<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Security Archives | cPanel</title>
	<atom:link href="https://www.cpanel.net/blog/category/security/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.cpanel.net/blog/category/security/</link>
	<description>Hosting Platform of Choices</description>
	<lastBuildDate>Sun, 10 May 2026 08:53:17 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0.3</generator>

<image>
	<url>https://www.cpanel.net/wp-content/uploads/2025/07/cropped-android-chrome-512x512-1-32x32.png</url>
	<title>Security Archives | cPanel</title>
	<link>https://www.cpanel.net/blog/category/security/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>CVE-2026-41940: Response, Actions and Next Steps</title>
		<link>https://www.cpanel.net/blog/security/security-update-cve-2026-41940/</link>
					<comments>https://www.cpanel.net/blog/security/security-update-cve-2026-41940/#respond</comments>
		
		<dc:creator><![CDATA[Neska Husar]]></dc:creator>
		<pubDate>Sun, 10 May 2026 05:23:42 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://www.cpanel.net/?p=82261</guid>

					<description><![CDATA[<p>On 28 April 2026, we released security updates for cPanel &amp; WHM to address CVE-2026-41940, an authentication vulnerability in the session&#160;management layer.&#160;&#160; Once a verified and reproducible report was confirmed, our team made updates available within approximately 28 hours across all supported versions of the platform, as well as select legacy versions.&#160;As of today,&#160;over&#160;98% of [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/security/security-update-cve-2026-41940/">CVE-2026-41940: Response, Actions and Next Steps</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">On 28 April 2026, we released security updates for cPanel &amp; WHM to address CVE-2026-41940, an authentication vulnerability in the session&nbsp;management layer.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Once a verified and reproducible report was confirmed, our team made updates available within approximately 28 hours across all supported versions of the platform, as well as select legacy versions.&nbsp;As of today,&nbsp;over&nbsp;98% of servers worldwide are running an updated version of cPanel &amp; WHM. We continue to&nbsp;provide mitigation options for partners and customers&nbsp;who are unable to apply the update&nbsp;immediately. The complete update&nbsp;regarding&nbsp;patch coverage is listed in the following&nbsp;<a href="https://support.cpanel.net/hc/en-us/articles/40073787579671" target="_blank" rel="noreferrer noopener">support article.</a>&nbsp;</p>



<p class="wp-block-paragraph">We take security extremely seriously and recognize the urgency this created. We&nbsp;remain&nbsp;focused on supporting our partners and customers.&nbsp;</p>



<h2 class="wp-block-heading"><strong>What Was Addressed</strong>&nbsp;</h2>



<p class="wp-block-paragraph">CVE-2026-41940 is an authentication vulnerability in cPanel &amp; WHM’s session&nbsp;management layer. Two separate code paths write to session files on disk: one path included an input-sanitisation step; a second path, invoked during&nbsp;Basic authentication handling, did not. The absence of that sanitisation step on the second path created a condition under which a specially crafted request could result in an unauthenticated session being treated as authenticated, granting access without valid credentials.&nbsp;</p>



<p class="wp-block-paragraph">The vulnerability affects every version of cPanel &amp; WHM after v11.40, and WP Squared up to v11.136.1.6. VulnCheck has assigned it a CVSS score of 9.8. CISA added it to the Known Exploited Vulnerabilities catalog on 1 May 2026. No other WebPros products are affected.</p>



<p class="wp-block-paragraph">For servers on versions that cannot yet be updated, the <a href="https://support.cpanel.net/hc/en-us/articles/40073787579671" target="_blank" rel="noreferrer noopener">support article</a> provides mitigation guidance including cpsrvd service port blocking and ModSecurity rule application. We have also published a <a href="https://support.cpanel.net/hc/en-us/articles/40073787579671-Security-CVE-2026-41940-cPanel-WHM-WP2-Security-Update-04-28-2026" target="_blank" rel="noreferrer noopener">detection script</a>&nbsp; that scans session files for the indicators of compromise associated with this attack. Note that, as of 1 May 2026, the script has been refined to remove an earlier false-positive on session.lock files.</p>



<h2 class="wp-block-heading"><strong>How We Responded</strong>&nbsp;</h2>



<p class="wp-block-paragraph">The following sequence reflects how the response unfolded&nbsp;on confirming the vulnerability.&nbsp;</p>



<ul class="wp-block-list">
<li><strong>27&nbsp;April, 10:47 CDT &#8211;&nbsp;</strong>Vulnerability&nbsp;confirmed and&nbsp;classified.&nbsp;Incident response&nbsp;initiated</li>
</ul>



<ul class="wp-block-list">
<li><strong>28 April, 12:08 CDT&nbsp;&#8211;&nbsp;</strong>Support article (KB 40073787579671) published. Partner collaboration channels opened</li>
</ul>



<ul class="wp-block-list">
<li><strong>28 April, 12:30 CDT&nbsp;&#8211;&nbsp;</strong>Code update merged into v138 and applied simultaneously across v136, v134, v126, v118, and v110</li>
</ul>



<ul class="wp-block-list">
<li><strong>28 April, 16:19 CDT&nbsp;&#8211;&nbsp;</strong>Updated builds published across all supported tiers: LTS, STABLE, RELEASE, CURRENT, and EDGE. Approximately 28 hours from confirmation to general availability&nbsp;</li>
</ul>



<ul class="wp-block-list">
<li><strong>29 April&nbsp;15:18 CDT&nbsp;&#8211;&nbsp;</strong>Comprehensive&nbsp;email issued to all partners and direct customers, alongside publication of the indicators-of-compromise detection script. A second coordinated email followed on 1 May with expanded version coverage and&nbsp;additional&nbsp;mitigation measures</li>
</ul>



<p class="wp-block-paragraph">From there, the work continued in parallel: back-ports for legacy and end-of-life versions, automated remediation tooling,&nbsp;and direct support for partners working through specific fleet configurations.&nbsp;&nbsp;</p>



<h3 class="wp-block-heading"><strong>Detection and Auto-Remediation Tooling</strong></h3>



<p class="wp-block-paragraph">Two&nbsp;additional&nbsp;tools supported the broader response alongside the patches.&nbsp;</p>



<p class="wp-block-paragraph">The indicators-of-compromise detection script, available at&nbsp;<a href="https://support.cpanel.net/hc/en-us/articles/40073787579671" target="_blank" rel="noreferrer noopener">https://support.cpanel.net/hc/en-us/articles/40073787579671</a>&nbsp;scans session files for attributes associated with this specific exploit. It was refined on 1 May to correct a false-positive on session.lock files&nbsp;identified&nbsp;by partners during their own fleet testing. Any server that was unpatched at any point during the incident window should be scanned using the current version of the script.&nbsp;</p>



<p class="wp-block-paragraph">Automated remediation tooling was deployed on our side to accelerate update adoption across the installed base, including&nbsp;a&nbsp;majority of&nbsp;affected builds,&nbsp;a number of&nbsp;end-of-life versions and a&nbsp;dedicated path for CL6/C6 environments accessible via&nbsp;<mark style="background-color:rgba(0, 0, 0, 0)" class="has-inline-color has-black-color">run_security_update</mark>. This allowed us to drive patch coverage to&nbsp;over&nbsp;98%&nbsp;of servers as of&nbsp;today&nbsp;without requiring manual intervention across every affected configuration.&nbsp;Coverage continues to expand&nbsp;through specific mitigation steps outlined in our&nbsp;<a href="https://support.cpanel.net/hc/en-us/articles/40073787579671" target="_blank" rel="noreferrer noopener">support article</a>.&nbsp;</p>



<h3 class="wp-block-heading"><strong>Updates for Legacy Versions&nbsp;</strong>&nbsp;</h3>



<p class="wp-block-paragraph">In addition to all currently supported tiers, we delivered targeted updates for v86, v94, v102, v124, and v130, which have been outside standard support for some time, along with a dedicated update tier for CL6/C6 (CloudLinux 6) environments, available through the run_security_update autofixer.</p>



<p class="wp-block-paragraph">Each of these required individual engineering work: targeted porting, version-specific validation, and full regression testing before release.&nbsp;</p>



<h2 class="wp-block-heading"><strong>Working Closely with Partners on Edge Cases</strong>&nbsp;</h2>



<p class="wp-block-paragraph">The update coverage we can report today was built alongside our partners, not independently of them. Over the past week, hosting partners and server administrators have been active participants in the response, and we want to be specific about what that looked like.&nbsp;</p>



<h3 class="wp-block-heading"><strong>Testing the Detection Script Against Live Fleets</strong>&nbsp;</h3>



<p class="wp-block-paragraph">Several partners ran the detection script across their server fleets in the days after publication and reported edge cases that had not surfaced in our own testing environment.&nbsp;This partner&nbsp;feedback is what produced the 1 May update to the script. Their environments effectively extended our validation coverage in ways that improved the quality of the tooling for everyone.&nbsp;</p>



<h3 class="wp-block-heading"><strong>Validating Update Behaviour on Non-Standard Configurations</strong>&nbsp;</h3>



<p class="wp-block-paragraph">Pinned, locked, and version-restricted configurations do not always behave the way standard configurations do when an update runs. Partners with these environments worked directly alongside our engineering team to&nbsp;validate&nbsp;tooling behaviour against their specific setups, and to surface update blockers before broader rollout. Several of the back-ports for older version tiers were shaped directly by these conversations: partners described exactly what their fleet was running and why it could not move, and our team built the update path around that constraint.&nbsp;</p>



<h3 class="wp-block-heading"><strong>Coordinating Customer Communications</strong>&nbsp;</h3>



<p class="wp-block-paragraph">A number of&nbsp;partners aligned their own customer communications with ours, requesting accuracy checks, version-specific guidance, and technical detail they could relay to their support teams. We supported each of these requests directly. The result was a more consistent message reaching downstream customers across a wide range of hosting environments.&nbsp;</p>



<h3 class="wp-block-heading"><strong>Surfacing Partner-Specific Update Blockers</strong>&nbsp;</h3>



<p class="wp-block-paragraph">In several cases, partners&nbsp;identified&nbsp;conditions specific to their environment that prevented the standard update path from completing and brought them to our attention directly.&nbsp;Our team prioritised each one as part of the incident response rather than routing it through standard support. That prioritisation contributed directly to the pace at which update coverage moved.&nbsp;</p>



<div style="color:#0369a1;background-color:#e0f2fe" class="wp-block-roelmagdaleno-callout-block has-text-color has-background is-layout-flex wp-container-roelmagdaleno-callout-block-is-layout-4fc3f8e1 wp-block-roelmagdaleno-callout-block-is-layout-flex"><div>
<p class="has-text-align-left wp-block-paragraph"><em>“The server coverage we have reached within days of updates being available reflects a genuine collaboration. Partners tested our tooling, flagged issues, worked through non-standard configurations alongside our engineers, and shared information that made our response better. That kind of partnership is what this ecosystem is built on.”</em>&nbsp;<br><strong>Team cPanel</strong>&nbsp;</p>
</div></div>



<h2 class="wp-block-heading has-text-align-left"><strong>Further Context</strong></h2>



<p class="wp-block-paragraph">During the course of&nbsp;April, we received separate reports&nbsp;regarding&nbsp;a possible pre-authentication&nbsp;issue in cPanel &amp; WHM. For one of the two reports, our team engaged in follow-up correspondence with the person behind it to better understand, categorize and clarify the information provided. With the details available at that stage, we were unable to independently reproduce the reported behavior, and our&nbsp;initial&nbsp;assessment did not confirm a vulnerability. When the second report arrived with&nbsp;additional&nbsp;context, our team was able to reproduce and confirm the vulnerability the same day, and our incident response protocol began&nbsp;immediately.</p>



<h2 class="wp-block-heading"><strong>What We Are Changing</strong>&nbsp;</h2>



<p class="wp-block-paragraph">The following commitments reflect&nbsp;our&nbsp;focus on&nbsp;continuous improvements&nbsp;in security practices, to address an evolving threat landscape.&nbsp;</p>



<figure class="wp-block-table is-style-regular"><table class="has-fixed-layout"><tbody><tr><td><strong>Commitment</strong>&nbsp;</td><td><strong>What It Means</strong>&nbsp;</td></tr><tr><td><strong>CVE Numbering Authority</strong>&nbsp;</td><td>We are applying to become a CVE Numbering&nbsp;Authority.&nbsp;This&nbsp;will give us the ability to assign CVE identifiers to vulnerabilities in cPanel &amp; WHM directly, without reliance on third-party timelines. In the interim,&nbsp;we&nbsp;will continue issuing CVEs for any&nbsp;new items&nbsp;through an existing partnership with a CNA.&nbsp;&nbsp;</td></tr><tr><td><strong>Partner&nbsp;&amp; Customer&nbsp;Communication</strong>&nbsp;</td><td>We are formalising two distinct communication tracks.&nbsp;We&nbsp;will&nbsp;continue&nbsp;publishing&nbsp;a structured notice covering upcoming updates,&nbsp;priority items, and versions approaching end-of-life, giving&nbsp;our&nbsp;partners&nbsp;&amp; customers&nbsp;the lead time needed to plan accordingly. For&nbsp;critical&nbsp;vulnerabilities,&nbsp;we will communicate&nbsp;directly ahead of public disclosure, if and&nbsp;where coordinated timing allows, as we have done in the past week.&nbsp;</td></tr><tr><td><strong>Additional Capabilities</strong>&nbsp;</td><td>We are adding&nbsp;additional&nbsp;resources to our existing security tooling&nbsp;scans&nbsp;and review, driven by both humans and AI&nbsp;tooling.&nbsp;</td></tr></tbody></table></figure>



