Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Vulnerabilities SecurityBiaS

AI-driven coding reshapes vulnerability management

CI/CD pipelines and AI-generated code are forcing a rethink of CVE tracking and CVSS scoring, industry experts argue.

AI-driven coding reshapes vulnerability management
Hoàng Vũ · Pexels

The rise of AI-assisted software development and continuous integration/continuous deployment (CI/CD) pipelines is accelerating changes in how vulnerabilities are identified, tracked, and remediated. As developers increasingly rely on AI agents to generate and refactor code, the static models underpinning vulnerability management systems like the Common Vulnerabilities and Exposures (CVE) catalog and Common Vulnerability Scoring System (CVSS) are showing their age. Industry experts argue that these systems, designed for a slower, version-based software landscape, may no longer align with the realities of cloud-native architectures and AI-driven development workflows.

Traditional vulnerability management assumes a relatively static codebase, where patches are applied to specific versions and vulnerabilities persist until manually addressed. In contrast, AI-assisted development enables rapid, large-scale code regeneration. When a vulnerability is detected, AI tools can scan the entire codebase, identify similar flaws, and rewrite sections to eliminate them—often resolving unknown vulnerabilities in the process. This approach leverages updated architectural patterns, zero-trust principles, and secure API designs embedded in the AI’s training data. The result is a dynamic environment where vulnerabilities may be eradicated before they are even cataloged, raising questions about the ongoing relevance of CVEs as live threat indicators.

The limits of static vulnerability tracking

The CVE system was built to coordinate awareness and remediation across vendors and operators, ensuring that known vulnerabilities are addressed before they can be exploited. However, in environments where code is continuously regenerated and deployed, the assumption that vulnerabilities persist until patched no longer holds. If an AI-driven pipeline automatically resolves a vulnerability and verifies its removal, the CVE entry may become redundant for active threat feeds. While historical records remain valuable for analysis, the utility of CVEs as real-time signals diminishes in highly dynamic systems.

Similarly, CVSS scores, which assign severity ratings based on static assessments of vulnerabilities, struggle to account for the operational context of modern deployments. A vulnerability’s impact can vary dramatically depending on environmental controls, such as trusted execution environments or runtime exploit detection. A static CVSS score may overstate risk for workloads running in secure enclaves or under continuous monitoring, while understating it for unprotected systems. Experts suggest that future scoring systems may need to incorporate environmental factors to remain relevant.

Persistent risks and future challenges

Despite the potential for AI to reduce vulnerabilities, risks remain. Memory safety issues, while mitigated by modern languages, are not the only concern. Insider threats, embedded malicious code, and hardware-based vulnerabilities—such as Spectre and Meltdown—require ongoing attention. AI can rapidly rewrite software to mitigate hardware flaws, but the underlying hardware limitations persist. Additionally, the shift to AI-generated code does not eliminate the need for rigorous oversight. Legacy codebases, though declining, still pose challenges, and the transition to newer languages and architectures is not uniform across the industry.

The rapid evolution of software development practices demands corresponding changes in vulnerability management. Kathleen Moriarty, founder of SecurityBiaS and former IETF Security Area Director, emphasizes the need for proactive engagement in shaping these changes. "CVEs, CVSS, and threat feeds were designed for a slower, more static world," she notes. "It is time to step back and consider the implications not only for vulnerabilities and exploits, but also for the processes we use to manage them."

For professionals

For professionals: Teams relying on traditional vulnerability feeds may find increasing noise as AI-driven remediation outpaces CVE updates. Consider supplementing static feeds with dynamic, environment-aware tools that reflect real-time code states. Review CVSS scores in the context of your deployment’s security controls, as static ratings may not accurately reflect actual risk.

What to watch

The industry is likely to see growing experimentation with alternative vulnerability tracking mechanisms tailored to CI/CD and AI-driven workflows. These may include automated verification systems that confirm remediation before deprecating CVE entries or scoring models that incorporate runtime context. As cloud-native architectures become the norm, the distinction between development, deployment, and vulnerability management will continue to blur, requiring closer collaboration between security teams and developers.

Companies mentioned

SecurityBiaS

Discussion · coming soon

Be the first to join the thread when community discussion launches.