47-Day SSL Certificate Lifetime: Critical Automation for Hosts
Public TLS certificate validity drops to 200 days in 2026, 100 in 2027 and 47 in 2029, with DCV reuse shrinking alongside. What breaks on cPanel and DirectAdmin servers, and the automation, DNS and monitoring changes to make before it does.
September 29, 2026
Replace CSF with firewalld and fail2ban: Secure Step-by-Step
A complete walkthrough for removing CSF and LFD from an AlmaLinux 9 or 10 server and rebuilding the same protection with firewalld zones and fail2ban jails for SSH, mail, FTP and panel logins, including verification and rollback.
September 29, 2026
cxs Replacement: Free Malware Scanning with LMD and ClamAV
ConfigServer eXploit Scanner died with ConfigServer; this guide sets up Linux Malware Detect with ClamAV as its engine, explains where ImunifyAV fits, and shows how to reproduce cxs upload scanning and scheduled sweeps on cPanel and plain Linux.
September 29, 2026
Migrating a cPanel server to the cPanel CSF fork and verifying auto-updates
How to move a cPanel or WHM server from the abandoned ConfigServer CSF to cPanel's maintained fork, confirm the RPM is installed, make sure updates flow through upcp, and keep your existing rules and allow lists intact.
September 29, 2026
MailBaby Compromised Account Detection: 2026 Delisting Without Problems
How MailBaby detects a compromised mailbox or script on your server, what a block on a sender address looks like in the logs and portal, and the clean-up and delisting steps that restore sending and protect the rest of the account.
September 29, 2026
Lock Down WHM: 2FA, cPHulk and API Tokens for Secure Access
A practical hardening checklist for the WHM control surface after a year of root-escalation CVEs, covering two-factor authentication, cPHulk brute-force protection, Host Access Control restrictions and API tokens with limited privileges.
September 29, 2026
LiteSpeed cPanel plugin CVE-2026-48172: the symlink-to-root flaw and how to verify you’re patched
The June 2026 LiteSpeed WHM plugin flaws CVE-2026-48172 and CVE-2026-54420 let a cPanel user plant a symlink the root-level plugin followed. How to check the version against the fixed 2.4.8 release, update, and look for exploitation.
September 29, 2026
Install Imunify360 DirectAdmin: ImunifyAV Setup
How to install Imunify360 or the free ImunifyAV scanner on a DirectAdmin server, the ModSecurity and CSF prerequisites that decide whether the WAF and firewall components work, and how to confirm the agent, plugin and scans are running.
September 29, 2026
Installing Sentinel Firewall as a drop-in CSF replacement on Ubuntu 24.04 and Debian 13
How to remove an unmaintained CSF install from an Ubuntu 24.04 or Debian 13 server and put Sentinel Firewall in its place, reusing existing csf.conf, allow and deny files, then confirming the rules and login-failure blocking work.
September 29, 2026
KernelCare Setup on cPanel and DirectAdmin: Reliable Patching
How to install KernelCare live patching on a cPanel or DirectAdmin host, register it, confirm patches are applied for named CVEs, keep it current automatically, and unload patches when a kernel package update or a suspected regression demands it.
September 29, 2026
Imunify360 Under Attack Mode 2026: WAF and L7 Rate Limit
What changed in Imunify360 across the 2026 releases, how the default-on WordPress WAF, the Layer 7 rate limiter and WebShield's Under Attack Mode behave on shared cPanel and CloudLinux servers, and how to tune each without blocking legitimate customers.
September 29, 2026
cPanel Root Escalation Incident Response: Critical First 24 Hours
A structured response plan for a cPanel server that was exposed to one of the 2026 root-escalation vulnerabilities before patching, covering containment, evidence capture, indicators of the .sorry ransomware campaign, credential rotation, session and token audits, and the decision to rebuild.
September 29, 2026