Web Hosting News & Industry Updates

Breaking news, M&A deals, pricing moves, security alerts and in-depth analysis for the web hosting industry — 643 articles across 14 categories.

M&A
Thirty Deals in Six Months: The H1 2026 Hosting Consolidation Map, and the Two Clocks Driving What Sells Next
Natalia Nowak · 28 Jul 2026 · 13 min read
#cloud-computing#domains#hosting-ma
H1 2026 produced a US$1B Polish hosting-commerce merger, a $450M registrar champion, serial buyers closing two deals apiece within a fortnight, and a $40B data-centre record, while Google's AdSense shutdown forced Sedo and Team Internet to market. The map, the multiples, and the debt walls pushed to 2028-2029.
All articles
21–40 of 643
Security
A Critical Nginx Flaw and Who Is Actually Exposed
by Natalia Nowak · 20 Jul 2026 · 3 min read
F5 patched CVE-2026-42533, a heap-overflow flaw in Nginx rated 9.2 that has sat in the code since 2011. It is unauthenticated and remote, but only triggers under a specific regex-map configuration, so not every server is exposed. With a proof-of-concept exploit due in early August, here is who actually needs to patch.
Security
An Unauthenticated Path to Code Execution in WordPress Core, Already Being Exploited
by Łukasz Nowak · 18 Jul 2026 · 8 min read
A flaw in the heart of WordPress lets a complete stranger seize a site without ever logging in, and the attacks began the day it was disclosed. Millions of sites run the vulnerable code, and the only real protection is an update most owners assume already happened.
Industry reports
Cloudways Just Handed AI Agents the Admin Panel, and the Locks Are Racing to Catch Up
by Natalia Nowak · 17 Jul 2026 · 4 min read
Cloudways' MCP server now exposes 244 tools, letting an AI agent run security scans, deployments, and billing on your hosting by chat. It is part of a wave, from DigitalOcean to cPanel, and its role-based scoped tokens stand out in a category where research finds many MCP servers insecure.
Expert's Voice
The Hosting Price Squeeze, Part 1: Why Your Costs Keep Climbing
by Michiel Grotenhuis · 17 Jul 2026 · 8 min read
Almost everything hosts depend on has gone up fast: energy, hardware, consolidation, and above all software licensing, from cPanel's post-2019 climb to Broadcom's VMware reset. Part one of a three-part series on what is really driving hosting costs up.
Software reviews
We Asked Six Hosting AI Assistants to Name a Better Rival. Not One Would.
by Natalia Nowak · 16 Jul 2026 · 10 min read
We tested the public AI assistants of six hosting companies against a demanding WooCommerce buyer. Asked which rival would fit better, with no list to choose from, not one named a competitor, so the real test became how well they deflected. Bluehost's assistant broke, and the most useful answers did not come from the priciest names.
Industry reports
GoDaddy Opens Its Domain API to AI Agents, With Guardrails Built In
by Natalia Nowak · 16 Jul 2026 · 5 min read
GoDaddy's new Developer Platform lets AI agents search, register, and manage domains without a browser. Unlike the first wave's "no human required" pitch, it ties every registration to a recorded consent object and scoped tokens, the domain version of the authorization pattern agentic commerce is converging on.
M&A
Green Olive Tree Acquires ZebraHost for $1.1 Million, Nearly Doubling in Size
by Natalia Nowak · 15 Jul 2026 · 4 min read
Green Olive Tree, a veteran-owned managed host, has acquired ZebraHost LLC for $1.1 million, closing June 22 and nearly doubling its revenue. Struck as ZebraHost's 76-year-old founder retires, it shows the founder-succession M&A quietly consolidating hosting's small end.
Security
Roundcube’s Zero-Click Webmail XSS, and How Fast It Reached cPanel
by Natalia Nowak · 15 Jul 2026 · 4 min read
A zero-click stored XSS in Roundcube webmail, scored CVSS 7.2, lets a crafted plain-text email run script in a victim's session on preview. Roundcube fixed it on July 5, cPanel shipped it in 134.0.45 on July 14, and standalone installs still need patching separately.
Partners
Top 5 Mistakes Hosting Companies Make That Drives Churn and How to Fix Them
by Xiomara González · 14 Jul 2026 · 3 min read
Customers rarely churn because they found a better host; they leave because they felt lost, overwhelmed, or misled. Extendify lays out five fixable experience gaps, from confusing plans to invisible security, that decide whether a first-time customer stays or disappears.
Security
A US Sanction, a Montenegrin Domain, and Why Every t.me Link Went Dark
by Natalia Nowak · 14 Jul 2026 · 4 min read