<h2 class="wp-block-heading"><strong>Thank You</strong>&nbsp;</h2>



<p class="wp-block-paragraph">Our&nbsp;customers, our&nbsp;partners&nbsp;and their customers,&nbsp;depend on this infrastructure, and that dependency carries a responsibility we take seriously.&nbsp;Our response has been to&nbsp;fix first,&nbsp;move quickly,&nbsp;provide clear and actionable communication, and commit&nbsp;to a continuous&nbsp;improvement in our processes to address a fast-changing threat landscape.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">To the partners who worked alongside our team this past week, testing tooling, working through non-standard configurations, aligning customer communications, and flagging issues as they found them: the update coverage we have achieved is a direct result of that collaboration. Thank you.</p>



<p class="wp-block-paragraph">To the security community whose scrutiny has kept this incident in clear focus: that scrutiny is&nbsp;appropriate&nbsp;and it produces better outcomes.&nbsp;Thank you.</p>



<p class="wp-block-paragraph">The support article at&nbsp;<a href="https://support.cpanel.net/hc/en-us/articles/40073787579671" target="_blank" rel="noreferrer noopener">https://support.cpanel.net/hc/en-us/articles/40073787579671</a>&nbsp;remains&nbsp;the live operational reference and is updated continuously.</p>



<!-- &#8209; -->
<style>
@media (max-width: 1367px) {
    #article-content {
        width: 100%;
    }
}
@media (min-width: 991px) {
   #brxe-xuiyqh {
      width: 64%;
   }
   #brxe-jjxbcv {
      width: 36%;
   }
   .wp-block-table table tbody tr:nth-child(1) td:nth-child(1) {
      width: 30%;
   }
   .wp-block-table table tbody tr:nth-child(1) td:nth-child(1) {
      width: 30%;
   }
}
#article-sidebar {
   display: none;
}
</style>



<p class="wp-block-paragraph"></p>
<p>The post <a href="https://www.cpanel.net/blog/security/security-update-cve-2026-41940/">CVE-2026-41940: Response, Actions and Next Steps</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cpanel.net/blog/security/security-update-cve-2026-41940/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Strengthening Server Security: Top Cybersecurity Features in cPanel</title>
		<link>https://www.cpanel.net/blog/security/strengthening-server-security-top-cybersecurity-features-in-cpanel/</link>
					<comments>https://www.cpanel.net/blog/security/strengthening-server-security-top-cybersecurity-features-in-cpanel/#respond</comments>
		
		<dc:creator><![CDATA[Megan Reynolds]]></dc:creator>
		<pubDate>Thu, 30 Oct 2025 14:21:13 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[proactive defense]]></category>
		<category><![CDATA[top security features]]></category>
		<category><![CDATA[WordPress security]]></category>
		<guid isPermaLink="false">https://www.cpanel.net/?p=79085</guid>

					<description><![CDATA[<p>October marks Cybersecurity Awareness Month, and at cPanel, we’re here to help hosting providers, developers, and website owners keep their digital spaces safe. Security is at the heart of everything we do, from spotting vulnerabilities early to keeping servers protected and software up to date, so our users can focus on what they do best, [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/security/strengthening-server-security-top-cybersecurity-features-in-cpanel/">Strengthening Server Security: Top Cybersecurity Features in cPanel</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">October marks Cybersecurity Awareness Month, and at cPanel, we’re here to help hosting providers, developers, and website owners keep their digital spaces safe. Security is at the heart of everything we do, from spotting vulnerabilities early to keeping servers protected and software up to date, so our users can focus on what they do best, without worrying about threats.  </p>



<p class="wp-block-paragraph">Here’s a look at the top cybersecurity features that make cPanel a trusted choice for secure web hosting in 2025 and beyond.&nbsp;</p>



<h2 class="wp-block-heading"><strong>1. Proactive Security Updates &amp; CVE Response</strong>&nbsp;</h2>



<p class="wp-block-paragraph">We’re more committed than ever to keeping things transparent and staying ahead of security risks. Throughout 2025, we’ve provided <strong>regular security updates </strong>to tackle vulnerabilities both within cPanel &amp; WHM and in upstream components such as PHP, Apache, Node.js, and ModSecurity.&nbsp;</p>



<ul class="wp-block-list">
<li><strong>15+ CVEs addressed in Q3 2025 alone</strong>, including CVE-2025-40929, CVE-2025-6965, and CVE-2025-20260 </li>
</ul>



<ul class="wp-block-list">
<li><strong>Security patches</strong> rolled out for all supported versions: v110, v118, v128, v130, and v132 </li>
</ul>



<ul class="wp-block-list">
<li><strong>Swift vulnerability responses</strong> ensuring users stay protected without disruption </li>
</ul>



<p class="wp-block-paragraph">This proactive approach helps hosting providers maintain a hardened environment with minimal downtime or manual intervention.&nbsp;</p>



<h2 class="wp-block-heading"><strong>2. SSL/TLS Certificate Management Made Easy</strong>&nbsp;</h2>



<p class="wp-block-paragraph">Security by default is our standard. With <strong>AutoSSL</strong>, every domain and subdomain hosted on cPanel can automatically receive and renew SSL certificates, including <strong>free certificates via Let’s Encrypt</strong>.&nbsp;</p>



<figure class="wp-block-image size-full"><img fetchpriority="high" decoding="async" width="885" height="598" src="https://www.cpanel.net/wp-content/uploads/2025/10/Screenshot-2025-10-16-at-13.11.59.png" alt="A screenshot of the Manage AutoSSL interface showing 'Providers', 'Options', 'Logs', and 'Manage Users' tabs." class="wp-image-79097" srcset="https://www.cpanel.net/wp-content/uploads/2025/10/Screenshot-2025-10-16-at-13.11.59.png 885w, https://www.cpanel.net/wp-content/uploads/2025/10/Screenshot-2025-10-16-at-13.11.59-300x203.png 300w, https://www.cpanel.net/wp-content/uploads/2025/10/Screenshot-2025-10-16-at-13.11.59-768x519.png 768w" sizes="(max-width: 885px) 100vw, 885px" /></figure>



<p class="wp-block-paragraph">Whether you’re using DV or OV validation, cPanel ensures <strong>end-to-end encryption</strong> for all your hosted domains, making HTTPS accessible to everyone. No more expired certificates or complex setup steps — just seamless, secure encryption for your users. </p>



<h2 class="wp-block-heading"><strong>3. WordPress Security Through WP Guardian</strong>&nbsp;</h2>



<p class="wp-block-paragraph">WordPress powers millions of websites. Keeping them secure requires a proactive defense solution. That’s why we introduced <strong>WP Guardian</strong>, a built-in security solution for your WordPress installations. </p>



<ul class="wp-block-list">
<li><strong>Automatic malware scanning and vulnerability patching</strong> </li>
</ul>



<ul class="wp-block-list">
<li><strong>Powered by Patchstack </strong>for real-time virtual patching without code changes </li>
</ul>



<ul class="wp-block-list">
<li><strong>Proactive protection</strong> against zero-day exploits and known vulnerabilities </li>
</ul>



<figure class="wp-block-image size-full"><img decoding="async" width="1400" height="710" src="https://www.cpanel.net/wp-content/uploads/2025/10/WP-guardian-clear.png" alt="" class="wp-image-79141" srcset="https://www.cpanel.net/wp-content/uploads/2025/10/WP-guardian-clear.png 1400w, https://www.cpanel.net/wp-content/uploads/2025/10/WP-guardian-clear-300x152.png 300w, https://www.cpanel.net/wp-content/uploads/2025/10/WP-guardian-clear-1024x519.png 1024w, https://www.cpanel.net/wp-content/uploads/2025/10/WP-guardian-clear-768x389.png 768w" sizes="(max-width: 1400px) 100vw, 1400px" /></figure>



<p class="wp-block-paragraph">WP Guardian acts before threats can take hold, keeping your WordPress websites safe, stable, and secure.&nbsp;</p>



<h2 class="wp-block-heading"><strong>4. Comprehensive Server Protection with Imunify360</strong>&nbsp;</h2>



<p class="wp-block-paragraph">For hosting providers seeking all-in-one protection, <strong>Imunify360</strong> is the perfect choice. Through our partnership with Imunify, we offer seamless integration with cPanel for full-stack server security.&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Multi-layered defense</strong>: Firewall, malware scanning, intrusion prevention, and IP reputation management </li>
</ul>



<ul class="wp-block-list">
<li><strong>Automated patching</strong> to reduce administrative overhead </li>
</ul>



<ul class="wp-block-list">
<li><strong>Flexible deployment</strong> through Imunify360 or ImunifyAV+ </li>
</ul>



<p class="wp-block-paragraph">This powerful integration ensures that servers stay protected from evolving threats without slowing down performance.&nbsp;</p>



<h2 class="wp-block-heading"><strong>5. Strengthening Access Security with Two-Factor Authentication (2FA)</strong>&nbsp;</h2>



<p class="wp-block-paragraph">Protecting administrative access is one of the most effective ways to keep servers safe. cPanel supports <strong>TOTP-based two-factor authentication (2FA)</strong> for WHM and user logins, giving both administrators and end users the ability to secure their accounts with an extra layer of protection.&nbsp;</p>



<figure class="wp-block-image size-full"><img decoding="async" width="886" height="239" src="https://www.cpanel.net/wp-content/uploads/2025/10/Screenshot-2025-10-16-at-13.14.56.png" alt="" class="wp-image-79117" srcset="https://www.cpanel.net/wp-content/uploads/2025/10/Screenshot-2025-10-16-at-13.14.56.png 886w, https://www.cpanel.net/wp-content/uploads/2025/10/Screenshot-2025-10-16-at-13.14.56-300x81.png 300w, https://www.cpanel.net/wp-content/uploads/2025/10/Screenshot-2025-10-16-at-13.14.56-768x207.png 768w" sizes="(max-width: 886px) 100vw, 886px" /></figure>



<p class="wp-block-paragraph">By encouraging the use of <strong>multi-factor authentication</strong>, we help users embrace best practices that significantly reduce the risk of unauthorized access.&nbsp;</p>



<h2 class="wp-block-heading"><strong>6. Preparing for the CSF Transition</strong>&nbsp;</h2>



<p class="wp-block-paragraph">In August 2025, <strong>ConfigServer (CSF)</strong> reached end-of-life. Nearly half of cPanel servers relied on CSF, and we heard our customers loud and clear. </p>



<p class="wp-block-paragraph">We’re <strong>actively exploring native firewall solutions</strong> and <strong>enhanced integration with Imunify360</strong> to ensure smooth transitions and continuous protection. Learn more about our CSF sunset response: <a href="https://www.cpanel.net/blog/products/the-end-of-configserver/" target="_blank" rel="noreferrer noopener">The End of ConfigServer.</a>&nbsp;</p>



<p class="wp-block-paragraph">Our goal remains simple: to deliver a <strong>customer-first approach</strong> to server security that evolves with your needs.&nbsp;</p>



<h2 class="wp-block-heading"><strong>7. Continuous OS &amp; Software Updates</strong>&nbsp;</h2>



<p class="wp-block-paragraph">A secure hosting stack depends on staying up to date. Through <strong>EasyApache 4</strong>, cPanel delivered <strong>41 releases in 2024</strong>, addressing <strong>over 61 CVEs</strong> across PHP, Apache, and related technologies.&nbsp;</p>



<p class="wp-block-paragraph">We also provide <strong>modern OS support</strong> and upgrade tools like <strong>ELevate</strong>, ensuring hosting environments can safely migrate to newer distributions to stay current with OS level security updates and features.&nbsp;</p>



<h2 class="wp-block-heading"><strong>8. Built-In Security Advisor &amp; Monitoring Tools</strong>&nbsp;</h2>



<p class="wp-block-paragraph">Security isn’t a one-time action. It’s an active, ongoing process. That’s why cPanel includes tools that help users <strong>monitor, identify, and respond</strong> to potential issues before they become threats.&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Security Advisor</strong>: Offers clear, actionable recommendations to improve your server’s security posture </li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="558" height="280" src="https://www.cpanel.net/wp-content/uploads/2025/10/Screenshot-2025-10-16-at-13.10.23.png" alt="" class="wp-image-79121" srcset="https://www.cpanel.net/wp-content/uploads/2025/10/Screenshot-2025-10-16-at-13.10.23.png 558w, https://www.cpanel.net/wp-content/uploads/2025/10/Screenshot-2025-10-16-at-13.10.23-300x151.png 300w" sizes="auto, (max-width: 558px) 100vw, 558px" /></figure>



<ul class="wp-block-list">
<li><strong>cpHulk</strong>: Provides built-in brute force protection </li>
</ul>



<ul class="wp-block-list">
<li><strong>Real-time monitoring</strong> for server health and security metrics </li>
</ul>



