Jason Nickerson — Hosting Industry InsiderTwo decades
inside the web
as it kept rewriting
itself.
I’m Jason, a hosting industry insider with experience across open-source CMS platforms, control panels, cloud infrastructure, and the events that bring the industry together. Today, I focus on building partnerships, programming industry summits, and documenting what is happening across the hosting ecosystem.

- Sep 7, 2026
Middlemen Never Miss a Settlement Meeting
When AI companies pay up for scraping data, authors are finding that their publishers and agents are first in line with their hands out for the settlement cash.
Read article: Middlemen Never Miss a Settlement Meeting→ - Sep 7, 2026
When Hosting Becomes the Cash Cow for E-commerce Dreams
cyber_Folks has a massive war chest for acquisitions, but if you're looking for hosting innovation, you might want to look toward their e-commerce plays instead.
Read article: When Hosting Becomes the Cash Cow for E-commerce Dreams→ - Sep 5, 2026
The Speed of Sound and Capital: XDOF Hits Unicorn Status
XDOF is reportedly hitting a $1.2 billion valuation just three months after exiting stealth, proving that in the robotics data space, the early bird gets the billion-dollar worm.
Read article: The Speed of Sound and Capital: XDOF Hits Unicorn Status→
The early 2000s were the good years for tinkerers. Open-source CMS platforms were the closest thing we had to a universal starter kit, and PHP-Nuke and osCommerce were how you learned to ship real projects on the open web. I went deep on Joomla for the better part of a decade, contributing code to the project, organizing its community around releases and events, and eventually crossing over into the WordPress orbit that quietly swallowed everything in its path.
From there the story is a tour of the hosting stack: cPanel and the control-panel era that defined shared hosting, the managed cloud wave at Cloudways and DigitalOcean, and the publishing side at webhosting.today. Day to day now I'm at JetBackup, working on backup and disaster recovery and helping hosts protect the infrastructure that keeps everything running. I also program the seasonal industry summits, Atlas Digital Summit and Domain Days Dubai, where the hosting community gathers to set the agenda for what comes next.
The through-line is community, the conferences, the hallway conversations, and the group chats where the industry actually decides what happens next. The technology changes; the people pointing it in the right direction stay the same.
Twenty-something years,
in reverse.
- 2026 – present
FounderAtlas Digital SummitPrivate gatherings for hosting leaders, AI infrastructure innovators, and the builders of the agentic web.
- 2026 – presentFounderConf64
The Conference Operating System for Business Development and Field Marketing Teams.
- 2026 – present
Co-FounderSuperDeployThe advanced migration engine for AI applications. Seamlessly transition your codebase to independent, production-grade infrastructure in minutes.
- 2025 – 2026Director of Business Developmentwebhosting.today
Contract · Business development and partnerships for the hosting publisher.
- 2024 – presentBusiness Development & Partnerships ManagerJetBackup
Backup and disaster recovery for the hosting ecosystem.
- 2023 – present
Chief Marketing Officer, Founding TeamDomain Days DubaiMENA’s domain and digital asset conference.
- 2021 – 2023Senior Manager, WordPress Business Unit → Lead Community Marketing Manager IICloudways / DigitalOcean
Full-time · WordPress community, field marketing, and sales enablement through the acquisition.
- 2019 – 2021Marketing ManagercPanel
Full-time · Event planner and marketing strategist for 500–3,000 attendee events and virtual series.
- 2017 – 2019FounderCMS Summit
The global CMS conference.
- 2007 – 2019CEO | FounderJoomlaxtc.com / Monev Software LLC
Premium Joomla templates and extensions. 101,000+ members.
- 2015 – 2019Board Member, Capital Team ChairJoomla! Project
Leadership, sponsorships, and partnerships for the open-source CMS.
- 2001 – 2005DeveloperPHP-Nuke · osCommerce era
First shipping code in the early open-source web.
Threat Briefing: N-able N-central Critical RCE & Control Web Panel Active Exploits
1. Infrastructure & Server Layer
N-able N-central Remote Code Execution — Active Exploitation Underway
An emergency hotfix has been issued for a maximum-severity RCE flaw in N-central remote monitoring and management (RMM) software. The vulnerability is reportedly being exploited in the wild to gain full control of infrastructure management nodes [3].