Telegram's t.me domain went offline worldwide, placed on serverHold by the .me registry. The likely trigger is a US OFAC sanction on a cybercrime group whose t.me address was listed, enforced through a Montenegrin ccTLD run by US firms Identity Digital and GoDaddy. One URL, a whole domain down.
M&A
The Balance Sheet Behind Your Renewal Invoice: Who Owns the Hosting Industry, and What It Owes
by Natalia Nowak · 13 Jul 2026 · 14 min read
Your renewal invoice has a balance sheet behind it. We mapped hosting's private-equity owners, their debt, and the 2028 maturity wall against our own Renewal Multiplier Index: the most leveraged operator restructured in December, the tooling layer is reportedly funding sponsor dividends, and the debt-free cohort is quietly taking the customers.
Industry reports
UK Financial Regulators Now Oversee AWS, Google, Microsoft and Oracle
by Natalia Nowak · 13 Jul 2026 · 4 min read
The UK's three financial regulators are now overseeing the cloud giants. From July 13, AWS, Google Cloud, Microsoft and Oracle are designated critical third parties, a recognition that regulated finance runs on a handful of clouds and one outage could ripple across it. It mirrors the EU's DORA.
Security
Januscape and Bad Epoll: Two Linux Flaws That Let One Customer Take Over the Whole Server
by Łukasz Nowak · 11 Jul 2026 · 9 min read
Januscape (CVE-2026-53359) lets a guest VM escape to the host and take over co-tenants; Bad Epoll (CVE-2026-46242) lets any unprivileged user reach root with a near-perfect exploit. Both are patched upstream and in AlmaLinux, and for both the only fix is a new kernel and a reboot.
Industry reports
The Free Tier Isn’t Dying Loudly. It’s Being Repriced Quietly. And the Developer Pipeline Goes With It.
by Natalia Nowak · 10 Jul 2026 · 9 min read
Fly.io removed free for new accounts and Netlify doubled credit costs to halve free capacity, while Render, Cloudflare, and a reversing Railway keep free as strategy. The quiet unwinding of developer free tiers decides where the next CTO generation's defaults form.
Security
Three Unauthenticated File Flaws in a Week, and One Root Cause: Validation by Shortcut
by Natalia Nowak · 10 Jul 2026 · 5 min read
Between July 7 and 9, three serious unauthenticated flaws surfaced in file-handling code: an RCE in Blocksy Companion Pro, arbitrary file deletion in Frontend File Manager, and an SSRF in Monsta FTP. Different codebases, one root cause, and a blast radius that lands on the hosting provider.
Software reviews
Extendify Launches Code, a White-Label Vibe-Coding Platform for Hosts
by Natalia Nowak · 9 Jul 2026 · 4 min read
Extendify's new Code platform lets any hosting provider sell prompt-to-app building under its own brand, deployed through WHMCS or API. It answers the customer drift toward vibe-coding tools, and it hands hosts new revenue along with the support and security risks of AI-built software.
Industry reports
Which Top-Level Domains Are Worth Carrying? The Abuse Data Most Registrars Never Book.
by Natalia Nowak · 9 Jul 2026 · 8 min read
A wide TLD lineup looks like pure margin, but Spamhaus data shows that in extensions like .bond and .lol nearly the whole zone is registered and discarded within months. The reputation, deliverability, and abuse-desk costs are real and unbooked, and ICANN is moving to make them explicit.
Industry reports
DigitalOcean Lands Nine-Figure AI Deals as Its Backlog Jumps Tenfold
by Natalia Nowak · 8 Jul 2026 · 3 min read
DigitalOcean, long the cloud for developers, says its preliminary Q2 backlog will top $800 million, up more than tenfold, on multiple nine-figure AI-inference commitments. Revenue growth is re-accelerating to 29 percent, and it now sells itself as an "AI-native cloud" rather than raw GPU rental.
Security
Hostinger Turns On Patchstack npm Scanning for Node.js Apps by Default
by Natalia Nowak · 8 Jul 2026 · 4 min read
Hostinger has built Patchstack's vulnerability intelligence into its Node.js hosting, scanning npm dependencies by default. It targets the unmonitored supply-chain risk of apps shipped fast with AI help, and fits Patchstack's push to embed its security inside large hosts rather than as an upsell.
Industry reports
team.blue Reports the Climate Trade-Off of Consolidation
by Natalia Nowak · 7 Jul 2026 · 4 min read
Europe's hosting groups have consolidated for a decade and now want science-based climate targets to match. But growth by acquisition works against it: each deal adds emissions to the total they have pledged to cut. team.blue's report documents the bind, making it the sector's test case.
🚀

Reach hosting professionals

Sponsor webhosting.today and get in front of hosting buyers, founders and engineers.

50k+monthly readers
643articles
Become a sponsor →
Page 2 of 33