<figure class="wp-block-image size-full"><img loading="lazy" decoding="async" width="844" height="407" src="https://www.cpanel.net/wp-content/uploads/2025/10/Screenshot-2025-10-16-at-13.11.01-1.png" alt="" class="wp-image-79125" srcset="https://www.cpanel.net/wp-content/uploads/2025/10/Screenshot-2025-10-16-at-13.11.01-1.png 844w, https://www.cpanel.net/wp-content/uploads/2025/10/Screenshot-2025-10-16-at-13.11.01-1-300x145.png 300w, https://www.cpanel.net/wp-content/uploads/2025/10/Screenshot-2025-10-16-at-13.11.01-1-768x370.png 768w" sizes="auto, (max-width: 844px) 100vw, 844px" /></figure>



<p class="wp-block-paragraph">With these insights, we aim to simplify and strengthen the way you maintain a secure environment.</p>



<h2 class="wp-block-heading"><strong>Keeping Servers Safe, Together</strong>&nbsp;</h2>



<p class="wp-block-paragraph">Cybersecurity is a shared responsibility. At cPanel, we remain committed to helping our partners and users stay ahead of threats with a secure, transparent, and continuously improving platform.&nbsp;</p>



<p class="wp-block-paragraph">Stay secure. Stay updated. Stay ahead, with cPanel. </p>
<p>The post <a href="https://www.cpanel.net/blog/security/strengthening-server-security-top-cybersecurity-features-in-cpanel/">Strengthening Server Security: Top Cybersecurity Features in cPanel</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cpanel.net/blog/security/strengthening-server-security-top-cybersecurity-features-in-cpanel/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The Ultimate cPanel Security Checklist for Sysadmins</title>
		<link>https://www.cpanel.net/blog/security/cpanel-security-checklist-for-sysadmins/</link>
					<comments>https://www.cpanel.net/blog/security/cpanel-security-checklist-for-sysadmins/#respond</comments>
		
		<dc:creator><![CDATA[Julian Holt]]></dc:creator>
		<pubDate>Thu, 12 Jun 2025 12:53:06 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://www.cpanel.net/?p=68829</guid>

					<description><![CDATA[<p>If you&#8217;re a system administrator, you&#8217;ll want to check out our cPanel Security Checklist. After all, you know that securing your cPanel environment, and keeping it secure, is your top priority. A properly configured cPanel server can prevent cyber threats, data breaches, and unauthorized access.&#160;&#160; However, misconfigurations and overlooked settings can leave your server vulnerable [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/security/cpanel-security-checklist-for-sysadmins/">The Ultimate cPanel Security Checklist for Sysadmins</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">If you&#8217;re a system administrator, you&#8217;ll want to check out our cPanel Security Checklist. After all, you know that securing your <a href="https://www.cpanel.net/" target="_blank" rel="noreferrer noopener">cPanel</a> environment, and keeping it secure, is your top priority. A properly configured cPanel server can prevent cyber threats, data breaches, and unauthorized access.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">However, misconfigurations and overlooked settings can leave your server vulnerable to attacks. This can lead to irretrievable data loss, increased costs, legal and compliance issues, and malware infections, to name just a few of the biggest problems.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">That’s why we’ve compiled the information in this post: the ultimate cPanel security checklist! We’ll cover the essential security measures that every sysadmin should implement. From firewall configuration and backups, all the way to SSL certificates and intrusion detection, this guide will help you fortify your cPanel server against potential threats.&nbsp;</p>



<p class="wp-block-paragraph">Let’s get to it!&nbsp;&nbsp;</p>



<h2 class="wp-block-heading">Summary of What You’ll Learn&nbsp;</h2>



<ul class="wp-block-list">
<li>Use a step-by-step checklist to secure your cPanel servers. Such as strong passwords, two-factor authentication, and IP access to prevent unauthorized logins and brute-force attacks&nbsp;</li>



<li>Focuses on best practices for system administrators to prevent cyber threats and unauthorized access&nbsp;</li>



<li>Enable automated and remote backups, test them regularly, and always stay up to date with cPanel, WHM, and third-party software.&nbsp;</li>



<li>Aims to help admins maintain a secure, compliant, and high-performance hosting environment&nbsp;</li>
</ul>



<figure class="wp-block-pullquote has-text-align-center has-medium-font-size"><blockquote><p>“In 2024, the global average cost of a single data breach hit an all‑time high of&nbsp;<strong>$4.88 million</strong>, a 10 % jump from the previous year.”&nbsp;</p><cite><a href="https://spacelift.io/blog/data-breach-statistics" target="_blank" rel="noreferrer noopener">60+ Key Data Breach Statistics for 2025</a>&nbsp;</cite></blockquote></figure>



<h2 class="wp-block-heading"><strong>1. Secure Your cPanel Login</strong>&nbsp;</h2>



<h3 class="wp-block-heading"><strong>Use Strong Passwords and Two-Factor Authentication (2FA)</strong>&nbsp;</h3>



<p class="wp-block-paragraph">Ensuring both you and all <a href="https://www.cpanel.net/products/cpanel-whm-features/" target="_blank" rel="noreferrer noopener">cPanel and WHM</a> users have the correct password and security protocols set up is the first step towards a safe environment.  </p>



<ul class="wp-block-list">
<li>Ensure that all cPanel and WHM users have strong, unique passwords. For specific help with configuring this, follow the guide <a href="https://docs.cpanel.net/whm/security-center/password-strength-configuration/" target="_blank" rel="noreferrer noopener">here</a>. &nbsp;</li>



<li>Enforce <strong>Two-Factor Authentication (2FA)</strong> via WHM &gt; Security Center &gt; Two-Factor Authentication.&nbsp;</li>



<li>Disable the “root” user login and use sudo-enabled accounts instead.&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>Restrict Access by IP Address</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Set up IP-based access control to high privileged or admin accounts by restricting logins to specific IPs.&nbsp;</li>



<li>Use <strong>cPHulk Brute Force Protection</strong> to block repeated failed login attempts.&nbsp;</li>
</ul>



<h2 class="wp-block-heading"><strong>2. Secure the cPanel Server with Firewalls</strong>&nbsp;</h2>



<p class="wp-block-paragraph">Firewalls help you filter traffic, prevent unauthorized access, mitigate attacks, and help you monitor logins, to name just a few of the ways they keep your environment safe.&nbsp;&nbsp;</p>



<h3 class="wp-block-heading"><strong>Install and Configure CSF (ConfigServer Security &amp; Firewall)</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Install <strong>ConfigServer Security &amp; Firewall (CSF)</strong> to manage network traffic and block suspicious activity.&nbsp;</li>



<li>Enable <strong>Login Failure Daemon (LFD)</strong> to detect repeated login failures.&nbsp;</li>



<li>Whitelist trusted IPs and blacklist known malicious ones.&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>Close Unused Ports</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Disable all unnecessary ports to minimize entry points for attackers.&nbsp;</li>



<li>Use WHM &gt; Security Center &gt; <strong>Host Access Control</strong> to control access.&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>Enable ModSecurity</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Navigate to WHM &gt; Security Center &gt; <strong>ModSecurity Configuration</strong>.&nbsp;</li>



<li>Ensure that <strong>OWASP ModSecurity Core Rule Set (CRS)</strong> is enabled to protect against common web vulnerabilities.&nbsp;</li>
</ul>



<h2 class="wp-block-heading"><strong>3. SSL and Encryption Best Practices</strong>&nbsp;</h2>



<p class="wp-block-paragraph">Following best practice for SSL and encryption ensures a continued level of trust between you and your users and keeps all your data (and theirs!) protected.&nbsp;&nbsp;</p>



<h3 class="wp-block-heading"><strong>Enforce SSL for cPanel, WHM, and Webmail</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Enable <strong>AutoSSL</strong> in WHM &gt; Manage AutoSSL to provide free SSL certificates.&nbsp;</li>



<li>Force SSL redirection in WHM &gt; Tweak Settings &gt; <strong>Require SSL for cPanel Services</strong>.&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>Disable Weak SSL/TLS Protocols</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Navigate to WHM &gt; Service Configuration &gt; Apache Configuration &gt; Global Configuration.&nbsp;</li>



<li>Disable <strong>TLS 1.0 and 1.1</strong>, ensuring only TLS 1.2 and 1.3 are allowed. TLI 1.0 and 1.1 are deprecated and no longer part of best practice.&nbsp;&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>Use Strong Cipher Suites</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Modify your Apache or Nginx configuration to allow only secure cipher suites by following <a href="https://httpd.apache.org/docs/trunk/ssl/ssl_howto.html#:~:text=a%20particular%20URL%3F-,how%20can%20i%20create%20an%20ssl%20server%20which%20accepts%20strong%20encryption%20only%3F,-The%20following%20configuration" target="_blank" rel="noreferrer noopener">this guide</a>. &nbsp;</li>



<li>Test your server security using <strong>Qualys SSL Labs</strong> (<a href="https://www.ssllabs.com/ssltest/" target="_blank" rel="noreferrer noopener">https://www.ssllabs.com/ssltest/</a>).&nbsp;</li>
</ul>


<div class="wp-block-image">
<figure class="aligncenter size-full"><img loading="lazy" decoding="async" width="1216" height="600" src="https://www.cpanel.net/wp-content/uploads/2025/06/cPanel-Blog-Two-factor-Authentocation.jpg" alt="" class="wp-image-76513" srcset="https://www.cpanel.net/wp-content/uploads/2025/06/cPanel-Blog-Two-factor-Authentocation.jpg 1216w, https://www.cpanel.net/wp-content/uploads/2025/06/cPanel-Blog-Two-factor-Authentocation-300x148.jpg 300w, https://www.cpanel.net/wp-content/uploads/2025/06/cPanel-Blog-Two-factor-Authentocation-1024x505.jpg 1024w, https://www.cpanel.net/wp-content/uploads/2025/06/cPanel-Blog-Two-factor-Authentocation-768x379.jpg 768w" sizes="auto, (max-width: 1216px) 100vw, 1216px" /></figure>
</div>


<h2 class="wp-block-heading"><strong>4. Secure User Accounts and Permissions</strong>&nbsp;</h2>



<p class="wp-block-paragraph">This step is incredibly important in order to prevent unauthorized access to your system, as well as to maintain data integrity and minimize insider threats. In general, it’s always best to follow the Least Privileges Principle when you assign roles and permissions to users.&nbsp;&nbsp;</p>



<h3 class="wp-block-heading"><strong>Implement CageFS within CloudLinux</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Install CloudLinux for improved security and resource allocation.&nbsp;</li>



<li>Use <strong>CageFS</strong> to isolate user accounts and prevent cross-account attacks.&nbsp;</li>



<li><strong>Restrict File Permissions</strong>&nbsp;</li>



<li>Set secure file permissions by following the FileProtect documentation <a href="https://docs.cpanel.net/ea4/apache/the-easyapache-4-fileprotect-option/" target="_blank" rel="noreferrer noopener">here</a>.&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>Disable Shell Access for Non-Admins</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Go to WHM &gt; Account Functions &gt; <strong>Manage Shell Access</strong> and disable shell access for all non-admin users.&nbsp;</li>
</ul>



<h2 class="wp-block-heading"><strong>5. Regular Backups and Disaster Recovery</strong>&nbsp;</h2>



<p class="wp-block-paragraph">Regular backups might seem like a simple task, but you’d be surprised how many companies have been the victims of data loss due to not sufficiently backing up. One survey on this subject from 2024 concluded that over 80% of organizations lost data due to not backing up enough, so don’t think it can’t happen to you too!&nbsp;&nbsp;</p>



<h3 class="wp-block-heading"><strong>Enable cPanel Backups</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Configure <strong>Automated Backups</strong> via WHM &gt; Backup &gt; Backup Configuration.&nbsp;</li>



<li>Store backups on a <strong>remote server</strong> to prevent loss in case of an attack.&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>Test Your Backups</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Regularly restore a backup in a test environment to verify integrity.&nbsp;</li>



<li><strong>Use Incremental Backups</strong>&nbsp;</li>



<li>Enable <strong>Incremental Backups</strong> to reduce storage space while maintaining recent changes.&nbsp;</li>
</ul>



<h2 class="wp-block-heading"><strong>6. Secure Database and PHP Settings</strong></h2>



<p class="wp-block-paragraph">This part of the process is incredibly important for securing sensitive data and ensuring data integrity, as well as preventing code injection and enhancing performance.&nbsp;&nbsp;</p>



<h3 class="wp-block-heading"><strong>Protect MySQL Databases</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Restrict MySQL access to localhost unless required.&nbsp;</li>



<li>Use <strong>strong, unique passwords</strong> for database users.&nbsp;</li>



<li>Disable MySQL <strong>SHOW DATABASES</strong> for non-root users.&nbsp;</li>



<li>Follow the guide <a href="https://cheatsheetseries.owasp.org/cheatsheets/Database_Security_Cheat_Sheet.html" target="_blank" rel="noreferrer noopener">here</a> for a more detailed explanation.&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>Harden PHP Configuration</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Edit /etc/php.ini and set: disable_functions = exec,passthru,shell_exec,system&nbsp;<br>expose_php = Off&nbsp;<br>allow_url_fopen = Off&nbsp;</li>



<li>Enable <strong>open_basedir restriction</strong> in WHM &gt; MultiPHP Manager.&nbsp;</li>



<li>For a more specific set of configurations and assistance, follow the guide <a href="https://cheatsheetseries.owasp.org/cheatsheets/PHP_Configuration_Cheat_Sheet.html" target="_blank" rel="noreferrer noopener">here</a>.&nbsp;</li>
</ul>



