Industry stats Updated Jun 2026 All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026 .com + .net total 176.1M names in zone Verisign · Q1 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026 Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026 Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026 Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026 No CMS detected 30% of all sites W3Techs · 17 Jun 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025 Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025 Industry stats Updated Jun 2026 All domains worldwide 392.5M registered names +6.5% YoY Verisign · Q1 2026 .com + .net total 176.1M names in zone Verisign · Q1 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.5% of all sites · 59.3% of CMS sites W3Techs · 17 Jun 2026 Shopify 5.2% of all sites · 7.5% of CMS sites W3Techs · 17 Jun 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 17 Jun 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 17 Jun 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 17 Jun 2026 Webflow 0.9% of all sites · 1.2% of CMS sites W3Techs · 17 Jun 2026 Drupal 0.7% of all sites · 1% of CMS sites W3Techs · 17 Jun 2026 No CMS detected 30% of all sites W3Techs · 17 Jun 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue (Hg-backed) acquired Loopia Group (Nordics) in 2025. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Perwyn-backed Miss Group acquired Web4U s.r.o. (Prague-based web hosting and domain registration provider) in 2025. This is Miss Group’s 14th acquisition under Perwyn ownership. 2025 Deal group.one → Webglobe · group.one acquired Webglobe (Slovakia/Czechia/Serbia) in 2025. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com (formerly World Host Group) acquired FastComet in April 2025 and A2 Hosting in January 2025, rebranding A2 Hosting under the hosting.com name. 2025
Security Vulnerabilities OpenAI

ChatGPT workspace flaw let attackers forge AI agents

One-click link could deploy rogue AI inside corporate ChatGPT accounts

ChatGPT workspace flaw let attackers forge AI agents
Pixabay · Pexels

A security vulnerability in OpenAI's ChatGPT workspace agents allowed attackers to deploy rogue AI agents inside corporate accounts with a single click. The flaw, identified by security firm Zenity Labs, exploited the agent builder feature to create autonomous assistants that could access connected business applications under the victim's identity and permissions.

How the attack worked

The technique, dubbed "AgentForger," relied on tricking ChatGPT into processing malicious instructions embedded in what appeared to be a standard ChatGPT link. When clicked by a user with agent creation permissions, the link triggered the workspace to automatically configure, publish, and schedule an attacker-controlled AI agent. The agent could then leverage the victim's existing connections to services like Outlook, Teams, Slack, SharePoint, or Google Drive—provided the workspace allowed those actions.

Unlike traditional phishing methods that steal credentials or session tokens, this attack created a persistent insider threat. The rogue agent operated autonomously, using the victim's permissions to search corporate data, send messages, or exfiltrate documents. Zenity's proof-of-concept demonstrated how the agent could map organizational structures by scanning emails, chats, and calendars, or hunt for sensitive information like passwords and API keys in messages. Attackers could issue new tasks by sending emails with "TASK" in the subject line, turning the agent into a long-term corporate mole.

Background

Background: ChatGPT workspace agents are AI assistants designed to automate tasks across business applications like email, calendars, and collaboration tools. Organizations enable these agents to streamline workflows, but they require permissions to interact with connected services. The vulnerability exploited the trust model between the agent builder and the user's existing integrations.

Impact and response

Zenity reported the vulnerability to OpenAI via Bugcrowd on June 4. OpenAI acknowledged the issue the following day and implemented a fix four days later by removing the URL parameter that enabled the attack. The patch was deployed before the flaw was publicly disclosed, preventing exploitation in the wild.

The attack surface highlighted by AgentForger extends beyond this specific bug. As AI agents evolve from passive assistants to active participants in corporate systems, they introduce new risks. Traditional security controls, such as endpoint protection or session monitoring, may not detect malicious agents operating within trusted environments. The incident underscores the need for granular permission models and behavioral monitoring for AI-driven workflows.

For professionals

For professionals: Organizations using ChatGPT workspace agents should audit connected services and permissions, even if the immediate vulnerability has been patched. Review agent activity logs for unusual patterns, such as unexpected data access or message-sending behavior. Consider implementing approval workflows for agent actions until AI-specific security controls mature.

Broader implications

The AgentForger flaw illustrates a shift in attack vectors. Instead of breaching systems directly, attackers can now exploit the trust placed in AI agents to create insider threats. This method bypasses conventional security measures, as the malicious activity originates from within the organization's approved tools and permissions. As AI agents become more integrated into business processes, the distinction between software vulnerabilities and human-like threats will continue to blur.

Zenity's research also raises questions about the long-term security of AI-driven automation. Agents designed to act independently across multiple platforms may require new layers of oversight, such as real-time behavior analysis or AI-specific access controls. Without these measures, organizations risk exposing sensitive data to attacks that traditional security tools cannot detect.

Companies mentioned

OpenAI Bugcrowd Zenity Labs

Discussion · coming soon

Be the first to join the thread when community discussion launches.