Weekly Pulse · 2026-05-09 → 2026-05-16

Internet TLS / HNDL Pulse

Aggregate state of public TLS posture across the 427 domains Cipherwake observed this week. No specific domains called out — pure aggregate signal. Drawn from cert_observations, posture_snapshots, subdomain_observations, script_observations, and caa_observations.

Domains observed
427
Cert observations this week
447
live-served SPKI events recorded
New subdomains observed
261
first-time appearance in CT or live scans
New 3rd-party script hosts
0
first-time supply-chain dependencies detected
CAA changes
138
cert-issuance authorization shifts
SPKI cross-domain reuse
13
distinct public keys observed serving more than one registrable domain

TLS posture this week

PostureDomains%
Ephemeral-only (no RSA-kex fallback) ✓11145.7%
Ephemeral-preferred but RSA-fallback accepted ⚠12953.1%
RSA-only (no forward secrecy) ✗20.8%

53.9% of observed domains still accept RSA key exchange — meaning a single harvested cert key would decrypt every TLS session captured under that posture, retroactively.

Hybrid PQC adoption

4.1% of observed domains advertise a hybrid post-quantum key exchange (X25519MLKEM768 or similar). The remaining 95.9% are exposed to harvest-now-decrypt-later attacks if quantum decryption arrives during the cert's lifetime.

HSTS adoption

55.1% of observed domains advertise HSTS. Domains without HSTS allow clients to be downgraded to HTTP, breaking the encryption guarantee entirely.

Want this for your portfolio?

Cipherwake Monitoring tracks attack-surface changes on your own + your vendors' domains. Alerts on cert rotations, posture regressions, third-party script drift, and SPKI reuse across vendor tenants.

See Monitoring → Scan your domain →

Methodology: Pulse is generated from Cipherwake's own observation history — every live-TLS probe and cert observation we've run in the last 7 days. Aggregate only; no individual domain identification per our methodology + Rule 3. Data accumulates daily via the observe-popular cron + organic user scans. JSON feed.