Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Vulnerabilities Cloudflare

Cloudflare integrates threat intel into WAF rules in real time

Cloudflare now lets customers block traffic using its Cloudforce One threat data directly within web application firewalls.

Cloudflare integrates threat intel into WAF rules in real time
Negative Space · Pexels

Cloudflare has rolled out a new capability that embeds its Cloudforce One threat intelligence directly into Web Application Firewall (WAF) rules. This integration enables customers to block high-risk traffic in real time by leveraging structured threat indicators without manual intervention. The feature is designed to reduce the window between threat detection and mitigation, a gap that has historically allowed attackers to exploit vulnerabilities before defenses can be updated.

How the integration works

The new functionality introduces cf.intel fields within Cloudflare’s WAF rule syntax. Security teams can now reference these fields to create automated rules that target specific threat actors, industries, or attack patterns identified by Cloudflare’s threat intelligence team. For example, if Cloudforce One detects a surge in attacks against financial services, customers in that sector can deploy a WAF rule to block traffic matching those indicators without waiting for manual rule updates. The system operates in real time, meaning protections are applied as soon as the threat intelligence is generated, rather than relying on periodic updates or third-party feeds.

Background

Background: Cloudflare’s WAF is a security layer that filters and monitors HTTP traffic to web applications. It is commonly used to protect against attacks such as SQL injection, cross-site scripting (XSS), and distributed denial-of-service (DDoS) attacks. Cloudforce One is Cloudflare’s threat intelligence team, which tracks and analyzes global cyber threats, including state-sponsored actors, criminal groups, and emerging attack vectors.

Why the change matters

For enterprises, the integration addresses a long-standing challenge: the delay between threat detection and protective action. Traditional WAF deployments often rely on static rule sets or third-party threat feeds that require manual updates, leaving systems exposed during the lag. By automating this process, Cloudflare reduces the operational burden on security teams while improving response times. The feature is particularly relevant for industries frequently targeted by sophisticated actors, such as finance, healthcare, and government, where even brief exposure can lead to significant breaches.

The move also reflects a broader industry shift toward tighter integration between threat intelligence and security infrastructure. As attackers increasingly use automation and AI to scale their operations, defenders are under pressure to match that speed. Cloudflare’s approach—embedding intelligence directly into WAF rules—eliminates the need for customers to parse and apply threat data separately, streamlining workflows for security operations centers (SOCs).

Limitations and considerations

While the integration offers clear benefits, its effectiveness depends on the quality and timeliness of Cloudflare’s threat intelligence. Customers relying solely on this feature may still need to supplement it with additional threat feeds or custom rules, particularly for niche or highly targeted threats. Additionally, the real-time nature of the system could introduce false positives if threat indicators are overly broad, potentially blocking legitimate traffic. Cloudflare has not disclosed specific metrics on false-positive rates or the volume of threats covered by the new fields, leaving some questions about its practical impact unanswered.

For professionals

For professionals: Security teams should evaluate whether Cloudflare’s built-in threat intelligence aligns with their existing detection and response strategies. The feature may reduce the need for manual rule updates but should not replace comprehensive monitoring or incident response plans. Organizations with custom WAF rules or third-party threat feeds may need to test for compatibility before full deployment.

What to watch

The success of this integration will likely hinge on two factors: adoption among Cloudflare’s enterprise customers and the accuracy of its threat detection. If the feature proves reliable, it could set a new standard for how WAFs incorporate threat intelligence, pressuring competitors to offer similar capabilities. Cloudflare may also expand the functionality to include additional threat data sources or deeper integration with other security products in its portfolio, such as its Zero Trust platform or bot management tools. For now, the feature is available to all Cloudflare customers, with no additional licensing required.

Companies mentioned

Cloudflare

Discussion · coming soon

Be the first to join the thread when community discussion launches.