Investigating Security Warning Notice in Browsers
Update: Google Review In Progress
We completed an extensive security investigation after Google Safe Browsing flagged portions of our client and billing area.
Our review included multiple full malware scans, code checksum verification, checks for web shells, malicious redirects, injected code, cloaking, suspicious scheduled tasks, unauthorized administrators, temporary payloads, and recently modified files.
No malware, compromise, malicious redirects, backdoors, cloaking, unauthorized access, or evidence of customer-data exposure was found.
We also verified that our public client-area login returns the same content to both normal visitors and Googlebot.
The most likely cause is a custom security/access-denied page previously used for our restricted administration area. It contained strong warning language and displayed the visitor’s IP address, which may have been misclassified by Google’s automated systems. That page has been removed, while the protected administration area remains secured.
Google also listed an Anti-Bot verification endpoint among its example URLs. This endpoint is generated by our legitimate server security system and is not malicious content.
A formal Google Search Console review has been submitted, and a separate Google Webmaster Tools security case is currently In Progress.
Hosting services remain fully operational, and we have found no evidence that customer accounts, passwords, payment information, hosted websites, or other customer data were compromised.
Customers may continue to log in and use services as usual. If you have any concerns, our support team is available to assist.
We completed an extensive security investigation after Google Safe Browsing flagged portions of our client and billing area.
Our review included multiple full malware scans, code checksum verification, checks for web shells, malicious redirects, injected code, cloaking, suspicious scheduled tasks, unauthorized administrators, temporary payloads, and recently modified files.
No malware, compromise, malicious redirects, backdoors, cloaking, unauthorized access, or evidence of customer-data exposure was found.
We also verified that our public client-area login returns the same content to both normal visitors and Googlebot.
The most likely cause is a custom security/access-denied page previously used for our restricted administration area. It contained strong warning language and displayed the visitor’s IP address, which may have been misclassified by Google’s automated systems. That page has been removed, while the protected administration area remains secured.
Google also listed an Anti-Bot verification endpoint among its example URLs. This endpoint is generated by our legitimate server security system and is not malicious content.
A formal Google Search Console review has been submitted, and a separate Google Webmaster Tools security case is currently In Progress.
Hosting services remain fully operational, and we have found no evidence that customer accounts, passwords, payment information, hosted websites, or other customer data were compromised.
Customers may continue to log in and use services as usual. If you have any concerns, our support team is available to assist.
Investigating Security Warning Notice in Browsers 7hr 1min ago
Update 5hr 4min ago
Update: Google Review In Progress
We completed an extensive security investigation after Google Safe Browsing flagged portions of our client and billing area.
Our review included multiple full malware scans, code checksum verification, checks for web shells, malicious redirects, injected code, cloaking, suspicious scheduled tasks, unauthorized administrators, temporary payloads, and recently modified files.
No malware, compromise, malicious redirects, backdoors, cloaking, unauthorized access, or evidence of customer-data exposure was found.
We also verified that our public client-area login returns the same content to both normal visitors and Googlebot.
The most likely cause is a custom security/access-denied page previously used for our restricted administration area. It contained strong warning language and displayed the visitor’s IP address, which may have been misclassified by Google’s automated systems. That page has been removed, while the protected administration area remains secured.
Google also listed an Anti-Bot verification endpoint among its example URLs. This endpoint is generated by our legitimate server security system and is not malicious content.
A formal Google Search Console review has been submitted, and a separate Google Webmaster Tools security case is currently In Progress.
Hosting services remain fully operational, and we have found no evidence that customer accounts, passwords, payment information, hosted websites, or other customer data were compromised.
Customers may continue to log in and use services as usual. If you have any concerns, our support team is available to assist.
Update: Google Review In Progress
We completed an extensive security investigation after Google Safe Browsing flagged portions of our client and billing area.
Our review included multiple full malware scans, code checksum verification, checks for web shells, malicious redirects, injected code, cloaking, suspicious scheduled tasks, unauthorized administrators, temporary payloads, and recently modified files.
No malware, compromise, malicious redirects, backdoors, cloaking, unauthorized access, or evidence of customer-data exposure was found.
We also verified that our public client-area login returns the same content to both normal visitors and Googlebot.
The most likely cause is a custom security/access-denied page previously used for our restricted administration area. It contained strong warning language and displayed the visitor’s IP address, which may have been misclassified by Google’s automated systems. That page has been removed, while the protected administration area remains secured.
Google also listed an Anti-Bot verification endpoint among its example URLs. This endpoint is generated by our legitimate server security system and is not malicious content.
A formal Google Search Console review has been submitted, and a separate Google Webmaster Tools security case is currently In Progress.
Hosting services remain fully operational, and we have found no evidence that customer accounts, passwords, payment information, hosted websites, or other customer data were compromised.
Customers may continue to log in and use services as usual. If you have any concerns, our support team is available to assist.
Investigating 7hr 1min ago
We are aware that some users are encountering a browser security warning when accessing our site/dashboard. Our security team is actively investigating the cause to resolve this immediately. Your data and account security remain unaffected. Further updates will be provided shortly.
We are aware that some users are encountering a browser security warning when accessing our site/dashboard. Our security team is actively investigating the cause to resolve this immediately. Your data and account security remain unaffected. Further updates will be provided shortly.
