Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025 Industry stats Updated Aug 2026 All domains worldwide 401.6M registered names +6.4% YoY Verisign · Q2 2026 .com + .net total 179.1M names in zone Verisign · Q2 2026 .com + .net 11.5M newly registered · 76.3% renewed Verisign · Q1 2026 Country-code TLDs 146.3M names +2.4% YoY Verisign · Q1 2026 New gTLDs 49.6M names · 30.9% renewed +3.7% QoQ Verisign · Q1 2026 Legacy gTLDs 20.5M names · 67.6% renewed +14.6% YoY Verisign · Q1 2026 WordPress 41.2% of all sites · 59.1% of CMS sites W3Techs · 1 Aug 2026 Shopify 5.3% of all sites · 7.6% of CMS sites W3Techs · 1 Aug 2026 Wix 4.3% of all sites · 6.1% of CMS sites W3Techs · 1 Aug 2026 Squarespace 2.5% of all sites · 3.5% of CMS sites W3Techs · 1 Aug 2026 Joomla 1.2% of all sites · 1.7% of CMS sites W3Techs · 1 Aug 2026 Webflow 0.8% of all sites · 1.2% of CMS sites W3Techs · 1 Aug 2026 Drupal 0.7% of all sites · 1.1% of CMS sites W3Techs · 1 Aug 2026 No CMS detected 30.4% of all sites W3Techs · 1 Aug 2026 Nginx on 33%–39% of sites W3Techs · Mar–Apr 2026 Apache on 24%–29% of sites W3Techs · Mar–Apr 2026 LiteSpeed gaining share among web servers W3Techs · Mar–Apr 2026 DMARC adoption 937.9K valid records +79% in 3 yrs EasyDMARC · 2026 YTD Fortune 500 95% publish DMARC · 80% enforced EasyDMARC Fortune 500 62.7% use strict reject policy EasyDMARC Inc. 5000 15.2% use strict reject policy EasyDMARC Deal CVC Capital Partners → Namecheap · CVC Capital Partners acquired a majority stake in Namecheap in September 2025, valuing the company at ~$1.5B (including debt). Namecheap reported $398M in revenue for 2024, an 18% year-on-year increase. 2025 Deal team.blue (Hg-backed) → Loopia Group · team.blue acquired Loopia Group in May 2025, expanding its customer base from 2.5M to over 3M entrepreneurs across Europe. Loopia Group operates in Sweden, Finland, Slovakia, Czechia, Hungary, and Serbia, with 320 professionals and ~650,000 customers. 2025 Deal Miss Group (Perwyn-backed) → Web4U s.r.o. · Miss Group acquired Web4U, a Prague-based web hosting and domain registration provider, in 2025. This marked Miss Group’s 14th acquisition under Perwyn ownership and its 22nd acquisition since 2018. Web4U serves 15,000+ customers and reported CZK 38M in revenue for 2021. 2025 Deal group.one → Webglobe · group.one acquired 100% of Webglobe in May 2025, a leading hosting provider in Slovakia, Czechia, and Serbia. Webglobe manages ~300,000 registered domains and registers ~10% of national domains in its core markets. 2025 Deal hosting.com → FastComet, A2 Hosting · hosting.com acquired FastComet in April 2025 and A2 Hosting in January 2025. FastComet serves 32,000 clients across 100 countries, and A2 Hosting was rebranded under the hosting.com name in April 2025, including a $2M purchase of the hosting.com domain. 2025
Security Vulnerabilities OVHcloud

OVH patches critical KVM escape bug with global reboots

French cloud provider used Sydney site as testbed for mass hypervisor updates

OVH patches critical KVM escape bug with global reboots
Scott Rodgerson · Unsplash

A critical security flaw in the Linux KVM hypervisor forced French cloud operator OVH to perform emergency maintenance across its entire fleet, rebooting physical servers to apply patches without tenant consent. The vulnerability, tracked as CVE-2026-53359 and nicknamed Januscape, allowed attackers with root access to a guest virtual machine to execute code on the host system, crash the physical server, or compromise other tenants' workloads. Given KVM's widespread use in cloud environments, the bug posed a severe risk to multi-tenant isolation, a core promise of infrastructure-as-a-service platforms.

OVH's chief information security officer, Julien Levrard, disclosed the company's response in a detailed technical post, offering rare insight into how large-scale cloud providers handle urgent security updates. The operator ruled out several mitigation strategies before settling on a full reboot of all hosts. Disabling nested virtualization—a potential workaround—was deemed impractical, as OVH lacks visibility into which tenants rely on the feature. Live patching was rejected due to stability concerns, while live migration of virtual machines to patched hosts was considered too slow for the scale of OVH's infrastructure, which spans tens of thousands of physical servers hosting approximately one million virtual machines.

Patch rollout and testing

OVH selected its Sydney data center as the initial testbed for the reboot process, citing the region's smaller size and the time zone advantage for European engineering teams. The Australian site allowed OVH to refine its approach before expanding the operation globally. The company implemented a wave-based reboot strategy designed to minimize disruption for tenants with high-availability setups. Rather than rebooting servers sequentially by rack, OVH's orchestration system calculated "co-location graphs" to ensure that virtual machines belonging to the same customer project were never taken offline simultaneously. This required hosts running instances of the same project to be rebooted in mutually exclusive waves, with each server brought back online before the next wave began.

The rollout encountered several technical challenges. Some virtual machines failed to restart after hypervisor reboots, while others experienced data corruption during forced shutdowns. OpenStack APIs in one region became overwhelmed, producing hours of HTTP 503 errors and delaying a patching wave. In Canada, API traffic spiked to ten times normal levels, straining support teams. Hardware issues also surfaced during the process, with 20 to 30 out of 6,000 hosts in Sydney failing to recover automatically due to faulty memory modules, BIOS misconfigurations, or inactive network interfaces. Some servers required CMOS battery replacements to restore functionality.

Background

Background: KVM (Kernel-based Virtual Machine) is an open-source virtualization technology built into the Linux kernel, widely used by cloud providers to create and manage virtual machines. A guest-host escape vulnerability allows malicious code running inside a virtual machine to break out of its isolated environment and interact with the underlying host system or other tenants' workloads.

Operational impact and lessons

OVH's executive committee approved the mass reboot strategy despite the inevitability of downtime for single-host customers, prioritizing the protection of the majority over individual cases. The company deliberately limited public communication about the patching plan while the infrastructure remained vulnerable, fearing that detailed disclosures could prompt attackers to test the publicly available exploit. Levrard described the operation as a "remarkable feat" given the scale, though he acknowledged the need for improvement in managing reboot impacts and providing better customer support during future incidents.

The company is conducting a post-mortem analysis to refine its emergency patching procedures, anticipating that additional kernel vulnerabilities may require similar large-scale interventions. OVH's experience highlights the operational complexities cloud providers face when addressing critical security flaws that cannot be mitigated through live updates or gradual migrations. The trade-off between transparency, customer communication, and security remains a contentious issue in the industry, particularly when rapid action is required to prevent potential exploits.

Companies mentioned

OVHcloud

Discussion · coming soon

Be the first to join the thread when community discussion launches.