal.
- Enable Geo-IP filtering to block traffic from unexpected regions until patched.
JFrog Artifactory Admin Token Forgery — Flaw allows attackers to forge administrative tokens, gaining full control over artifact repositories [5, 12].
- CVE / severity: CVE-2026-6782 (CVSS 9.8)
- Affected versions: JFrog Artifactory versions prior to 7.77.x.
- Fixed in: Artifactory 7.77.5 / 6.27.30.
- Action now:
- Upgrade Artifactory instances immediately.
- Rotate all administrative access tokens and audit repository access logs for anomalous behavior [12].
WordPress & CMS Vulnerabilities
Massive Takeover Flaw in Popular Backup Plugin — A critical flaw allows remote attackers to gain full site control, impacting millions of WordPress installations [4, 5, 6].
- CVE / severity: CVE-2026-81294 (CVSS 9.8) [3].
- Affected versions: Widely used WordPress backup plugin (likely UpdraftPlus or similar based on "backup plugin" and "millions" identifiers in snippets [4, 5]).
- Fixed in: Not explicitly disclosed in snippets; check for latest plugin updates released in the last 24 hours.
- Action now:
- Run
wp plugin update --allor check specific backup plugin versions. - Verify that the plugin author is "Paul Ryan" or matches the CVSS entity listed [3].
- Run
Gitea Repository-to-RCE Active Exploitation — Repository write access can be escalated to full server command execution; now confirmed in CISA KEV [12].
- CVE / severity: CVE-2026-60004 (CVSS 9.9)
- Affected versions: Gitea versions prior to 1.22.0.
- Fixed in: Gitea 1.22.0 or later.
- Action now:
- Update Gitea binary/container immediately.
- Audit all users with "Write" permissions to ensure no unauthorized accounts were created.
Threat Landscape & Remediation
Sality P2P Botnet Takedown — International law enforcement has disrupted the 23-year-old Sality botnet, which targeted Windows servers and clients via P2P [10].
- Action: While the botnet is disrupted, infrastructure teams should continue to block known Sality P2P ports and update AV signatures to remove legacy infections that may still attempt to beacon [10].
Freelancer-Targeted Phishing (TVRAT) — A Russian national has been charged for a phishing campaign targeting freelancers with TVRAT malware to gain remote access to systems [7].
- Action: Infrastructure teams providing shared hosting or managed services for freelancers should monitor for TVRAT indicators of compromise (IoCs) and implement stricter SPF/DKIM/DMARC policies to mitigate phishing [7].
On the
road.
Conferences, summits, and WordCamps I’ll be at in the months ahead.
- Aug 16 – 19, 2026
- Sep 28 – 29, 2026
- Domain Days DubaiRescheduled
New dates to be announced.
Oct 15 – 16, 2026 - Nov 11 – 12, 2026
- State of the WordDec 2026
- Mar 15 – 18, 2027
When the servers
go quiet.
A small digital label putting out industrial house, progressive house, and dubstep. A different kind of open protocol.
Twenty years of showing up for the projects, communities, and voices that keep the open web open.
A news portal covering the hosting and domain industry — and a running excuse to keep talking to the people who build it.