NEW! DNS Inspector is an automated testing system that reveals your infrastructure security vulnerabilities. Learn how it works →
Book a discovery call

Articles

Curated Press on Domain and DNS Compromises To help our web audience better understand DNS related security exposures and compliance gaps this curated article page is dedicated to educating business leaders, IT and infrastructure teams. The more we understand the exposures, the better we can prevent them.
Source: Spiceworks Massive Domain Hijacking Campaign Used for Ad Fraud, Malvertising, Phishing Emails

Researchers at Guardio Labs have discovered a massive email ad fraud campaign based on thousands of hijacked domains and subdomains. Threat actors are carrying out SPF-hijacking to bypass spam security by leveraging legitimate domains to send millions of emails for malvertising and click scams for at least 16 months.

Source: Bleeping Computer Over 60,000 parked domains were vulnerable to AWS hijacking

Domain registrar MarkMonitor had left more than 60,000 parked domains vulnerable to domain hijacking.

Source: Info Security Magazine DNS Attacks on the Rise, Costing $1 Million Each

According to new research, cyber-attacks using DNS channels to steal data, DDoS victims, and deploy malware have grown in volume and cost throughout the pandemic.

Source: National Cyber Security Centre Protecting parked domains for the UK public sector

Non-email sending (parked) domains can be used to generate spam email, but they’re easy to protect.

Source: The Register That Salesforce outage

Global DNS downfall started by one engineer trying a quick fix The sound of rumbling rubber could be heard today as Salesforce threw an engineer responsible for a change that knocked it offline under a passing bus.

Source: Honey Badger Subdomain Takeover: Ignore This Vulnerability at Your Peril

Management thinks that letting folks from WidgetCo log into widgetco.ourapp.com will really help make the sale. It seems harmless enough. But using a custom subdomain like this can open WidgetCo up to potential security issues.

Source: Adweek Report: 78% cyber pros expect increase in DNS threats

Neustar, a global information services and technology company, has released a report from the Neustar International Security Council (NISC) which explores the rise in DNS security threats over the Christmas period.

Source: ZDNet Four years after the Dyn DDoS attack, critical DNS dependencies have only gone up

If Cloudflare, AWS, or GoDaddy go down, around 40% of the Alexa Top 100,000 websites will also go down with DNS resolution problems.