Google Starts Serious Security Talks With the CMS Community

Last week, Chicago was the coldest place on earth! This was all over the news. The temperatures dropped to -30 degrees Celsius (-22 Fahrenheit) with a  wind chill of -50. I consider myself lucky to have been there to witness this rare polar vortex. However, I was in Chicago for a different event, one that didn’t make the news but was just as exciting — the Google CMS Security Summit.

Close to thirty top security experts from Google, different CMS platforms, and hosting companies came together to discuss how to make the internet a safer place for everyone. I consider myself even luckier to have been a part of this discussion as a representative of SiteGround.

For two days, we talked with the representatives of WordPress, Drupal, Joomla!, PrestaShop, TYPO3, Squarespace, Symfony, Sucuri, Wordfence, and more. It was inspiring to see how organizations that are competitors when it comes to attracting the end user to their platforms, can actually be unified for the higher aim of making the internet safer.

Continue reading “Google Starts Serious Security Talks With the CMS Community”

Linux kernel local root exploit (CVE-2016-8655) fixed

Yesterday a Linux kernel local root exploit was found and reported. One more time our dedicated Linux kernel team acted quickly and was able to apply the official vulnerability patch in less than 24 hours. All our shared and cloud servers are now protected and again we managed to do this with no reboots and downtime. Read below to find out more about the security problem and how we patched it.

Continue reading “Linux kernel local root exploit (CVE-2016-8655) fixed”

PHP 7.1 Already Available on Our Servers


We are thrilled to announce that one more time SiteGround has made the latest PHP version (PHP 7.1) available on most of its servers just minutes after it was officially released. PHP 7.1 comes with exciting new features for developers. However, it also reintroduces incompatible changes and migrations from 7.0 to 7.1 should be performed with great caution.

In this blog post we would like to:

Continue reading “PHP 7.1 Already Available on Our Servers”

Dirty COW Linux Kernel Vulnerability Fixed

Last week a very serious vulnerability in the Linux kernel, the so called Dirty COW, was reported. Our dedicated Linux kernel team immediately addressed the issues and were able to patch it in less than 24 hours on the majority of our servers. What is more, we managed to do this without server reboot and we avoided the downtime that normally results from such kernel update activities. To learn more about the vulnerability and how we addressed it read below.

Continue reading “Dirty COW Linux Kernel Vulnerability Fixed”

Safe from httpoxy Vulnerability or How Thinking Ahead Pays Off

A dangerous easy-to-exploit vulnerability called httpoxy discovered 15 years ago, reappeared again yesterday, leaving server-side website software potentially open to attackers. This security hole impacts a large number of PHP and CGI web-apps. This means that anything that runs on PHP, Apache, Go, HHVM, Python can be vulnerable. The exploit allows man-in-the-middle attacks that could compromise web servers and potentially access sensitive data or seize control of the code. Thanks to our unique in-house developed systems and some precautions taken ahead of time by our DevOps team, SiteGround customers are unaffected by the return of the vulnerability.

Continue reading “Safe from httpoxy Vulnerability or How Thinking Ahead Pays Off”

Day Zero of PHP 7 – Give it a try!

PHP 7.0 Available on all SiteGround servers

PHP 8.4: Stay Updated! 🚀 Check out our latest blog post to explore the newest features and enhancements in PHP 8.4.

Today PHP 7 has reached its General Availability status. As you probably know it has been available on SiteGround servers for quite a while and you can refer to an earlier post of ours about its features. Now it has reached GA status which means PHP7 can be used on production sites.

Continue reading “Day Zero of PHP 7 – Give it a try!”

HTTP/2 Now Available on all shared/cloud servers at SiteGround

http2

The Internet as we all know it today wouldn’t have existed without the HTTP protocol. It is the heart and soul that pumps content to all of us. It makes it possible for us to read the latest news, order stuff online, watch videos on YouTube and get to our favourite websites on all types of devices – workstations with 27-inch displays, laptops, mobile phones, tablets and even e-readers that offer browsing capabilities. Sadly, that protocol has not been changed since 1999 when version 1.1 was released so, when HTTP/2 was released earlier this year, it was a source of major excitement. Of course, the SiteGround team has immediately started working on it and we are now happy to announce that all our shared and cloud servers support HTTP/2.
Continue reading “HTTP/2 Now Available on all shared/cloud servers at SiteGround”

Core Joomla! Vulnerability Patched in Version 3.4.5 Security Release

joomla-vulnerability

A few days ago, a critical vulnerability in the Joomla! core was found. It comes from an unsanitized input in the Joomla! core, which makes an SQL injection possible. The result of such an attack can lead to totally compromised websites – stolen login details, hijacking website access, malicious file uploads, etc. It’s a serious threat, without a doubt, and one that applies to all Joomla! 3.2 versions and above.
Continue reading “Core Joomla! Vulnerability Patched in Version 3.4.5 Security Release”

Major Change of Our Shared Hosting Infrastructure Starts This Month

rocket2
Most of our clients know that here at SiteGround we tend to upgrade our hardware quite often. We aim to ensure that all our clients’ sites run on the latest and fastest hardware on the market and when we spot a valuable new piece of hardware, we immediately start testing. This year again, we are getting ready to migrate all of our shared hosting servers to new supercharged monster servers. Unlike other times though, this time we’ll not only upgrade the hardware, but also the whole infrastructure of our shared hosting platform.
Continue reading “Major Change of Our Shared Hosting Infrastructure Starts This Month”

Killing SSL SHA-1 Certificates And Making The Web A Safer Place

sha1

Recently PayPal has sent emails to many of its users informing them that SSL upgrades will be performed on their servers and SHA-1 certificates will be upgraded to SHA-256. Some people got confused what they should do when receiving these emails, as the mail that PayPal sent and the blog post they shared, giving more details to the users contain very technical information. Hence, we would like to explain to our customers how end users will be affected from the changes that PayPal makes and what they have to do. Continue reading “Killing SSL SHA-1 Certificates And Making The Web A Safer Place”