<h2 class="wp-block-heading"><strong>7. Enable Intrusion Detection and Security Logs</strong>&nbsp;</h2>



<p class="wp-block-paragraph">This part of the process is incredibly important for real time threat detection, identifying vulnerabilities, as well as compliance!&nbsp;&nbsp;</p>



<h3 class="wp-block-heading"><strong>Install and Configure Fail2Ban</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Install <strong>Fail2Ban</strong> to monitor and block suspicious login attempts.&nbsp;</li>



<li>Configure rules to ban IPs after repeated failed logins.&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>Monitor Logs for Suspicious Activity</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Regularly check security logs, <a href="https://www.plesk.com/blog/featured/linux-logs-explained/" target="_blank" rel="noreferrer noopener">this blog</a> can be helpful in learning how!&nbsp;</li>



<li>Set up log monitoring alerts to notify you of unusual activity.&nbsp;</li>
</ul>



<h2 class="wp-block-heading"><strong>8. Keep Software and Plugins Updated</strong>&nbsp;</h2>



<p class="wp-block-paragraph">This might seem basic, but again, sometimes the easiest and simplest parts of security processes are the ones we take for granted, and therefore the ones it’s easy to forget about and miss.&nbsp;&nbsp;</p>



<h3 class="wp-block-heading"><strong>Regularly Update cPanel and WHM</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Enable automatic updates in WHM &gt; Update Preferences.&nbsp;</li>



<li>Regularly check <strong>WHM &gt; cPanel Version Information</strong> for updates.&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>Update Third-Party Plugins and Applications</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Ensure WordPress, Joomla, and other CMS applications are up to date.&nbsp;</li>



<li>Use <strong>WordPress Toolkit</strong> to manage WordPress security settings.&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>Remove Unused Plugins and Themes</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Disable and delete any unused plugins to minimize security risks.&nbsp;</li>
</ul>



<h2 class="wp-block-heading"><strong>9. DDoS Protection and Network Security</strong>&nbsp;</h2>



<p class="wp-block-paragraph">Ensuring you’re compliant with this part of the process helps to prevent service interruptions, safeguard your reputation, as well as reducing financial losses and protecting sensitive data.&nbsp;</p>



<h3 class="wp-block-heading"><strong>Use Cloudflare or a WAF</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Integrate <strong>Cloudflare</strong> to provide DDoS protection and web application firewall (WAF).&nbsp;</li>



<li>Enable <strong>Imunify360</strong> for advanced malware protection.&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>Implement Rate Limiting</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Configure <strong>ModEvasive</strong> to protect against brute-force attacks.&nbsp;</li>



<li>Set up rate limiting for login attempts.&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>Use CDN for Improved Security</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Implement <strong>Content Delivery Networks (CDN)</strong> to reduce server load and protect against attacks.&nbsp;</li>
</ul>



<h2 class="wp-block-heading"><strong>10. Security Audits and Best Practices</strong>&nbsp;</h2>



<p class="wp-block-paragraph">Performing regular security audits on your cPanel environment is vital to keeping your users’ data safe, and their trust in you high.&nbsp;</p>



<h3 class="wp-block-heading"><strong>Conduct Regular Security Audits</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Use <strong>cPanel Security Advisor</strong> (WHM &gt; Security Advisor) to check for vulnerabilities.&nbsp;</li>



<li>Perform <strong>manual security audits</strong> every quarter.&nbsp;</li>
</ul>



<h3 class="wp-block-heading"><strong>Educate Users and Staff</strong>&nbsp;</h3>



<ul class="wp-block-list">
<li>Train users on secure password policies and phishing awareness.&nbsp;</li>



<li><strong>Subscribe to Security Updates</strong>&nbsp;</li>



<li>Stay updated on <strong>cPanel security patches</strong> and apply them immediately.&nbsp;</li>



<li>Subscribe to <strong>cPanel’s security mailing list</strong> for alerts.&nbsp;</li>
</ul>



<h2 class="wp-block-heading"><strong>Conclusion</strong>&nbsp;</h2>



<p class="wp-block-paragraph">As you know, securing your cPanel server is an ongoing process, one that requires constant diligence and proactive management. By following our cPanel security checklist, you can significantly reduce the risk of security breaches and maintain a safe hosting environment, ensuring your team members and customers stay safe.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Regular updates, strong password policies, firewalls, backups, and active monitoring are key components of a strong security posture. Implement these measures today to safeguard your cPanel server against evolving cyber threats.&nbsp;</p>



<h2 class="wp-block-heading"><strong>Frequently Asked Questions (FAQs)</strong>&nbsp;</h2>



<div class="schema-faq wp-block-yoast-faq-block"><div class="schema-faq-section" id="faq-question-1750691956609"><strong class="schema-faq-question"><strong>1. Why is securing cPanel important?</strong> </strong> <p class="schema-faq-answer">A misconfigured or insecure cPanel server can lead to data breaches, malware infections, financial loss, and non-compliance with regulations. </p> </div> <div class="schema-faq-section" id="faq-question-1750691984442"><strong class="schema-faq-question"><strong>2. What are the first steps to secure cPanel?</strong></strong> <p class="schema-faq-answer">Use strong, unique passwords, enforce Two-Factor Authentication (2FA), and restrict access by IP address. Disable the root login for added security.</p> </div> <div class="schema-faq-section" id="faq-question-1750692005746"><strong class="schema-faq-question"><strong>3. How can firewalls protect a cPanel server?</strong> </strong> <p class="schema-faq-answer">Firewalls like CSF filter traffic, block suspicious logins, and close unused ports. Enabling LFD and ModSecurity adds further protection against common attacks. </p> </div> <div class="schema-faq-section" id="faq-question-1750692018229"><strong class="schema-faq-question"><strong>4. What are SSL/TLS best practices for cPanel?</strong></strong> <p class="schema-faq-answer">Enable AutoSSL, enforce SSL redirection, and disable outdated protocols (TLS 1.0/1.1). Use only strong cipher suites for encryption. </p> </div> <div class="schema-faq-section" id="faq-question-1750692026530"><strong class="schema-faq-question"><strong>5. How should user permissions be managed?</strong></strong> <p class="schema-faq-answer">Follow the Least Privilege Principle, use CloudLinux with CageFS, restrict shell access, and set secure file permissions. </p> </div> <div class="schema-faq-section" id="faq-question-1750692043306"><strong class="schema-faq-question"><strong>6. How often should backups be done?</strong> </strong> <p class="schema-faq-answer">Set up automatic daily backups, store them offsite, and regularly test their integrity to ensure data recovery in case of emergencies. </p> </div> <div class="schema-faq-section" id="faq-question-1750692057961"><strong class="schema-faq-question"><strong>7. How do I secure PHP and MySQL settings?</strong> </strong> <p class="schema-faq-answer">Harden PHP using php.ini and disable risky functions. Restrict MySQL access and privileges to reduce exposure to SQL injection attacks.</p> </div> <div class="schema-faq-section" id="faq-question-1750692090108"><strong class="schema-faq-question"><strong>8. What tools help with intrusion detection?</strong> </strong> <p class="schema-faq-answer">Install Fail2Ban to block brute-force attacks and monitor logs for suspicious activity. Set up alerts for real-time threat detection.</p> </div> <div class="schema-faq-section" id="faq-question-1750692117748"><strong class="schema-faq-question"><strong>9. How do I mitigate DDoS attacks on my cPanel server?</strong></strong> <p class="schema-faq-answer">Use services like Cloudflare and Imunify360, configure rate limiting, and deploy a Content Delivery Network (CDN) to absorb malicious traffic.</p> </div> <div class="schema-faq-section" id="faq-question-1750692129691"><strong class="schema-faq-question"><strong>10. What regular practices ensure long-term security?</strong> </strong> <p class="schema-faq-answer">Conduct quarterly security audits, train staff on security hygiene, subscribe to cPanel updates, and immediately patch known vulnerabilities. </p> </div> </div>
<p>The post <a href="https://www.cpanel.net/blog/security/cpanel-security-checklist-for-sysadmins/">The Ultimate cPanel Security Checklist for Sysadmins</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cpanel.net/blog/security/cpanel-security-checklist-for-sysadmins/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The Hidden Dangers of Using a Fraudulent cPanel License </title>
		<link>https://www.cpanel.net/blog/security/the-hidden-dangers-of-using-a-fraudulent-cpanel-license/</link>
					<comments>https://www.cpanel.net/blog/security/the-hidden-dangers-of-using-a-fraudulent-cpanel-license/#respond</comments>
		
		<dc:creator><![CDATA[Megan Reynolds]]></dc:creator>
		<pubDate>Tue, 27 May 2025 16:03:39 +0000</pubDate>
				<category><![CDATA[General Knowledge]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://www.cpanel.net/?p=68657</guid>

					<description><![CDATA[<p>cPanel is one of the most well-known and trusted hosting panels. Its user-friendly interface and powerful tools simplify the management of servers, websites, databases, and more. However, not all cPanel licenses are purchased through legitimate, authorized channels. Sometimes users are led down a risky path: the use of fraudulent or ‘cracked’ cPanel licenses. Here’s how [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/security/the-hidden-dangers-of-using-a-fraudulent-cpanel-license/">The Hidden Dangers of Using a Fraudulent cPanel License </a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">cPanel is one of the most well-known and trusted hosting panels. Its user-friendly interface and powerful tools simplify the management of servers, websites, databases, and more. However, not all cPanel licenses are purchased through legitimate, authorized channels. Sometimes users are led down a risky path: the use of fraudulent or ‘cracked’ cPanel licenses. Here’s how cPanel itself detects and handles <a href="https://www.cpanel.net/blog/security/from-detection-to-action-handling-fraudulent-cpanel-whm-licenses/">fraudulent licenses</a>.</p>



<p class="wp-block-paragraph">The short-term savings hide long-term dangers that can compromise your entire server or website. In this post, we dive deep into the hidden risks associated with using fraudulent cPanel licenses and why the true cost is far higher than the license fee you avoid.&nbsp;</p>



<h2 class="wp-block-heading">Understanding Fraudulent cPanel Licenses&nbsp;</h2>



<p class="wp-block-paragraph">A fraudulent cPanel license is one that has not been legitimately purchased directly from cPanel or an authorized partner. These licenses are often obtained illegally, bypassing the official activation and validation processes.&nbsp;</p>



<p class="wp-block-paragraph">Wondering how users end up with these unlicensed accounts? Often, it&#8217;s through attractive offers for &#8220;cheap cPanel hosting&#8221; or &#8220;cheap cPanel licenses&#8221; advertised on different forums or websites. These sellers might offer what looks like a working cPanel installation, but it&#8217;s built upon an illegal licensing foundation. Sometimes, users might even be unaware that they are receiving an unlicensed product, totally misled by the vendor&#8217;s claims.&nbsp;</p>



<h2 class="wp-block-heading">Hidden Risks and Dangers You Can&#8217;t Afford to Ignore&nbsp;</h2>



<p class="wp-block-paragraph">The consequences of using a fraudulent cPanel license don’t just include a conflict of ethics. Fake licenses pose serious threats to the security, stability, and legality of your servers and websites.&nbsp;</p>



<h2 class="wp-block-heading">Security Vulnerabilities&nbsp;</h2>



<p class="wp-block-paragraph">Fraudulent cPanel licenses are often tampered with. They can have malicious code or backdoors or even be intentionally left unpatched in order to create significant security holes.</p>



<p class="wp-block-paragraph">Hackers actively seek out servers running unlicensed software because they are easy targets. They can use these vulnerabilities to steal sensitive data, infect your server and your visitors with malware, launch phishing attacks, or even take complete control of your server.</p>



<p class="wp-block-paragraph">Want to learn how to protect your server? Check out our <a href="https://docs.cpanel.net/knowledge-base/security/security-best-practices/">cPanel Security Best Practices</a>.</p>



<h2 class="wp-block-heading">Lack of Support&nbsp;</h2>



<p class="wp-block-paragraph">By using a fake license, you’re working outside of the official cPanel ecosystem. This means you are not entitled to any official <a href="https://support.cpanel.net/hc/en-us">support from cPanel</a>.</p>



<p class="wp-block-paragraph">You won’t have access to cPanel’s expert support team, leaving you to diagnose and resolve potentially critical problems by yourself which can lead to extended downtime and a compromised server. If you meet technical issues, bugs, or security threats, you’re on your own.</p>



<h2 class="wp-block-heading">Legal Consequences&nbsp;</h2>



<p class="wp-block-paragraph">Software licenses are legal agreements. Using unlicensed software is a violation of copyright and licensing laws. cPanel actively monitors for fraudulent licenses, and if your server is identified, you could face legal repercussions. This can include significant fines and penalties, and in severe cases, facing legal action that could force your website and services offline.&nbsp;</p>



<h2 class="wp-block-heading">Performance Issues&nbsp;</h2>



<p class="wp-block-paragraph">Non-official licenses might be outdated or improperly optimized. These versions can lack the latest optimizations and updates of official licenses, leading to significant performance problems.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">You might experience slow website loading times, frequent downtime, errors, and crashes. This not only frustrates your users but also harms your online reputation. It can also negatively impact your search engine rankings.&nbsp;</p>



<h2 class="wp-block-heading">The Danger of Fraudster-Operated Update Mirrors&nbsp;</h2>



