Part two of the hosting price squeeze series tackles the decision that keeps founders up at night: pass rising costs on, absorb them, or find a middle path. A segment-by-segment guide to raising prices without breaking customer trust.
From September 1, everyone holding a .ru domain must verify their identity through a Russian government system or lose the name, and foreign owners are the ones most exposed. It is a blunt reminder that a country-code domain carries the politics of the country behind it.
A critical flaw in WordPress core, the first of its kind in nearly a decade, triggered a rare forced update to millions of sites. Within 72 hours it was mass exploitation, because forced updates never reach everyone. Why patched and safe are not the same thing.
A 16-year-old flaw in KVM let a customer with admin access escape their virtual server and seize the host on both Intel and AMD. OVHcloud built a fix and rebooted around a million VMs in a week to deploy it, and the campaign shows the quiet choice every host makes between your consent and your safety.
H1 2026 synthesized from forty pieces of verified reporting: renewal spreads past 5x, RAM and storage up 50–300%, domain escalators restarted into record demand, the acquisition funnel measurably broken, $850B of leases off balance sheet, and the machine customer arriving. Growth by invoice.
F5 patched CVE-2026-42533, a heap-overflow flaw in Nginx rated 9.2 that has sat in the code since 2011. It is unauthenticated and remote, but only triggers under a specific regex-map configuration, so not every server is exposed. With a proof-of-concept exploit due in early August, here is who actually needs to patch.
Hosting M&A Desk
with Konrad & Łukasz · M&A advisors
Hosting M&A Desk
Sell or acquire a hosting company with expert guidance. We connect sellers with 250+ verified buyers worldwide. Private deals, real valuations, and full support – from strategy to closing.