H1 2026 synthesized from forty pieces of verified reporting: renewal spreads past 5x, RAM and storage up 50–300%, domain escalators restarted into record demand, the acquisition funnel measurably broken, $850B of leases off balance sheet, and the machine customer arriving. Growth by invoice.
F5 patched CVE-2026-42533, a heap-overflow flaw in Nginx rated 9.2 that has sat in the code since 2011. It is unauthenticated and remote, but only triggers under a specific regex-map configuration, so not every server is exposed. With a proof-of-concept exploit due in early August, here is who actually needs to patch.
A flaw in the heart of WordPress lets a complete stranger seize a site without ever logging in, and the attacks began the day it was disclosed. Millions of sites run the vulnerable code, and the only real protection is an update most owners assume already happened.
Cloudways' MCP server now exposes 244 tools, letting an AI agent run security scans, deployments, and billing on your hosting by chat. It is part of a wave, from DigitalOcean to cPanel, and its role-based scoped tokens stand out in a category where research finds many MCP servers insecure.
Almost everything hosts depend on has gone up fast: energy, hardware, consolidation, and above all software licensing, from cPanel's post-2019 climb to Broadcom's VMware reset. Part one of a three-part series on what is really driving hosting costs up.
We tested the public AI assistants of six hosting companies against a demanding WooCommerce buyer. Asked which rival would fit better, with no list to choose from, not one named a competitor, so the real test became how well they deflected. Bluehost's assistant broke, and the most useful answers did not come from the priciest names.
Hosting M&A Desk
with Konrad & Łukasz · M&A advisors
Hosting M&A Desk
Sell or acquire a hosting company with expert guidance. We connect sellers with 250+ verified buyers worldwide. Private deals, real valuations, and full support – from strategy to closing.