<p class="wp-block-paragraph">Some providers of fraudulent licenses run their own unofficial update mirrors. This allows servers with fake licenses to seemingly receive updates, giving users a false sense of security. However, these mirrors are not verified or controlled by cPanel.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">The people running them could decide to replace certain packages with their own versions at any time. This means that even when you think you&#8217;re updating your server, you could actually be installing malware or creating new vulnerabilities. These unofficial mirrors expose your server to third-party exploits and put your data at extreme risk.&nbsp;&nbsp;</p>



<h2 class="wp-block-heading">How to Identify and Avoid Fraudulent Licenses&nbsp;</h2>



<figure class="wp-block-image size-full"><img decoding="async" src="/wp-content/uploads/2025/05/cPanel_license_verification.png" alt="verify your license form screenshot" class="wp-image-68769"/></figure>



<p class="wp-block-paragraph">There are clear steps you can take to protect yourself:</p>



<ul class="wp-block-list">
<li><strong>Verify your license</strong>: The first step is to <a href="https://verify.cpanel.net/app/verify">verify the authenticity of your cPanel license</a>.</li>



<li><strong>Purchase from official sources</strong>: To avoid the risks altogether, purchase your cPanel license directly from the <a href="https://www.cpanel.net/pricing/">official cPanel website</a> or through an authorized <a href="https://partnernoc.cpanel.net/">cPanel Partner</a>. A list of official partners is available on the cPanel website.</li>



<li><strong>Question “cheap” offers</strong>: Always keep in mind that if a deal seems too good to be true, it probably is. Legitimate cPanel licenses have a standard pricing structure, and big deviations should raise red flags for you at once.</li>
</ul>



<h2 class="wp-block-heading">Conclusion&nbsp;</h2>



<p class="wp-block-paragraph">The short-term savings of using a fraudulent cPanel license are an illusion. They come at the expense of your security, reliability, legal standing, and performance. The hidden dangers and potential consequences just aren’t worth the risk. From critical server and site vulnerabilities to the complete lack of support available if things go wrong, using an unlicensed cPanel account puts your entire online presence in jeopardy.</p>



<p class="wp-block-paragraph">If you are currently using a fraudulent cPanel license, we strongly urge you to <a href="https://cpanel.net/pricing/">switch to a legitimate license</a> as soon as possible. Don’t compromise your online security and reputation for the sake of a “cheap” deal. By buying a legitimate cPanel license you’ll receive the best benefit of all: <strong>total peace of mind</strong>.</p>
<p>The post <a href="https://www.cpanel.net/blog/security/the-hidden-dangers-of-using-a-fraudulent-cpanel-license/">The Hidden Dangers of Using a Fraudulent cPanel License </a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cpanel.net/blog/security/the-hidden-dangers-of-using-a-fraudulent-cpanel-license/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>A Proactive Approach to Server Management with cPanel &#038; WHM </title>
		<link>https://www.cpanel.net/blog/products/a-proactive-approach-to-server-management-with-cpanel-whm/</link>
					<comments>https://www.cpanel.net/blog/products/a-proactive-approach-to-server-management-with-cpanel-whm/#respond</comments>
		
		<dc:creator><![CDATA[Megan Reynolds]]></dc:creator>
		<pubDate>Mon, 05 May 2025 09:05:05 +0000</pubDate>
				<category><![CDATA[Products]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://www.cpanel.net/?p=68405</guid>

					<description><![CDATA[<p>Server management has traditionally been a reactive process, with it often only possible to respond to issues once they have arisen. Even tools labelled as proactive, such as synthetic monitoring, only identify problems that occur after following users’ predictive behavior, and can lead to a false sense of security as systems may still crash in [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/products/a-proactive-approach-to-server-management-with-cpanel-whm/">A Proactive Approach to Server Management with cPanel &amp; WHM </a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Server management has traditionally been a reactive process, with it often only possible to respond to issues once they have arisen. Even tools labelled as proactive, such as synthetic monitoring, only identify problems that occur after following users’ predictive behavior, and can lead to a false sense of security as systems may still crash in real-world scenarios. Therefore, staying ahead of potential issues is the surest way to maintain a high-performing, seamless environment.&nbsp;</p>



<p class="wp-block-paragraph">With cPanel &amp; WHM’s Server Monitoring powered by 360 Monitoring, administrators now have access to powerful tools that ensure service quality and uptime are maintained with ease. This new integration transforms server management into a continuous, automated monitoring process that identifies potential problems before they arise. Whether you’re overseeing a single server or an entire network, Server Monitoring’s advanced features can handle any site or use case.&nbsp;</p>



<h2 class="wp-block-heading">Why Monitoring Matters&nbsp;</h2>



<p class="wp-block-paragraph">How much time do you spend reacting to server issues; website load times, security breaches, or email delivery failures? Instead of always stressing to fix problems as or after they arise, Server Monitoring transforms your server management strategy from reactive to proactive.&nbsp;&nbsp;</p>



<h3 class="wp-block-heading">Smart, Automated Monitoring for Smooth Server Management </h3>



<p class="wp-block-paragraph">Smartly configured, automated monitoring can be your first line of defense in maintaining service quality standards. By actively monitoring key performance metrics and sending real-time alerts, Server Monitoring ensures that your website stays online, your email delivers properly, and your server operates at its best. This means you can avoid the stress of unexpected outages and performance issues, allowing for smoother operations and less time spent troubleshooting. </p>



<h3 class="wp-block-heading">Advanced Monitoring Features for Every Need&nbsp;</h3>



<p class="wp-block-paragraph">Whether you’re a beginner or an experienced server administrator, WHM&#8217;s Server Monitoring offers a comprehensive suite of features designed to fit every use case. From keeping track of website performance to ensuring your server is secure and compliant, the flexibility and sophistication of these tools make them a must-have for any server management routine.&nbsp;</p>



<h3 class="wp-block-heading">Key Applications for Server Monitoring:&nbsp;</h3>



<ul class="wp-block-list">
<li><strong>Website Performance Monitoring</strong> <br>Ensure your site is always accessible to visitors by tracking uptime, response times, and server resource usage. With real-time alerts, you’ll be able to address issues before they impact your users’ experience. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Email Deliverability</strong> <br>Monitor your server’s IP address against Realtime Blackhole Lists to prevent email delivery issues. This is a game-changer for maintaining high email deliverability, keeping your emails out of spam folders, and avoiding unnecessary support tickets. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Security Monitoring</strong> <br>Protect your server from security threats by using the uptime and performance monitoring features to detect unusual activity, like unexpected spikes in resource usage or downtime, that could indicate a security threat. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Resource Optimization</strong> <br>Track critical resources such as CPU, RAM, and disk I/O usage to optimize your server’s performance. This allows you to prevent overloads and ensure your server can handle peak traffic without slowing down. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Compliance Monitoring</strong> <br>Use the built-in web crawler to identify non-compliant GDPR assets, broken links, or JavaScript errors on your website, to ensure your site remains legally compliant and user-friendly. </li>
</ul>



<h2 class="wp-block-heading">Seamless Integration with WHM: A Tool for Every User&nbsp;</h2>



<p class="wp-block-paragraph">One of the standouts of Server Monitoring<strong> </strong>is its integration with WHM, offering a unified, customizable dashboard experience for both non-technical users and advanced server administrators.&nbsp;</p>



<ul class="wp-block-list">
<li>If you’re <strong>new to server management</strong>, WHM&#8217;s Server Monitoring is designed to be intuitive and user-friendly. With ready-made dashboards, you’ll be able to monitor key server metrics like CPU usage, memory, and disk space without the need for any technical expertise. The clear, concise metrics help you spot potential issues quickly, and real-time alerts ensure you can act before problems escalate. </li>
</ul>



<ul class="wp-block-list">
<li>For <strong>more experienced users</strong>, get ready to dive into sophisticated metrics such as server response times and uptime, and integrate your alerts with your most-used tools and platforms, like Slack, Discord, and PagerDuty. The smart configuration options ensure you can create the monitoring setup that works best for your workflow. </li>
</ul>



<h2 class="wp-block-heading">Maximize Uptime, Minimize Stress&nbsp;</h2>



<p class="wp-block-paragraph">With Server Monitoring, you’ll have the tools to monitor and respond to issues quickly, maximizing uptime and ensuring that your business stays online and performs at its best.&nbsp;</p>



<ul class="wp-block-list">
<li><strong>Avoid Outages</strong> <br>Keep tabs on downtime, port tracking, Time to First Byte, and performance metrics across multiple locations to ensure your website is running smoothly, no matter where your users are. You can even display a public status page to inform visitors if there&#8217;s an ongoing issue and keep them updated during troubleshooting. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Monitor Business Reputation</strong> <br>Ensure your emails don’t end up in spam by actively monitoring your server’s IP reputation. Prevent email delivery problems before they escalate into larger issues, reducing the risk of support tickets and improving customer communication. </li>
</ul>



<ul class="wp-block-list">
<li><strong>Customizable Alerts for Quicker Customer Responses</strong> <br>Receive notifications through your preferred channels, e.g. text, email, Slack, etc., if your server reaches critical thresholds. This means you can respond instantly to customer issues and prevent errors from turning into larger problems. </li>
</ul>



<h2 class="wp-block-heading">Ready to Experience Proactive Monitoring?&nbsp;</h2>



<p class="wp-block-paragraph">Excited to experience the perfect blend of simplicity and sophistication in server management? By integrating Server Monitoring<strong> </strong>into your WHM setup, you can ensure your service quality standards are always maintained, while also gaining the peace of mind that comes with proactive monitoring.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Visit the cPanel store to <a href="https://store.cpanel.net/store/server-monitoring" target="_blank" rel="noreferrer noopener">purchase your plan today.</a> For more detailed information on setting up and configuring Server Monitoring, check out the <a href="https://docs.cpanel.net/whm/plugins/server-monitoring/" target="_blank" rel="noreferrer noopener">full documentation.</a>&nbsp;&nbsp;</p>
<p>The post <a href="https://www.cpanel.net/blog/products/a-proactive-approach-to-server-management-with-cpanel-whm/">A Proactive Approach to Server Management with cPanel &amp; WHM </a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cpanel.net/blog/products/a-proactive-approach-to-server-management-with-cpanel-whm/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>From Detection to Action: Handling Fraudulent cPanel &#038; WHM Licenses</title>
		<link>https://www.cpanel.net/blog/security/from-detection-to-action-handling-fraudulent-cpanel-whm-licenses/</link>
					<comments>https://www.cpanel.net/blog/security/from-detection-to-action-handling-fraudulent-cpanel-whm-licenses/#respond</comments>
		
		<dc:creator><![CDATA[Megan Reynolds]]></dc:creator>
		<pubDate>Tue, 29 Oct 2024 14:17:06 +0000</pubDate>
				<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://www.cpanel.net/?p=67337</guid>

					<description><![CDATA[<p>Don&#8217;t let fake cPanel licenses ruin your business. Fraudsters are on the rise, targeting both Partners and end-users. In this blog, we&#8217;ll expose their tactics, provide tools to protect yourself, and guide you toward legitimate licensing solutions. It&#8217;s time to take a stand against fraud and ensure the security and integrity of your cPanel environment.  [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/security/from-detection-to-action-handling-fraudulent-cpanel-whm-licenses/">From Detection to Action: Handling Fraudulent cPanel &amp; WHM Licenses</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Don&#8217;t let fake cPanel licenses ruin your business. Fraudsters are on the rise, targeting both Partners and end-users. In this blog, we&#8217;ll expose their tactics, provide tools to protect yourself, and guide you toward legitimate licensing solutions. It&#8217;s time to take a stand against fraud and ensure the security and integrity of your cPanel environment. </p>



<h2 class="wp-block-heading">Warning Signs</h2>



<p class="wp-block-paragraph">Do you ever encounter pricing for a high cPanel license tier that seems almost too good to be true? Do you attempt to contact your license provider for cPanel troubleshooting only to get the run-around? Does your license provider or host need to frequently “replace” the installed cPanel license on your server? These are some indicators of red flags with fraudulent retailers.&nbsp;&nbsp;</p>



<p class="wp-block-paragraph">Fraudsters will also claim that they are using a “GPL” version of a cPanel license to back up their false claim of legitimacy. GPL stands for General Public License, a license type that allows users to copy, modify, and otherwise share applicable software for distribution as they see fit. To be clear, there are no GPL versions of cPanel &amp; WHM.&nbsp;</p>



<h2 class="wp-block-heading">The Risks</h2>



<p class="wp-block-paragraph">Due to how cPanel’s licensing system functions, fraudsters need to go to great lengths to “crack” the mechanisms we have in place by configuring license circumvention scripts and software. This software is installed at the root level and almost always contains additional backdoors. Independent security investigations have found known compromises related to these licenses.&nbsp;</p>



<p class="wp-block-paragraph">Because these licenses also try to evade our licensing servers, they often will not receive important updates containing vital security patches. This can leave your server and website vulnerable to third-party exploits.&nbsp;</p>



<p class="wp-block-paragraph">In the event a user of a circumvented license reaches out to cPanel support for assistance, unfortunately, we must consider the associated server as root compromised, and we will not be able to provide support. The only actions that can be considered to address a root compromised server reasonably are to perform a fresh Operating System and WHM/cPanel installation and restore account backups, or to migrate the accounts to a known clean server that has not been previously root compromised.&nbsp;</p>



