Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Vulnerabilities Microsoft

Microsoft races to patch Defender zero-day RoguePlanet

A publicly disclosed exploit allows SYSTEM-level access on fully patched Windows devices via Microsoft Defender.

Microsoft races to patch Defender zero-day RoguePlanet
Ed Hardie · Unsplash

A zero-day vulnerability in Microsoft Defender has exposed fully patched Windows 10 and 11 systems to privilege-escalation attacks, prompting the company to accelerate a security update. The flaw, tracked as CVE-2026-50656 and nicknamed RoguePlanet, was disclosed publicly by a security researcher known as Nightmare Eclipse one week before Microsoft confirmed its existence in an advisory published Tuesday.

The researcher shared a proof-of-concept (PoC) exploit on a self-hosted Git repository, claiming the attack leverages a race condition in Microsoft Defender to spawn command prompts with SYSTEM-level privileges. Nightmare Eclipse reported a 100% success rate on some machines, though reliability varied across hardware configurations. Notably, the exploit functions regardless of whether Defender’s real-time protection is enabled, raising concerns about its potential impact on enterprise environments.

What happened

Nightmare Eclipse released the RoguePlanet PoC during the June 2026 Patch Tuesday cycle, following a pattern of public disclosures that have strained the researcher’s relationship with Microsoft. The company has previously removed Nightmare Eclipse’s exploit repositories from platforms like GitHub and GitLab, citing violations of its vulnerability disclosure policies. In response, the researcher has accused Microsoft of targeting their work and failing to address reported flaws in a timely manner.

Microsoft’s advisory confirmed awareness of the vulnerability but did not credit Nightmare Eclipse for the discovery. The company stated it is "working to provide a high-quality security update" and will share further details once the patch is available. Meanwhile, the researcher has continued to publish exploits for other Windows vulnerabilities, including flaws in BitLocker and additional Defender components, some of which were addressed in last week’s Patch Tuesday updates.

Key facts
  • CVE ID: CVE-2026-50656 (RoguePlanet)
  • Affected software: Microsoft Defender on Windows 10 and 11
  • Exploit method: Race condition enabling SYSTEM privilege escalation
  • Success rate: Varies by machine; up to 100% in some cases
  • Patch status: In development; no release date announced

Why it matters

The RoguePlanet vulnerability underscores ongoing tensions between Microsoft and independent security researchers over disclosure practices. Nightmare Eclipse’s decision to release the PoC publicly—rather than through coordinated channels—reflects broader frustrations within the research community about Microsoft’s bug bounty program and response times. The company’s history of legal threats against researchers who publish exploits has further exacerbated these disputes, drawing criticism from cybersecurity professionals.

For enterprise users, the flaw presents a tangible risk. SYSTEM-level access could allow attackers to bypass security controls, install malware, or exfiltrate data undetected. While Microsoft has not reported active exploitation in the wild, the public availability of the PoC increases the likelihood of opportunistic attacks. Organizations relying on Microsoft Defender for endpoint protection may need to implement compensatory controls, such as restricting local administrator privileges or monitoring for unusual process activity, until a patch is released.

For professionals
  • Test detection rules for race-condition exploits in Defender logs, particularly those involving unexpected command prompts with elevated privileges.
  • Review endpoint privilege policies to limit exposure if SYSTEM access is compromised.
  • Monitor Microsoft’s advisory for patch availability and prioritize deployment once released.

What to watch

The dispute between Microsoft and Nightmare Eclipse is likely to escalate if the researcher continues to disclose unpatched vulnerabilities. Observers will be watching for Microsoft’s next steps—whether it will adjust its bug bounty program, improve communication with researchers, or pursue legal action. Meanwhile, the cybersecurity community may see increased scrutiny of Defender’s architecture, particularly its handling of race conditions and privilege management.

For defenders, the incident serves as a reminder to validate security tooling against publicly disclosed exploits, even when patches are pending. Breach and attack simulation tools, such as those highlighted in recent industry reports, can help identify gaps in detection coverage before attackers exploit them.

Companies mentioned

Microsoft

Discussion · coming soon

Be the first to join the thread when community discussion launches.