Service Degradation – Node 01 (atlas.fah-dc3-ds.com) on 17 Aug 2026 12:58:27 (UTC-06:00)
Resolved on 18 Aug 2026 12:30:32 (UTC-06:00)
Update:
The atlas.fah-dc3-ds.com server is back online and now issues are detected.
Update:
The atlas.fah-dc3-ds.com server is back online and now issues are detected.
Update on 17 Aug 2026 16:23:24 (UTC-06:00)
Update:
The atlas.fah-dc3-ds.com server is back online and all services have been restored. Our team is actively monitoring performance and stability to ensure everything remains operational. We will provide further updates as needed.
Update:
The atlas.fah-dc3-ds.com server is back online and all services have been restored. Our team is actively monitoring performance and stability to ensure everything remains operational. We will provide further updates as needed.
Update on 17 Aug 2026 15:34:37 (UTC-06:00)
Update:
Technical teams are actively working with the data center on-site crew to repair the issue on atlas.fah-dc3-ds.com.
For mission-critical operations requiring immediate uptime, we can restore your account to a secondary server using our latest available backups (this requires updating your domain's IP or nameservers). However, for non-critical accounts, we strongly recommend waiting for Node atlas.fah-dc3-ds.com to come back online to minimize data loss and preserve your most up-to-date data in your cPanel(s).
Please open a support ticket if you require an immediate migration.
Update:
Technical teams are actively working with the data center on-site crew to repair the issue on atlas.fah-dc3-ds.com.
For mission-critical operations requiring immediate uptime, we can restore your account to a secondary server using our latest available backups (this requires updating your domain's IP or nameservers). However, for non-critical accounts, we strongly recommend waiting for Node atlas.fah-dc3-ds.com to come back online to minimize data loss and preserve your most up-to-date data in your cPanel(s).
Please open a support ticket if you require an immediate migration.
Update on 17 Aug 2026 13:14:41 (UTC-06:00)
Update: We have identified a hypervisor-level issue impacting Atlas.fah-dc3-ds.com and its associated nameservers (ns3 and ns4). Our engineering team is working directly with the data center's physical hands-on team to resolve the underlying hardware/host issue and restore full service. Further updates will be provided as work progresses.
Update: We have identified a hypervisor-level issue impacting Atlas.fah-dc3-ds.com and its associated nameservers (ns3 and ns4). Our engineering team is working directly with the data center's physical hands-on team to resolve the underlying hardware/host issue and restore full service. Further updates will be provided as work progresses.
Investigating on 17 Aug 2026 12:58:27 (UTC-06:00)
We are currently investigating an issue affecting services on the atlas.fah-dc3-ds.com node. Our team is actively analyzing the root cause and working toward a resolution. Further updates will be posted here as new information becomes available.
We are currently investigating an issue affecting services on the atlas.fah-dc3-ds.com node. Our team is actively analyzing the root cause and working toward a resolution. Further updates will be posted here as new information becomes available.
Scheduled Maintenance – Client Area & Ordering System on 6 Aug 2026 10:55:31 (UTC-06:00)
Scheduled
We will be performing scheduled maintenance to update our client area system. During this window, you may be temporarily unable to manage your account. Please note that this maintenance will not affect your websites or servers.
Scheduled Downtime: August 6, 2026, at 11:00 PM MST (Denver)
Support: Our live chat and support ticket systems will remain fully available throughout the maintenance.
We will be performing scheduled maintenance to update our client area system. During this window, you may be temporarily unable to manage your account. Please note that this maintenance will not affect your websites or servers.
Scheduled Downtime: August 6, 2026, at 11:00 PM MST (Denver)
Support: Our live chat and support ticket systems will remain fully available throughout the maintenance.
Security Mitigation Applied: CVE-2026-64531 (OVSwrap) on 30 Jul 2026 10:45:43 (UTC-06:00)
Resolved on 6 Aug 2026 10:53:07 (UTC-06:00)
Issue resolved
Issue resolved
Monitoring on 30 Jul 2026 10:45:43 (UTC-06:00)
We have applied the recommended temporary mitigation for CVE-2026-64531, also known as OVSwrap, across all affected CloudLinux shared hosting servers and Fully Managed end customer VPS or VDS servers.
The vulnerable Open vSwitch kernel module has been unloaded and blocked from loading on:
- Atlas
- Dragon
- Prometheus
- Hyperion
Verification was completed on each server. Attempts to load the module are correctly rejected, and the module is not currently loaded.
No service interruption or reboot was required. There is currently no indication that this vulnerability was exploited within our infrastructure.
We are monitoring for the production KernelCare livepatch and the applicable patched kernel release. The temporary mitigation will remain in place until the permanent patch is installed and independently verified on each server.
We have applied the recommended temporary mitigation for CVE-2026-64531, also known as OVSwrap, across all affected CloudLinux shared hosting servers and Fully Managed end customer VPS or VDS servers.
The vulnerable Open vSwitch kernel module has been unloaded and blocked from loading on:
- Atlas
- Dragon
- Prometheus
- Hyperion
Verification was completed on each server. Attempts to load the module are correctly rejected, and the module is not currently loaded.
No service interruption or reboot was required. There is currently no indication that this vulnerability was exploited within our infrastructure.
We are monitoring for the production KernelCare livepatch and the applicable patched kernel release. The temporary mitigation will remain in place until the permanent patch is installed and independently verified on each server.