<h2 class="wp-block-heading">Is My License Legitimate? </h2>



<p class="wp-block-paragraph">You want to believe you can trust a vendor, but if some of the red flags we outlined above sound all too familiar then you need to verify claims that the license you purchased from them is legitimate. Fortunately, <a href="http://verify.cpanel.net/" target="_blank" rel="noreferrer noopener">verify.cpanel.net</a> is free and easy to use at any time.</p>



<h3 class="wp-block-heading">How to verify a license</h3>



<ol class="wp-block-list">
<li>Navigate to verify.cpanel.net</li>



<li>Input your server’s IP address and click “Verify License”. If you do not know your server’s IP address, access your server via terminal and run the following command: curl -L <a href="https://cpanel.net/myip" target="_blank" rel="noreferrer noopener">https://cpanel.net/myip</a>&nbsp;</li>



<li>A legitimate cPanel license will appear like this:&nbsp;</li>
</ol>



<ul class="wp-block-list">
<li>A license purchased directly from the cPanel store, with an “Active” status:&nbsp;</li>
</ul>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="2410" height="466" src="https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-18-at-9.32.22-AM.png" alt="" class="wp-image-67357" srcset="https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-18-at-9.32.22-AM.png 2410w, https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-18-at-9.32.22-AM-300x58.png 300w, https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-18-at-9.32.22-AM-1024x198.png 1024w, https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-18-at-9.32.22-AM-768x149.png 768w, https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-18-at-9.32.22-AM-1536x297.png 1536w, https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-18-at-9.32.22-AM-2048x396.png 2048w" sizes="auto, (max-width: 2410px) 100vw, 2410px" /></figure>



<ul class="wp-block-list">
<li>A license purchased via a verified Partner (in this example, Siteocity), with an “Active” status:&nbsp;</li>
</ul>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="1252" height="545" src="https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-16-at-8.55.01-AM.png" alt="" class="wp-image-67353" srcset="https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-16-at-8.55.01-AM.png 1252w, https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-16-at-8.55.01-AM-300x131.png 300w, https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-16-at-8.55.01-AM-1024x446.png 1024w, https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-16-at-8.55.01-AM-768x334.png 768w" sizes="auto, (max-width: 1252px) 100vw, 1252px" /></figure>



<ol start="4" class="wp-block-list">
<li>A fraudulent license will appear like this:</li>
</ol>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="2410" height="402" src="https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-18-at-9.43.00-AM-1.png" alt="" class="wp-image-67361" srcset="https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-18-at-9.43.00-AM-1.png 2410w, https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-18-at-9.43.00-AM-1-300x50.png 300w, https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-18-at-9.43.00-AM-1-1024x171.png 1024w, https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-18-at-9.43.00-AM-1-768x128.png 768w, https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-18-at-9.43.00-AM-1-1536x256.png 1536w, https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-18-at-9.43.00-AM-1-2048x342.png 2048w" sizes="auto, (max-width: 2410px) 100vw, 2410px" /></figure>



<p class="wp-block-paragraph">Or, sometimes using an inappropriate license type such as:</p>



<figure class="wp-block-image"><img loading="lazy" decoding="async" width="1276" height="217" src="https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-16-at-8.52.37-AM.png" alt="" class="wp-image-67365" srcset="https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-16-at-8.52.37-AM.png 1276w, https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-16-at-8.52.37-AM-300x51.png 300w, https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-16-at-8.52.37-AM-1024x174.png 1024w, https://www.cpanel.net/wp-content/uploads/2024/10/Screenshot-2024-10-16-at-8.52.37-AM-768x131.png 768w" sizes="auto, (max-width: 1276px) 100vw, 1276px" /></figure>



<h3 class="wp-block-heading">A note on DNSOnly licenses</h3>



<p class="wp-block-paragraph">The <a href="https://docs.cpanel.net/knowledge-base/dnsonly/cpanel-dnsonly/" target="_blank" rel="noreferrer noopener">cPanel DNSOnly license</a> type is for the creation of dedicated nameservers and can replicate DNS zones to create a DNS cluster with other servers. <strong>This license type is not intended to serve actual website data</strong> and therefore, cannot be used to create cPanel accounts. Fraudulent license providers often circumvent our licensing system with the use of cPanel DNSOnly license types. &nbsp;</p>



<h2 class="wp-block-heading">What Do I Do Now?</h2>



<p class="wp-block-paragraph">As previously mentioned, we consider any servers the fraudulent licenses are associated with as root compromised. Firstly, you must procure a new server to prepare for a migration of your cPanel/WHM server data. If you also purchased hosting services from the same vendor of the fraudulent license, cPanel has a<a href="https://partnernoc.cpanel.net/"> directory of verified Partners</a> with a variety of hosting options to choose from.&nbsp;</p>



<p class="wp-block-paragraph">These verified Partners will also bundle cPanel &amp; WHM licenses with their hosting services. Alternatively, purchase a license directly from <a href="http://store.cpanel.net/" target="_blank" rel="noreferrer noopener">store.cpanel.net</a> if you are self-hosting.&nbsp;</p>



<p class="wp-block-paragraph">With a new server and valid license in hand, it is time to migrate your website data to your new server. If you still have access to the old server with the license intact, you can <a href="https://support.cpanel.net/hc/en-us/articles/360051341513--How-to-move-all-cPanel-accounts-from-one-server-to-another">utilize Transfer Tool to automate the migration.</a></p>



<p class="wp-block-paragraph">If you find that the circumvented license is non-functional, sites and configuration files will need to be migrated manually. We have guides available to help you in the manual transfer process, <a href="https://support.cpanel.net/hc/en-us/articles/1500010714501-How-To-Manually-Transfer-System-Configuration-Using-The-cpconftool-Script">using either cpconftool script </a>or <a href="https://support.cpanel.net/hc/en-us/articles/1500008356562-How-to-manually-transfer-all-accounts-using-pkgacct-and-restorepkg">using pkgacct and restorepkg</a>.</p>



<h2 class="wp-block-heading"><strong>A Helping Hand</strong>&nbsp;</h2>



<p class="wp-block-paragraph">If you have any questions about cPanel licensing, feel free to reach out to one of our verified Partners through our PartnerNoc directory, <a href="http://partnernoc.cpanel.net/" target="_blank" rel="noreferrer noopener">partnernoc.cpanel.net</a>. Alternatively, <a href="https://support.cpanel.net/hc/en-us/articles/4406219711511-How-To-Contact-cPanel-Customer-Service">contact cPanel Customer Service directly.</a></p>



<p class="wp-block-paragraph">By staying informed, using the tools provided, and working together, we can protect our businesses and ensure a secure cPanel ecosystem for all.&nbsp;</p>
<p>The post <a href="https://www.cpanel.net/blog/security/from-detection-to-action-handling-fraudulent-cpanel-whm-licenses/">From Detection to Action: Handling Fraudulent cPanel &amp; WHM Licenses</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cpanel.net/blog/security/from-detection-to-action-handling-fraudulent-cpanel-whm-licenses/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Introducing Experimental ARC Support</title>
		<link>https://www.cpanel.net/blog/products/introducing-experimental-arc-support/</link>
					<comments>https://www.cpanel.net/blog/products/introducing-experimental-arc-support/#respond</comments>
		
		<dc:creator><![CDATA[Megan Reynolds]]></dc:creator>
		<pubDate>Tue, 17 Sep 2024 10:39:49 +0000</pubDate>
				<category><![CDATA[Products]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://www.cpanel.net/?p=66953</guid>

					<description><![CDATA[<p>cPanel is introducing new experimental support for ARC (Authenticated Received Chain) for forwarded messages and mailing lists, to comply with Google’s recent email authentication requirements. This update is crucial for ensuring uninterrupted email communication for our customers using mailing lists and forwarded emails.&#160; ARC is an authentication method designed to verify the legitimacy of forwarded [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/products/introducing-experimental-arc-support/">Introducing Experimental ARC Support</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">cPanel is introducing new experimental support for ARC (Authenticated Received Chain) for forwarded messages and mailing lists, to comply with Google’s recent email authentication requirements. This update is crucial for ensuring uninterrupted email communication for our customers using mailing lists and forwarded emails.&nbsp;</p>



<p class="wp-block-paragraph">ARC is an authentication method designed to verify the legitimacy of forwarded emails and emails sent from mailing lists. Acting as a digital signature, ARC adds three message headers to an email: authentication results, a message signature, and a seal header.&nbsp;</p>



<p class="wp-block-paragraph">By implementing ARC, Google aims to enhance email security and prevent spam and phishing attacks. Emails sent to Google without ARC are at risk of being marked as spam or rejected entirely, significantly impacting deliverability and communication reliability.&nbsp;</p>



<p class="wp-block-paragraph">For more information about Google and ARC specifically, please refer to Google’s <a href="https://support.google.com/a/answer/13198639?sjid=9256278808621815437-NC" target="_blank" rel="noreferrer noopener">documentation</a>.&nbsp;</p>



<h2 class="wp-block-heading">Impact on cPanel &amp; WHM</h2>



<p class="wp-block-paragraph">To maintain seamless email functionality for our users, we integrated experimental support of ARC into cPanel v122. This update ensures that your emails reach their intended recipients without issue.&nbsp;</p>



<p class="wp-block-paragraph">Currently cPanel &amp; WHM’s experimental ARC support only applies to outbound headers.&nbsp;</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="389" src="https://www.cpanel.net/wp-content/uploads/2024/09/Screenshot-2024-08-07-at-2.46.17-PM-1024x389.png" alt="" class="wp-image-67101" srcset="https://www.cpanel.net/wp-content/uploads/2024/09/Screenshot-2024-08-07-at-2.46.17-PM-1024x389.png 1024w, https://www.cpanel.net/wp-content/uploads/2024/09/Screenshot-2024-08-07-at-2.46.17-PM-300x114.png 300w, https://www.cpanel.net/wp-content/uploads/2024/09/Screenshot-2024-08-07-at-2.46.17-PM-768x292.png 768w, https://www.cpanel.net/wp-content/uploads/2024/09/Screenshot-2024-08-07-at-2.46.17-PM-1536x584.png 1536w, https://www.cpanel.net/wp-content/uploads/2024/09/Screenshot-2024-08-07-at-2.46.17-PM.png 1581w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph"><strong>Please note:</strong> ARC is NOT ENABLED by default. Both DKIM and SPF must be enabled to use ARC. Review our documentation to make sure those DNS records are set up for your domains:</p>



<ul class="wp-block-list">
<li><a href="https://docs.cpanel.net/whm/dns-functions/enable-dkim-spf-globally/" target="_blank" rel="noreferrer noopener">Enable DKIM/SPF Globally</a>&nbsp;</li>



<li><a href="https://docs.cpanel.net/cpanel/email/email-deliverability-in-cpanel/" target="_blank" rel="noreferrer noopener">Email Deliverability in cPanel</a> (per domain DKIM/SPF management)</li>
</ul>



<p class="wp-block-paragraph">Once DKIM and SPF are enabled, you can log into WHM and navigate to Service Configuration &gt; Exim Configuration Manager &gt; Basic Editor &gt; Mail tab to enable ARC signing to outgoing mail. Here is an example of what those ARC headers look like on a message sent from a cPanel mail server:&nbsp;</p>



<figure class="wp-block-image size-large"><img loading="lazy" decoding="async" width="1024" height="880" src="https://www.cpanel.net/wp-content/uploads/2024/09/Screenshot-2024-08-08-at-1.52.13-PM-1024x880.png" alt="" class="wp-image-67105" srcset="https://www.cpanel.net/wp-content/uploads/2024/09/Screenshot-2024-08-08-at-1.52.13-PM-1024x880.png 1024w, https://www.cpanel.net/wp-content/uploads/2024/09/Screenshot-2024-08-08-at-1.52.13-PM-300x258.png 300w, https://www.cpanel.net/wp-content/uploads/2024/09/Screenshot-2024-08-08-at-1.52.13-PM-768x660.png 768w, https://www.cpanel.net/wp-content/uploads/2024/09/Screenshot-2024-08-08-at-1.52.13-PM.png 1334w" sizes="auto, (max-width: 1024px) 100vw, 1024px" /></figure>



<p class="wp-block-paragraph">cPanel is dedicated to providing a smooth transition for our users and maintaining the reliability of our email platform. We encourage our users to evaluate if ARC support is compatible with their current mailing list or email forwarding setup for uninterrupted delivery.&nbsp;</p>
<p>The post <a href="https://www.cpanel.net/blog/products/introducing-experimental-arc-support/">Introducing Experimental ARC Support</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cpanel.net/blog/products/introducing-experimental-arc-support/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Introducing WP Toolkit v6.4: Vulnerability Protection with Patchstack.</title>
		<link>https://www.cpanel.net/blog/security/introducing-wp-toolkit-v6-4-vulnerability-protection-with-patchstack/</link>
					<comments>https://www.cpanel.net/blog/security/introducing-wp-toolkit-v6-4-vulnerability-protection-with-patchstack/#respond</comments>
		
		<dc:creator><![CDATA[Louis Vanfraechem]]></dc:creator>
		<pubDate>Wed, 12 Jun 2024 13:33:17 +0000</pubDate>
				<category><![CDATA[Products]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://www.cpanel.net/?p=66433</guid>

