Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Vulnerabilities Microsoft

Microsoft patches 421 flaws as Lazarus exploits zero-day

North Korea’s Lazarus Group weaponized a Windows driver bug before August’s Patch Tuesday.

Microsoft patches 421 flaws as Lazarus exploits zero-day
Brett Sayles · Pexels

Microsoft’s August Patch Tuesday release closed 421 vulnerabilities across its products, among them a zero-day flaw already exploited by North Korea’s Lazarus Group since early June. The bug, tracked as CVE-2026-68820, resides in the Windows Ancillary Function Driver for WinSock and allows local privilege escalation to SYSTEM level without user interaction. Check Point researchers, who reported the vulnerability, observed Lazarus attackers leveraging it in a campaign dubbed Operation Dream Job, which impersonated defense contractors and privacy-tech firms to distribute trojanized applications and a new backdoor named Troy.

What was fixed

The 421 patches cover a range of severity levels, though Microsoft flagged only two as "notable." CVE-2026-68820, the zero-day, enables code execution at SYSTEM privileges via a use-after-free race condition in the WinSock driver. The second, CVE-2026-62832, is a publicly known elevation-of-privilege flaw in Windows registry handling that Microsoft rates as "more likely" to be exploited. An attacker with local credentials could load another user’s registry hive and gain administrator access without user interaction.

Trend Micro’s Zero Day Initiative highlighted five additional vulnerabilities as particularly critical. Among them, CVE-2026-62893—a remote code execution flaw in Windows Deployment Services TFTP Server—allows unauthenticated attackers to execute code via UDP port 69. Another, CVE-2026-62911, demonstrated at ZDI’s Pwn2Own Berlin, enables Exchange Server privilege escalation through an authentication bypass, granting attackers control over user mailboxes.

Key facts
  • 421 vulnerabilities patched in August’s release
  • CVE-2026-68820: Zero-day in WinSock driver, exploited since early June
  • CVE-2026-62832: Publicly known elevation-of-privilege flaw
  • CVE-2026-62893: Critical TFTP Server RCE (UDP port 69)
  • CVE-2026-62911: Exchange Server auth bypass (Pwn2Own demo)

How Lazarus exploited the zero-day

Check Point’s threat intelligence team linked the zero-day exploitation to Operation Dream Job, a long-running Lazarus campaign targeting defense and aerospace organizations. Attackers created fake websites impersonating Lockheed Martin and Enveil, using search engine optimization to rank them as top results. Victims were lured with fake job offers, then tricked into downloading a trojanized PDF viewer called SecurityPDF. When opened, the viewer executed a malicious payload embedded in attacker-crafted PDFs, deploying the Troy backdoor and the FudModule rootkit via CVE-2026-68820.

The campaign primarily targeted defense contractors in Europe and India. Check Point noted that Lazarus expanded its tactics to include SEO poisoning and impersonation sites, increasing the credibility of phishing attempts and evading detection. The group’s use of a zero-day in a widely deployed Windows component underscores its ability to identify and weaponize vulnerabilities before patches are available.

What professionals should prioritize

Microsoft’s advisory and third-party analyses agree on three immediate actions. First, patch CVE-2026-68820 and CVE-2026-62832, as both have been exploited in the wild. Second, block UDP port 69 at the perimeter to mitigate CVE-2026-62893, though internal lateral movement remains a risk. Third, prioritize Exchange Server updates, particularly CVE-2026-62911, despite Microsoft’s "less likely" exploitability rating—ZDI confirmed working exploits during Pwn2Own.

For professionals
  • Apply August patches for WinSock, Exchange, and TFTP Server immediately
  • Audit defense-sector employees for exposure to fake job offers or malicious PDFs
  • Monitor for registry hive manipulation and SYSTEM-level process execution

Companies mentioned

Microsoft Check Point Enveil Lockheed Martin Trend Micro

Discussion · coming soon

Be the first to join the thread when community discussion launches.