The Digital Omnibus moved the AI Act's high-risk obligations to December 2027, and much of the industry heard "delay." But August 2, 2026 still activates Commission fines up to 3% of turnover for GPAI providers and transparency duties for new AI systems. Where hosts sit, step by step.
Part two of the hosting price squeeze series tackles the decision that keeps founders up at night: pass rising costs on, absorb them, or find a middle path. A segment-by-segment guide to raising prices without breaking customer trust.
From September 1, everyone holding a .ru domain must verify their identity through a Russian government system or lose the name, and foreign owners are the ones most exposed. It is a blunt reminder that a country-code domain carries the politics of the country behind it.
A critical flaw in WordPress core, the first of its kind in nearly a decade, triggered a rare forced update to millions of sites. Within 72 hours it was mass exploitation, because forced updates never reach everyone. Why patched and safe are not the same thing.
A 16-year-old flaw in KVM let a customer with admin access escape their virtual server and seize the host on both Intel and AMD. OVHcloud built a fix and rebooted around a million VMs in a week to deploy it, and the campaign shows the quiet choice every host makes between your consent and your safety.
F5 patched CVE-2026-42533, a heap-overflow flaw in Nginx rated 9.2 that has sat in the code since 2011. It is unauthenticated and remote, but only triggers under a specific regex-map configuration, so not every server is exposed. With a proof-of-concept exploit due in early August, here is who actually needs to patch.
GoDaddy's new Developer Platform lets AI agents search, register, and manage domains without a browser. Unlike the first wave's "no human required" pitch, it ties every registration to a recorded consent object and scoped tokens, the domain version of the authorization pattern agentic commerce is converging on.
Green Olive Tree, a veteran-owned managed host, has acquired ZebraHost LLC for $1.1 million, closing June 22 and nearly doubling its revenue. Struck as ZebraHost's 76-year-old founder retires, it shows the founder-succession M&A quietly consolidating hosting's small end.
A zero-click stored XSS in Roundcube webmail, scored CVSS 7.2, lets a crafted plain-text email run script in a victim's session on preview. Roundcube fixed it on July 5, cPanel shipped it in 134.0.45 on July 14, and standalone installs still need patching separately.
Customers rarely churn because they found a better host; they leave because they felt lost, overwhelmed, or misled. Extendify lays out five fixable experience gaps, from confusing plans to invisible security, that decide whether a first-time customer stays or disappears.
Your renewal invoice has a balance sheet behind it. We mapped hosting's private-equity owners, their debt, and the 2028 maturity wall against our own Renewal Multiplier Index: the most leveraged operator restructured in December, the tooling layer is reportedly funding sponsor dividends, and the debt-free cohort is quietly taking the customers.
Fly.io removed free for new accounts and Netlify doubled credit costs to halve free capacity, while Render, Cloudflare, and a reversing Railway keep free as strategy. The quiet unwinding of developer free tiers decides where the next CTO generation's defaults form.
Between July 7 and 9, three serious unauthenticated flaws surfaced in file-handling code: an RCE in Blocksy Companion Pro, arbitrary file deletion in Frontend File Manager, and an SSRF in Monsta FTP. Different codebases, one root cause, and a blast radius that lands on the hosting provider.
Extendify's new Code platform lets any hosting provider sell prompt-to-app building under its own brand, deployed through WHMCS or API. It answers the customer drift toward vibe-coding tools, and it hands hosts new revenue along with the support and security risks of AI-built software.
DigitalOcean, long the cloud for developers, says its preliminary Q2 backlog will top $800 million, up more than tenfold, on multiple nine-figure AI-inference commitments. Revenue growth is re-accelerating to 29 percent, and it now sells itself as an "AI-native cloud" rather than raw GPU rental.
Hostinger has built Patchstack's vulnerability intelligence into its Node.js hosting, scanning npm dependencies by default. It targets the unmonitored supply-chain risk of apps shipped fast with AI help, and fits Patchstack's push to embed its security inside large hosts rather than as an upsell.
Europe's hosting groups have consolidated for a decade and now want science-based climate targets to match. But growth by acquisition works against it: each deal adds emissions to the total they have pledged to cut. team.blue's report documents the bind, making it the sector's test case.
WebHosting.com, a premium one-word .com long dormant under AT&T, now resolves to an Automattic-branded "coming soon" page, confirming the WordPress parent controls it. There is no announcement, price, or stated plan. The move fits Automattic's broader hosting push, but its plans are unconfirmed.
CloudFest Americas lands at Miami's Ice Palace Studios on November 11-12, 2026, the Americas edition of Europe's flagship cloud festival. Organizers expect 2,000+ attendees across keynotes, roundtables and a NamesCon co-location, with a five-theme program spanning AI, security and growth.
Pressable, an Automattic hosting lab, expanded its MCP integration in June so AI agents can run caching, backups, SSL, WP-CLI and bulk operations across a WordPress portfolio. With Rocket.net shipping a native MCP server too, the hosting control panel is becoming an interface built for agents.