Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Vulnerabilities Ivanti

CISA mandates Ivanti Sentry patch for federal agencies by 15 June

U.S. cybersecurity agency sets three-day deadline after active exploitation of critical Ivanti Sentry flaw.

CISA mandates Ivanti Sentry patch for federal agencies by 15 June
panumas nikhomkhai · Pexels

A critical vulnerability in Ivanti Sentry, a security gateway appliance used by enterprises to manage mobile devices, has triggered an emergency patching directive from the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The flaw, tracked as CVE-2026-10520, allows remote attackers to execute arbitrary commands on unpatched systems by exploiting an OS command injection weakness in the appliance’s management interface. Ivanti released patches on 10 June 2026, but evidence of active exploitation emerged within days, prompting CISA to enforce a three-day remediation window for federal agencies under Binding Operational Directive (BOD) 26-04.

What triggered the directive

CISA added CVE-2026-10520 to its Known Exploited Vulnerabilities (KEV) catalog on 12 June 2026 after security researchers at Shadowserver reported observing exploitation attempts against internet-exposed Ivanti Sentry instances. The vulnerability carries a CVSS score of 10, indicating maximum severity. However, Ivanti has emphasized that successful exploitation requires access to the appliance’s management port (8443), which should not be exposed to the public internet under recommended security practices. The company told BleepingComputer that CISA’s inclusion of the flaw in the KEV catalog was based on attacks against honeypots—deliberately vulnerable systems used to study attacker behavior—rather than confirmed breaches of production environments.

Despite Ivanti’s reassurances, Shadowserver’s data suggests that many organizations have not followed secure deployment guidelines. The security firm identified over 50 exposed Ivanti Sentry admin portals online, though it acknowledged that its scans may not detect all instances due to network-level blocking. Shadowserver warned that systems remaining unpatched by 12 June were "most likely compromised," given the rapid adoption of publicly available proof-of-concept exploits.

Why the deadline is aggressive

CISA’s directive reflects the agency’s updated approach to vulnerability management under BOD 26-04, which took effect on 11 June 2026. The new directive supersedes older policies and prioritizes patching for vulnerabilities that meet specific criteria: active exploitation, potential for automated large-scale attacks, or the ability to grant attackers control over a system. CVE-2026-10520 meets all three conditions, as attackers have already demonstrated the ability to backdoor vulnerable appliances.

Federal agencies are required to either patch the vulnerability by 15 June 2026, apply mitigations for cloud-based deployments, or discontinue use of the product if remediation is not feasible. The directive applies to all Federal Civilian Executive Branch (FCEB) agencies, though CISA encourages private-sector organizations to adopt the same timeline. This is the first vulnerability addressed under BOD 26-04, but CISA has issued similar three-day deadlines for other actively exploited flaws in recent weeks, including a Check Point VPN zero-day and a cPanel plugin vulnerability.

What organizations should do

Ivanti has urged customers to apply the available patches immediately and review their network configurations to ensure that management ports are not exposed to the internet. The company also recommended restricting access to trusted IP addresses as an additional safeguard. For organizations unable to patch immediately, Ivanti provided temporary mitigation steps, including disabling the affected management interface until updates can be deployed.

Security researchers have noted that Ivanti products have been frequent targets for attackers, including ransomware groups. Over the past three years, CISA has flagged 35 vulnerabilities in Ivanti software that were exploited in real-world attacks, with 12 of those targeted by ransomware operators. The repeated exploitation of Ivanti flaws underscores the importance of proactive vulnerability management, particularly for appliances that serve as gateways to enterprise networks.

For professionals

For professionals: Organizations using Ivanti Sentry should prioritize patching CVE-2026-10520 within the next 24 hours, even if the appliance is not directly exposed to the internet. Internal network segmentation and access controls should be reviewed to limit lateral movement in the event of a compromise. Security teams should also monitor for indicators of compromise, as exploitation attempts may escalate following CISA’s directive.

Companies mentioned

Ivanti CISA Shadowserver

Discussion · coming soon

Be the first to join the thread when community discussion launches.