A new evolution in the ClickFix social engineering campaign, which now employs a custom DNS hijacking technique to deliver malware.
This attack method tricks users into executing malicious commands that utilize DNS lookups to fetch the next stage of...
DNS the Domain Name System faces relentless threats, with no slowdown in sight as tactics evolve.
Operating primarily over connectionless UDP (and sometimes TCP), it proves vulnerable to manipulation, making it a prime vector for DDoS abuse.
Think of DNS...
A significant vulnerability has been discovered in CoreDNS that could allow attackers to disrupt services by pinning DNS cache entries, effectively creating a denial of service for updates.
The flaw, residing in the CoreDNS etcd plugin stems from a...
Cybercriminals are increasingly leveraging DNS (Domain Name System) tunneling to establish covert communication channels that bypass traditional network security measures.
This sophisticated technique exploits the fundamental trust placed in DNS traffic, which typically passes through corporate firewalls with minimal inspection...
A novel method has emerged that demonstrates how digital images can be seamlessly embedded within DNS TXT records, effectively transforming domain name infrastructure into an unconventional image storage system.
This innovative technique, dubbed "dnsimg," represents a novel approach to data...
A high-severity security vulnerability has been discovered in CoreDNS, one of the most widely used DNS servers in cloud-native environments, particularly within Kubernetes clusters.
The flaw, designated as CVE-2025-47950, allows remote attackers to exhaust server memory through DNS-over-QUIC (DoQ) stream...
A high-severity vulnerability in the BIND DNS server software was recently disclosed that allows attackers to crash DNS servers by sending just a single malicious packet.
The Internet Systems Consortium (ISC) released BIND versions 9.18.37, 9.20.9, and 9.21.8 on May...
DNS tunneling is a hacking technique that hides information by taking advantage of the DNS protocol. This attack enables threat actors to evade firewalls and security measures.
Hackers retrieve information usually encoded in DNS queries and responses. This allows them...
The communication between DNS recursive resolvers and authoritative nameservers is largely unsecured, making it susceptible to on-path and off-path attacks.
Though many security proposals have been put forward, they often face implementation challenges or lack adequate security features.
This persistent vulnerability...
Threat actors have been exploiting the attack vector known as Sitting Ducks since at least 2019 to conduct malware delivery, phishing, brand impersonation, and data exfiltration by exploiting flaws in DNS.
This widespread flaw, affecting multiple DNS providers, enables domain...