Security News

For flux sake: CISA, annexable allies warn of hot DNS threat
2025-04-03 22:54

Shape shifting technique described as menace to national security The US govt's Cybersecurity Infrastructure Agency, aka CISA, on Thursday urged organizations, internet service providers, and...

CISA warns of Fast Flux DNS evasion used by cybercrime gangs
2025-04-03 19:37

CISA, the FBI, the NSA, and international cybersecurity agencies are calling on organizations and DNS providers to mitigate the "Fast Flux" cybercrime evasion technique used by state-sponsored...

⚡ Weekly Recap: Chrome 0-Day, IngressNightmare, Solar Bugs, DNS Tactics, and More
2025-03-31 11:25

Every week, someone somewhere slips up—and threat actors slip in. A misconfigured setting, an overlooked vulnerability, or a too-convenient cloud tool becomes the perfect entry point. But what...

Phishing-as-a-service operation uses DNS-over-HTTPS for evasion
2025-03-28 16:33

A newly discovered phishing-as-a-service (PhaaS) operation that researchers call Morphing Meerkat, has been using the DNS over HTTPS (DoH) protocol to evade detection. [...]

New Morphing Meerkat Phishing Kit Mimics 114 Brands Using Victims’ DNS Email Records
2025-03-27 16:58

Cybersecurity researchers have shed light on a new phishing-as-a-service (PhaaS) platform that leverages the Domain Name System (DNS) mail exchange (MX) records to serve fake login pages that...

UK NCSC offers security guidance for domain and DNS registrars
2025-03-27 14:47

The UK National Cyber Security Centre (NCSC) has released security guidance for domain registrars and operators of Domain Name System (DNS) services. “DNS registrars have an important role to help...

Microsoft fixes Entra ID authentication issue caused by DNS change
2025-02-25 20:17

Microsoft has fixed an issue that caused Entra ID DNS authentication failures when using the company's Seamless SSO and Microsoft Entra Connect Sync. [...]

ExtensionHound: Open-source tool for Chrome extension DNS forensics
2025-01-30 05:00

Traditional monitoring tools reveal only traffic from the Chrome process, leaving security teams uncertain about which extension is responsible for a suspicious DNS query. ExtensionHound solves...

MikroTik botnet uses misconfigured SPF DNS records to spread malware
2025-01-15 20:04

A newly discovered botnet of 13,000 MikroTik devices uses a misconfiguration in domain name server records to bypass email protections and deliver malware by spoofing roughly 20,000 web domains. [...]

ZLoader Malware Returns With DNS Tunneling to Stealthily Mask C2 Comms
2024-12-11 14:07

Cybersecurity researchers have discovered a new version of the ZLoader malware that employs a Domain Name System (DNS) tunnel for command-and-control (C2) communications, indicating that the...