Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Vulnerabilities Oracle

ShinyHunters Exploits Oracle PeopleSoft Zero-Day, Breaches 100+ Organizations

A critical unauthenticated remote code execution flaw in Oracle PeopleSoft PeopleTools was weaponized as a zero-day by the ShinyHunters extortion group between late May and early June 2026, with higher education institutions accounting for roughly two-thirds of confirmed victims.

ShinyHunters Exploits Oracle PeopleSoft Zero-Day, Breaches 100+ Organizations
panumas nikhomkhai · Pexels

Mandiant and Google's Threat Intelligence Group (GTIG) have linked an extortion campaign running from May 27 to June 9, 2026 to the threat actor tracked as UNC6240, publicly known as ShinyHunters. The group exploited CVE-2026-35273, a CVSS 9.8 remote code execution flaw in the Environment Management component of Oracle PeopleSoft PeopleTools, before Oracle published its security advisory on June 10 — confirming the vulnerability was used as a zero-day.

Oracle has since acknowledged that PeopleSoft Enterprise PeopleTools versions 8.61 and 8.62 are affected and has released emergency mitigations while a full patch is in preparation. The flaw requires no authentication to exploit and can yield complete remote code execution on vulnerable instances.

Key facts
  • CVE-2026-35273 carries a CVSS base score of 9.8 (critical)
  • Affected versions: PeopleSoft Enterprise PeopleTools 8.61 and 8.62
  • Activity window: May 27 – June 9, 2026; Oracle advisory issued June 10, 2026
  • More than 100 organizations notified; 68% in higher education
  • ShinyHunters claims data stolen from 300 instances across those organizations

GTIG researchers identified five sequential staging IPs (142.11.200.186–.190) running Python SimpleHTTP servers on port 8888, which inadvertently exposed attacker tooling, command histories, and prebuilt agent binaries. Those binaries were MeshCentral remote management agents compiled for Windows and disguised as Microsoft Azure services — the executables carried names like meshagent64-azure-ops.exe and were hardcoded to call back to a command-and-control domain, azurenetfiles.net, chosen to mimic legitimate Azure NetApp Files infrastructure. A Let's Encrypt certificate for that domain was provisioned automatically via the acme-client npm package within minutes of the staging server being stood up.

The exposed .bash_history files, identical across all five hosts, gave investigators a detailed timeline of attacker operations. After establishing the C2 environment, the group used MeshCentral's CLI tool to run reconnaissance commands on victim hosts — querying PeopleSoft process scheduler configurations, WebLogic XML files, and internal network mounts. Lateral movement was carried out by a custom shell script, named with a victim-specific abbreviation followed by _fanout.sh, which parsed internal hostnames, attempted SSH credential spraying using hardcoded username-password pairs, and deposited a ransom-note file (README-IF-YOU-SEE-THIS-YOUVE-BEEN-HACKED.TXT) into WebLogic and Process Scheduler directories. Exfiltrated data was compressed with zstd before the staging host connected outbound to 176.120.22.24, the server hosting the public ShinyHunters data leak site.

Data from compromised organizations appeared on that leak site on June 9, 2026 — the same day open attacker directories were publicly flagged by researcher @nahamike01 on X, prompting GTIG's detailed triage.

ShinyHunters confirmed to BleepingComputer that they are responsible, describing the attack chain as a combination of older vulnerabilities and the new zero-day. The group has previously been connected to large-scale breaches of Snowflake-hosted data and Salesforce environments, as well as a recent intrusion at Instructure Canvas that reportedly led to a ransom payment.

For professionals

For professionals: PeopleSoft administrators should immediately block external access to /PSEMHUB/hub and /PSIGW/HttpListeningConnector at the network perimeter — WAF body-inspection rules alone are insufficient. Audit WebLogic application directories for unexpected .jsp files, check PSEMHUB.war transaction folders for unauthorized binaries, and monitor outbound SMB traffic (TCP 445) from PeopleSoft hosts, as the exploit chain may attempt NetNTLM hash capture via forced outbound connections.

Google SecOps customers will receive detection rules covering PeopleSoft configuration inspection, suspicious JSP writes to PSEMHUB, sshpass-based file deployment, zstd compression activity, and MeshCentral command execution via meshctrl.

Oracle has not publicly confirmed active exploitation in its advisory, but both Mandiant's telemetry and ShinyHunters' own statements corroborate ongoing attacks. Organizations on versions 8.61 or 8.62 should treat mitigation as urgent pending the forthcoming patch.

Companies mentioned

Oracle Google Cloud

Discussion · coming soon

Be the first to join the thread when community discussion launches.