					<description><![CDATA[<p>Get the WP Guardian Add-On For Partners Set Up via Manage2 As promised in the v6.3 announcement, WP Toolkit is back again with another major release. With v6.4 we introduce to you, Vulnerability Protection, and more! Let’s go over the changes in detail together. Vulnerability Protection: Safeguarding Your WordPress Sites Our new WP Guardian offering [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/security/introducing-wp-toolkit-v6-4-vulnerability-protection-with-patchstack/">Introducing WP Toolkit v6.4: Vulnerability Protection with Patchstack.</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<div class="wp-block-columns is-layout-flex wp-container-core-columns-is-layout-8f761849 wp-block-columns-is-layout-flex">
<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow">
<p class="cpbase-try" style="text-align:center"><a href="https://store.cpanel.net/store/extensions?utm_source=website&#038;utm_medium=blog_post&#038;utm_campaign=wpguardian_promo&#038;utm_content=cpanel_blog">Get the WP Guardian Add-On</a></p>
</div>



<div class="wp-block-column is-layout-flow wp-block-column-is-layout-flow">
<p class="cpbase-try" style="text-align:center"><a href="https://manage2.cpanel.net/addlisc?utm_source=website&#038;utm_medium=blog_post&#038;utm_campaign=wpguardian_promo&#038;utm_content=cpanel_blog">For Partners Set Up via Manage2</a></p>
</div>
</div>



<p class="wp-block-paragraph">As promised in the v6.3 announcement, WP Toolkit is back again with another major release. With v6.4 we introduce to you, Vulnerability Protection, and more! Let’s go over the changes in detail together.</p>



<h2 class="wp-block-heading"><strong>Vulnerability Protection: Safeguarding Your WordPress Sites</strong></h2>



<p class="wp-block-paragraph">Our new WP Guardian offering finally comes to WP Toolkit, bringing vulnerability protection for WordPress sites. This is a huge change for WordPress security and there’s a lot to unpack here. What is vulnerability protection? How does it work? What problems it aims to solve? Why it’s important?</p>



<h3 class="wp-block-heading"><strong>Addressing Key Challenges:</strong></h3>



<ol class="wp-block-list">
<li><strong>New Vulnerabilities:</strong> When new vulnerabilities rear their heads, WordPress domains are at their most fragile, with fixes often lagging behind. Vulnerability protection ensures site security during this critical period.<br></li>



<li><strong>Abandoned Sites:</strong> Neglected domains, left to languish or abandoned, present a menace to server and domain integrity. Vulnerability protection erects barriers against such domains metamorphosing into potential threats to the entire server.&nbsp;<br><br><br><img loading="lazy" decoding="async" width="2000" height="817" class="wp-image-66445" style="width: 2000px;" src="https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155354.png" alt="" srcset="https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155354.png 1834w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155354-300x123.png 300w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155354-1024x418.png 1024w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155354-768x314.png 768w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155354-1536x627.png 1536w" sizes="auto, (max-width: 2000px) 100vw, 2000px" /></li>
</ol>



<h3 class="wp-block-heading"><br><strong>How Does It Work:</strong></h3>



<p class="wp-block-paragraph">Protection is a service continuously working in the background, like an antivirus or a firewall. Enabling protection on a site installs a small worker plugin inside your WordPress. This plugin monitors your WordPress assets (plugins, themes, and WordPress core), constantly checking if they have any dangerous vulnerabilities. When such vulnerability is found, the plugin automatically downloads and applies special protection rules that prevent this vulnerability from being exploited on the site. After vulnerable asset is updated and vulnerability is removed by the update, protection rules are unapplied automatically.</p>



<p class="wp-block-paragraph">This approach ensures minimal performance overhead, as protection rules (also known as virtual patches) are very small and they&#8217;re applied surgically, only for those vulnerabilities which are actually present on a site. Moreover, since these protection rules work similar to firewall rules, they do not modify or change the site code itself in any way, ensuring its integrity.<br><br><img loading="lazy" decoding="async" width="2000" height="269" class="wp-image-66457" style="width: 2000px;" src="https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155442.png" alt="" srcset="https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155442.png 1273w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155442-300x40.png 300w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155442-1024x138.png 1024w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155442-768x103.png 768w" sizes="auto, (max-width: 2000px) 100vw, 2000px" /></p>



<h3 class="wp-block-heading"><br><strong>To Recap, vulnerability protection is:</strong></h3>



<ul class="wp-block-list">
<li><strong>Automated</strong>: Protection works continuously and automatically, protecting the site from current and future vulnerabilities without user involvement.</li>



<li><strong>Non-invasive</strong>: Protection rules work like a firewall, so they never modify the site code.</li>



<li><strong>Lightweight</strong>: Protection rules are applied only for specific vulnerabilities present on a given site, so they have minimal effect on site performance. (Premium feature)<br><br><img loading="lazy" decoding="async" width="400" height="290" class="wp-image-66453" style="width: 400px;" src="https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155242.png" alt="" srcset="https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155242.png 583w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155242-300x217.png 300w" sizes="auto, (max-width: 400px) 100vw, 400px" /></li>
</ul>



<h3 class="wp-block-heading"><br><strong>Does it work on all vulnerabilities?</strong></h3>



<p class="wp-block-paragraph">Vulnerability protection only neutralizes high and medium risk vulnerabilities. If you see a vulnerability that isn&#8217;t neutralized yet, it means one of the following:</p>



<ul class="wp-block-list">
<li><strong>Work in progress</strong>. Rules for high-risk vulnerabilities are usually made available within hours of vulnerability disclosure. Rules for medium risk vulnerabilities might take days to be created due to lower impact.</li>



<li><strong>Low risk</strong>. Some vulnerabilities have minimal impact on a site or lack real exploit methods. Since they do not present a real threat to websites, protection rules for them are not necessary (or, in some cases, plain impossible to verify).</li>



<li><strong>Missing in database</strong>. Vulnerability protection is powered by technology provided by our security partners from Patchstack, so it works with vulnerabilities in Patchstack database. Vulnerabilities that are present only in Wordfence database or not matched with corresponding entries from Patchstack database do not receive protection rules. We&#8217;re working on matching all possible duplicates between two databases, but it will take us some time, since there are thousands of entries to be matched.<br><img loading="lazy" decoding="async" width="500" height="328" class="wp-image-66469" style="width: 500px;" src="https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155317.png" alt="" srcset="https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155317.png 1092w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155317-300x197.png 300w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155317-1024x671.png 1024w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-155317-768x504.png 768w" sizes="auto, (max-width: 500px) 100vw, 500px" /></li>
</ul>



<h2 class="wp-block-heading"><br><strong>How do I get this feature?</strong></h2>



<p class="wp-block-paragraph">Vulnerability protection (also known as virtual patching) is a part of the WP Guardian platform. It requires purchasing a separate license called <strong>WP Guardian (cPanel Add-On).</strong></p>



<h2 class="wp-block-heading"><strong>How do I control who gets this feature?</strong></h2>



<p class="wp-block-paragraph">Packages in WHM now include a separate limit for the number of sites that can use vulnerability protection. This limit is set to zero by default to make sure resellers and customers cannot see this feature unless server administrator wants them to. In other words, only server administrators are able to see this feature and its purchase prompts out of the box. If you want to disable this feature completely (so that even server admin can&#8217;t see it), or if you&#8217;d like to configure the upsell links presented in WHM part of WP Toolkit, do the following: <br><br>* Navigate to manage2.cpanel.net and log in, <br>* Select Update Company Information and scroll down to the Sales Option section<br>* Change Purchase WP Guardian (cPanel Add-On) item to Custom Store (which will prompt you to specify your own store URL) or Do Not Sell (which will completely hide the feature).</p>



<p class="wp-block-paragraph">We hope that vulnerability protection feature will make millions of WordPress websites managed by WP Toolkit safer, contributing to the overall health of the WordPress ecosystem.</p>



<h2 class="wp-block-heading"><strong>Risk Rank and Vulnerability Filtering: Streamlining Vulnerability Management</strong></h2>



<p class="wp-block-paragraph">You might remember that WP Toolkit v6.3 has introduced the integration with Wordfence database. Now site admins around the world could see even more vulnerabilities on their websites! But do you know what&#8217;s better than seeing more vulnerabilities on your sites? Feeling the magical bliss from not seeing any pointless ones:<br><br><img loading="lazy" decoding="async" width="400" height="246" class="wp-image-66477" style="width: 400px;" src="https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-131455.png" alt="" srcset="https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-131455.png 752w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-131455-300x184.png 300w" sizes="auto, (max-width: 400px) 100vw, 400px" /><br>The image above is what site admins will see in v6.4 after installing a fresh copy of WordPress.<br><br>Wordfence database has introduced a number of vulnerabilities in WordPress core unlikely to ever be fixed by the WordPress team. These vulnerabilities are low-risk, theoretical, not-likely-to-be-exploited-ever, and so on. In other words, they were not important enough to really care about, and they weren&#8217;t getting a fix any time soon &#8212; but since they were present, site admins got vulnerability warnings on basically all WordPress sites without being able to do anything about it. This made vulnerability alerts pointless, since people were quickly getting alert fatigue. There was no way to differentiate between things you should take care of (dangerous or exploited vulnerabilities) and things you could simply ignore (like these low-risk WordPress core vulnerabilities), so people started to just ignore everything. This needed to be fixed, the sooner the better, and we did just that.</p>



<h2 class="wp-block-heading"><strong><strong>So, what did we do and how did we do it?</strong></strong></h2>



<p class="wp-block-paragraph">WP Toolkit v6.3 has also introduced the vulnerability filtering feature. It utilized a user-provided CVSS score threshold to hide vulnerabilities below the specified score. The main problem was that CVSS rating used for filtering vulnerabilities is difficult to understand for non-tech users (&#8220;<em>what number I&#8217;m supposed to use as a threshold?</em>&#8220;) and, without going into details, it&#8217;s not always accurately reflecting the actual severity of WordPress-specific vulnerabilities. We&#8217;ve set out to replace CVSS with our own internal Risk rank that&#8217;s calculated based on CVSS, EPSS, Patchstack Patch Priority and some other markers. <br><br>Our Risk rank does a much better job at reflecting the actual severity of WordPress vulnerabilities, so we&#8217;ve switched the filtering from CVSS to Risk rank. We have also enabled this filtering by default, meaning that all vulnerabilities with &#8220;<em>low</em>&#8221; risk rank will be hidden and ignored after the upgrade to WP Toolkit v6.4. This is how it looks now:<br><br><img loading="lazy" decoding="async" width="500" height="220" class="wp-image-66489" style="width: 500px;" src="https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-131608.png" alt="" srcset="https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-131608.png 1030w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-131608-300x132.png 300w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-131608-1024x451.png 1024w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-131608-768x339.png 768w" sizes="auto, (max-width: 500px) 100vw, 500px" /></p>



<p class="wp-block-paragraph">This solution gives a better out-of-the-box experience (no more warnings that your WordPress is vulnerable on a fresh install), doesn&#8217;t annoy users, retains the value of Wordfence database where it&#8217;s actually needed (there are some genuine vulnerabilities only present in the Wordfence database at the moment), and leaves the control in the hands of users. And yes, we&#8217;ve checked and confirmed that all these &#8220;annoying, low-score, won&#8217;t be fixed&#8221; WordPress core vulnerabilities reported by Wordfence will be correctly filtered out, so unless end-users explicitly disable the filtering, it should be smooth sailing with no distractions from that moment on.<br><br><img loading="lazy" decoding="async" width="600" height="285" class="wp-image-66497" style="width: 600px;" src="https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-131547.png" alt="" srcset="https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-131547.png 1467w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-131547-300x142.png 300w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-131547-1024x486.png 1024w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-131547-768x364.png 768w" sizes="auto, (max-width: 600px) 100vw, 600px" /></p>



<h2 class="wp-block-heading"><strong>Preinstallation of WordPress &amp; Sets on cPanel: Simplifying Site Provisioning</strong></h2>



<p class="wp-block-paragraph">All cPanel packages now have a package extension with WP Toolkit option for preinstalling a WordPress site when the account with this package is created. Another option allows to choose which set should be automatically installed together with WordPress. This set will be installed every time a new WordPress site is installed under the corresponding account.<br><br><img loading="lazy" decoding="async" width="400" height="283" class="wp-image-66529" style="width: 400px;" src="https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-131430.png" alt="" srcset="https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-131430.png 960w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-131430-300x212.png 300w, https://www.cpanel.net/wp-content/uploads/2024/06/image-20240605-131430-768x543.png 768w" sizes="auto, (max-width: 400px) 100vw, 400px" /><br><br>Disclaimer: This feature fully works when used via GUI, but it might have limited availability via API for now. We&#8217;re working on making it available via API as soon as possible.</p>



<h2 class="wp-block-heading"><strong>Bug fixes &amp; Improvements: Ensuring a Smooth Experience</strong></h2>



<p class="wp-block-paragraph">WP Toolkit Version 6.4 also includes numerous bug fixes and enhancements borne out of user feedback, enhancing overall product stability and performance.</p>