- CVE / severity: CVE-2026-XXXX (assigned by vendor as Max Severity) / 10.0
- Affected versions: N-central versions prior to the 2026.9 Hotfix
- Fixed in: N-central 2026.9 Hotfix / 2026.9.0.21+
- Action now:
- Apply emergency hotfix immediately via the N-able dashboard.
- Restrict access to the N-central management console to trusted IP ranges only.
- Review audit logs for unauthorized administrative user creation or unexpected script execution.
Control Web Panel (CWP7) Privilege Escalation — Actively Exploited
A critical privilege escalation vulnerability in Control Web Panel (formerly CentOS Web Panel) is being exploited to gain root access on hosting servers. Attackers are leveraging the flaw to bypass security controls and modify system configurations [11].
- CVE / severity: Not disclosed in sources / High-Critical
- Affected versions: CWP7 versions prior to September 2026 release
- Fixed in: Latest CWP7 security patch (v0.9.8.1187 or later recommended)
- Action now:
- Update CWP immediately using
sh /scripts/update_cwpfrom the terminal. - Audit
/var/log/cwp/for unusual logins or API calls. - Implement
NoNewPrivileges=yesin systemd units for Nginx and PHP-FPM to mitigate post-exploitation privilege escalation [12].
- Update CWP immediately using
Heap Buffer Overflow in PADR Packet Handling
A memory corruption vulnerability (CWE-122) has been identified involving mbuf cluster allocation during PADR (PPPoE Active Discovery Request) packet processing. This can lead to a heap-based buffer overflow, potentially allowing remote code execution at the network stack level [7].
- CVE / severity: CVE-2026-XXXX (cwe-122) / High
- Affected versions: Impacting specific Linux/Unix network stacks and PPPoE implementations (details emerging)
- Fixed in: Contact vendor for specific kernel/driver patches
- Action now:
- Deploy WAF/Firewall rules to drop malformed PPPoE discovery packets if PPPoE is not required.
- Monitor for system crashes related to network driver memory allocation errors.
2. WordPress & CMS Ecosystem
Systemd Hardening Requirement for WP Hosting Stack
New guidance for 2026 infrastructure emphasizes that standard hardening is insufficient for high-density WordPress environments. Vulnerabilities in PHP-FPM and Nginx are increasingly being chained with setuid binary exploits [12].
- CVE / severity: N/A (Configuration Hardening)
- Affected versions: All WordPress environments running Nginx + PHP-FPM on Linux VPS.
- Fixed in: Manual configuration adjustment.
- Action now:
- Edit
php-fpm.serviceandnginx.serviceto includeNoNewPrivileges=yes. - Restrict
ProtectSystem=fullandPrivateTmp=yesin service files to isolate CMS processes from the root filesystem [12].
- Edit
3. Emerging Threats & Intelligence
OpenSSH Packet Leakage Discovery
A new "chink" in OpenSSH encryption has been identified that potentially bares metadata or partial data from encrypted packets. While not a full decryption exploit, it allows for traffic analysis and data pattern recognition [4].
- CVE / severity: No CVE assigned in source
- Affected versions: Not disclosed in sources
- Fixed in: Pending vendor advisory
- Action now:
- Ensure SSH is updated to the latest stable release to receive side-channel mitigations.
- Use MFA for all SSH sessions to limit the impact of credential or session metadata theft.
On the
road.
Conferences, summits, and WordCamps I’ll be at in the months ahead.
- Aug 16 – 19, 2026
- Sep 28 – 29, 2026
- Domain Days DubaiRescheduled
New dates to be announced.
Oct 15 – 16, 2026 - Nov 11 – 12, 2026
- State of the WordDec 2026
- Mar 15 – 18, 2027
When the servers
go quiet.
A small digital label putting out industrial house, progressive house, and dubstep. A different kind of open protocol.
Twenty years of showing up for the projects, communities, and voices that keep the open web open.
A news portal covering the hosting and domain industry — and a running excuse to keep talking to the people who build it.