File Permissions: A Quiet but Important Layer of Hosting Security
The aim is to connect the technology with everyday operational decisions. File and directory permissions determine which users and processes may read, modify or execute data.
Updates, news and developments from hosting, security and Internet infrastructure.
The aim is to connect the technology with everyday operational decisions. File and directory permissions determine which users and processes may read, modify or execute data.
This article is based on a real 2025 incident or official security disclosure. Cloudflare published a post-mortem after elevated error responses affected R2 and multiple dependent services on 21 March 2025.
The aim is to connect the technology with everyday operational decisions. A fast web server cannot compensate indefinitely for inefficient database work.
The aim is to connect the technology with everyday operational decisions. Credential stuffing uses username and password combinations stolen from one service against other services.
The aim is to connect the technology with everyday operational decisions. DMARC connects SPF and DKIM authentication with a domain owner's policy and reporting.
The aim is to connect the technology with everyday operational decisions. DNSSEC adds cryptographic validation to DNS responses so resolvers can verify that signed DNS data has not been altered in transit.
The aim is to connect the technology with everyday operational decisions. A PHP worker handles an individual PHP request.
This article is based on a real 2025 incident or official security disclosure. Cloudflare reported an outage affecting R2 object storage and products depending on it on 6 February 2025.
The aim is to connect the technology with everyday operational decisions. Passwords remain necessary, but a password alone is a single point of failure.
This article is based on a real 2025 incident or official security disclosure. CISA added CVE-2024-55591 to its Known Exploited Vulnerabilities catalog on 14 January 2025.
Sender spoofing exploits the trust users place in familiar domains, company names and email identities.
A new year is a useful time to review updates, backups, plugins, users and basic performance across a WordPress installation.