Security researcher Paulos Yibelo found that five large web-hosting providers—Bluehost, DreamHost, HostGator, OVH and iPage—had bugs allowing hackers to steal sensitive customer information. Yibelo’s research included embedding malicious JavaScript on a webpage that could inject a hacker’s own profile information into a victim’s account, allowing them to take over and edit account details. (TechCrunch)
Talking point: The five hosting providers represent seven million domains between them. The hacking of a web host puts clients at risk of having their passwords revealed, and can interfere with the functioning of websites. In one of the more recent high-profile cases, the email addresses, phone numbers, addresses and bank account details of 40,000 customers of web host Hetzner’s South African branch were exposed. It was the provider’s second hack within a year.