<h2 class="wp-block-heading"><strong>The Road Ahead</strong></h2>



<p class="wp-block-paragraph">Our next stop on the road ahead is working on improving the performance of WP Toolkit, together with several bugfixes, long-requested features, and further improvements for the upcoming updates. Stay tuned.<br></p>
<p>The post <a href="https://www.cpanel.net/blog/security/introducing-wp-toolkit-v6-4-vulnerability-protection-with-patchstack/">Introducing WP Toolkit v6.4: Vulnerability Protection with Patchstack.</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.cpanel.net/blog/security/introducing-wp-toolkit-v6-4-vulnerability-protection-with-patchstack/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>cPanel Vulnerability Report: No Actions Required by Default</title>
		<link>https://www.cpanel.net/blog/products/cpanel-vulnerability-report-no-actions-required-by-default/</link>
		
		<dc:creator><![CDATA[cPanel Community]]></dc:creator>
		<pubDate>Wed, 11 Oct 2023 16:30:05 +0000</pubDate>
				<category><![CDATA[Products]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://blog.cpanel.com/?p=63825</guid>

					<description><![CDATA[<p>Just a few days ago, Zero Day Initiative (ZDI) publicly disclosed not one, not two, but six Zero-Day vulnerabilities in the widely-used Exim mail server. These vulnerabilities have been lurking in the shadows since their discovery in June 2022, when precautionary steps were taken to release patches for Exim and libspf2. Now, the vulnerabilities are [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/products/cpanel-vulnerability-report-no-actions-required-by-default/">cPanel Vulnerability Report: No Actions Required by Default</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<p class="wp-block-paragraph">Just a few days ago, Zero Day Initiative (ZDI) publicly disclosed not one, not two, but six Zero-Day vulnerabilities in the widely-used Exim mail server. These vulnerabilities have been lurking in the shadows since their discovery in June 2022, when precautionary steps were taken to release patches for Exim and libspf2. Now, the vulnerabilities are finally unraveled. And spoiler alert, you are totally safe!</p>



<h2 class="wp-block-heading"><strong>No Action Required by Default on Your End</strong></h2>



<p class="wp-block-paragraph">At cPanel, we prioritize the security of your hosting environments. Therefore, we provide you with important information regarding the recent Zero-Day vulnerabilities that have been disclosed for Exim, the message transfer agent (MTA) used on millions of systems worldwide.</p>



<p class="wp-block-paragraph">Based on our latest risk assessment and understanding of the defect reports, <strong>no further action is required from your side</strong>. Further changes in cPanel &amp; WHM of any version are not needed.</p>



<h2 class="wp-block-heading"><strong>What is Exim?</strong></h2>



<p class="wp-block-paragraph">Exim serves as a robust message transfer agent (MTA) initially created at the University of Cambridge for Unix systems that maintain internet connectivity. This versatile MTA boasts a widespread presence across millions of systems globally and has a track record of encountering noteworthy security challenges.</p>



<h2 class="wp-block-heading"><strong>Risk Assessment: Understanding the Zero-Day Disclosures</strong></h2>



<p class="wp-block-paragraph">Here is what we currently know about the Zero-Day vulnerabilities recently disclosed through the Zero Day Initiative (ZDI):</p>



<p class="wp-block-paragraph"><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1469/" target="_blank" rel="noopener" title=""><strong>CVE-2023-42115</strong></a><strong>:</strong><br>Exim addressed issues specific to external authentication. <strong>If you are using cPanel Exim with the default settings, you are not vulnerable</strong> to this issue unless the &#8216;external&#8217; authentication driver is explicitly enabled.</p>



<p class="wp-block-paragraph"><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1468/" target="_blank" rel="noopener" title=""><strong>CVE-2023-42114</strong></a><strong> </strong>&amp;<strong> </strong><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1470/" target="_blank" rel="noopener" title=""><strong>CVE-2023-42116</strong></a><strong>:</strong><br>Exim fixed vulnerabilities related to SPA (Secure Password Authentication) and NTLM (NT LAN Manager). By default, cPanel Exim is <strong>not vulnerable to these issues unless the &#8216;SPA&#8217; authentication driver is activated.</strong></p>



<p class="wp-block-paragraph"><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1471/" target="_blank" rel="noopener" title=""><strong>CVE-2023-42117</strong></a><strong>:</strong><br>There is a known defect related to proxy protocol usage in Exim. This <strong>only poses a risk if your mail traffic is being proxied to your server</strong>, and the proxy is untrusted. We recommend verifying the trustworthiness of your proxy.</p>



<p class="wp-block-paragraph"><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1472/" target="_blank" rel="noopener" title=""><strong>CVE-2023-42118</strong></a><strong>:</strong><br>A vulnerability related to libspf2 has been patched by cPanel to protect against integer underflow. However, due to limited details in ZDI&#8217;s reports, the exact nature of the problem remains unknown.</p>



<p class="wp-block-paragraph"><a href="https://www.zerodayinitiative.com/advisories/ZDI-23-1473/" target="_blank" rel="noopener" title=""><strong>CVE-2023-42119</strong></a><strong>:</strong><br>Another unknown issue has been reported, this time related to dnsdb, cPanel Exim builds with dnsdb in version 102 and later. If you do not use smart hosts, you are not at risk. However, <strong>if you have manually added a dnsdb configuration in any version of cPanel &amp; WHM, please review your settings</strong>.</p>



<h2 class="wp-block-heading"><strong>Your Safety First</strong></h2>



<p class="wp-block-paragraph">Your security is of utmost importance to us, and we will continue to monitor this situation closely. Rest assured, our team is dedicated to keeping your hosting environments secure and up-to-date.</p>



<p class="wp-block-paragraph">If you have any questions or concerns about any potential vulnerabilities or any other security-related matters, please do not hesitate to reach out to our support team. We are here to assist you in every way.</p>
<p>The post <a href="https://www.cpanel.net/blog/products/cpanel-vulnerability-report-no-actions-required-by-default/">cPanel Vulnerability Report: No Actions Required by Default</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>The Apache Log4j exploit and how to protect your cPanel server</title>
		<link>https://www.cpanel.net/blog/products/the-apache-log4j-exploit-and-how-to-protect-your-cpanel-server/</link>
		
		<dc:creator><![CDATA[Tabby Worthington]]></dc:creator>
		<pubDate>Wed, 15 Dec 2021 01:45:08 +0000</pubDate>
				<category><![CDATA[Announcements]]></category>
		<category><![CDATA[Products]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://blog.cpanel.com/?p=62193</guid>

					<description><![CDATA[<p>On Friday, December 10, 2021, a vulnerability for Log4j was announced in&#160;CVE-2021-44228.&#160;&#160; Log4j&#160;is developed by the Apache Foundation and is widely used by both enterprise apps and cloud services.&#160;It&#160;was&#160;reported by Alibaba Cloud&#8217;s security team&#160;to Apache on November 24.&#160;They also revealed that CVE-2021-44228 impacts default configurations of multiple Apache frameworks, including Apache Struts2, Apache&#160;Solr, Apache Druid, [&#8230;]</p>
<p>The post <a href="https://www.cpanel.net/blog/products/the-apache-log4j-exploit-and-how-to-protect-your-cpanel-server/">The Apache Log4j exploit and how to protect your cPanel server</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></description>
										<content:encoded><![CDATA[
<h2 class="wp-block-heading">On Friday, December 10, 2021, a vulnerability for Log4j was announced in&nbsp;<a href="https://nvd.nist.gov/vuln/detail/CVE-2021-44228" target="_blank" rel="noreferrer noopener">CVE-2021-44228</a>.&nbsp;&nbsp;</h2>



<p class="wp-block-paragraph"><a href="https://logging.apache.org/log4j/2.x/index.html" target="_blank" rel="noreferrer noopener">Log4j</a>&nbsp;is developed by the Apache Foundation and is widely used by both enterprise apps and cloud services.&nbsp;It&nbsp;was&nbsp;<a href="https://www.cyberkendra.com/2021/12/worst-log4j-rce-zeroday-dropped-on.html" target="_blank" rel="noreferrer noopener">reported by Alibaba Cloud&#8217;s security team</a>&nbsp;to Apache on November 24.&nbsp;They also revealed that CVE-2021-44228 impacts default configurations of multiple Apache frameworks, including Apache Struts2, Apache&nbsp;Solr, Apache Druid, Apache Flink, and others.&nbsp;The United States&nbsp;Cybersecurity and Infrastructure Security Agency&nbsp;also issued a statement from CISA Director Easterly on the log4j vulnerability.&nbsp;</p>



<h3 class="wp-block-heading">How does this impact my cPanel server?&nbsp;</h3>



<p class="wp-block-paragraph">The same day the vulnerability was announced, we published an update with the mitigation for&nbsp;CVE-2021-44228 to the&nbsp;cpanel-dovecot-solr&nbsp;RPM in version 8.8.2-4+. The only service provided by the cPanel software that uses the logging utility Log4j is&nbsp;cpanel-dovecot-solr. If you do not have this installed, then your server is secure.&nbsp;This patch will automatically be applied during the nightly updates if this package is installed. On new installations of&nbsp;Dovecot_FTS&nbsp;it will include the patched RPM by default.&nbsp;You can join the discussion&nbsp;on the cPanel Forums&nbsp;<a href="https://forums.cpanel.net/threads/log4j-cve-2021-44228-does-it-affect-cpanel.696249/" target="_blank" rel="noreferrer noopener">log4j-cve-2021-44228 thread.</a> You can check if this RPM is installed by running the command below. </p>



<h4 class="wp-block-heading">On RPM based versions&nbsp;</h4>



<pre class="wp-block-preformatted">#&nbsp;rpm&nbsp;-q&nbsp;cpanel-dovecot-solr&nbsp;--changelog | grep&nbsp;CVE-2021-44228&nbsp;&nbsp;</pre>



<h4 class="wp-block-heading">On Ubuntu based versions&nbsp;</h4>



<pre class="wp-block-preformatted">#&nbsp;zgrep&nbsp;-E&nbsp;CVE-2021-44228 /usr/share/doc/cpanel-dovecot-solr/changelog.Debian.gz&nbsp;&nbsp;</pre>



<p class="wp-block-paragraph">Example if installed:&nbsp;</p>



<pre class="wp-block-preformatted">#&nbsp;rpm&nbsp;-q&nbsp;cpanel-dovecot-solr&nbsp;&nbsp;</pre>



<pre class="wp-block-preformatted">cpanel-dovecot-solr-8.8.2-4.11.1.cpanel.noarch&nbsp;</pre>



<h3 class="wp-block-heading">Additional Information&nbsp;</h3>



<p class="wp-block-paragraph">Our Technical Support team has also published a knowledge base article regarding the Log4j vulnerability titled&nbsp;<a href="https://support.cpanel.net/hc/en-us/articles/4415775520919-ApacheSolr-vulnerability-CVE-2021-44228-for-Log4j" target="_blank" rel="noreferrer noopener">ApacheSolr&nbsp;vulnerability&nbsp;CVE-2021-44228&nbsp;for&nbsp;Log4j.</a>&nbsp;If you have any additional questions or need further assistance, please open a ticket at&nbsp;<a href="https://support.cpanel.net/" target="_blank" rel="noreferrer noopener">support.cpanel.net.</a>&nbsp;&nbsp;</p>



<h3 class="wp-block-heading">Update for December 15, 2021&nbsp;</h3>



<p class="wp-block-paragraph">The Apache Logging team released an update after it was discovered&nbsp;that&nbsp;certain non-default configurations were still vulnerable&nbsp;to the log4j exploit.&nbsp;We released an updated&nbsp;patch with&nbsp;additional mitigation into our&nbsp;cpanel-dovecot-solr.&nbsp;<a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-45046" target="_blank" rel="noreferrer noopener">Learn more about CVE-2021-45046.</a>&nbsp;You can also read the&nbsp;<a href="https://logging.apache.org/log4j/2.x/security.html" target="_blank" rel="noreferrer noopener">Apache Logging site&#8217;s Security page</a>&nbsp;for more information.&nbsp;&nbsp;</p>



<h4 class="wp-block-heading">References:&nbsp;</h4>



<ul class="wp-block-list"><li><a href="https://www.bleepingcomputer.com/news/security/new-zero-day-exploit-for-log4j-java-library-is-an-enterprise-nightmare/" target="_blank" rel="noreferrer noopener">New Zero Day Exploit for log4j Java Library is an Enterprise Nightmare (Bleeping Computer)</a>&nbsp;</li><li><a href="https://solr.apache.org/security.html#apache-solr-affected-by-apache-log4j-cve-2021-44228" target="_blank" rel="noreferrer noopener">Apache Solr Affected by Apache log4j-cve-2021-44228&nbsp;</a>&nbsp;</li><li><a href="https://forums.cpanel.net/threads/log4j-cve-2021-44228-does-it-affect-cpanel.696249/" target="_blank" rel="noreferrer noopener">cPanel Community Forums logj4-cve-2021-44228 thread</a>&nbsp;&nbsp;</li><li><a href="https://www.zdnet.com/article/second-log4j-vulnerability-found-apache-log4j-2-16-0-released/" target="_blank" rel="noreferrer noopener">Second Log4j vulnerability discovered, patch already released</a>&nbsp;</li></ul>
<p>The post <a href="https://www.cpanel.net/blog/products/the-apache-log4j-exploit-and-how-to-protect-your-cpanel-server/">The Apache Log4j exploit and how to protect your cPanel server</a> appeared first on <a href="https://www.cpanel.net/">cPanel</a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
