The Internet Systems Consortium (ISC) has released critical security advisories addressing multiple vulnerabilities in the Berkeley Internet Name Domain (BIND) 9 software, a cornerstone of the Domain Name System (DNS) infrastructure.
These vulnerabilities, identified as CVE-2024-0760, CVE-2024-1737, CVE-2024-1975, and CVE-2024-4076,...
Cybersecurity researchers have unveiled a new and potent Denial of Service (DoS) attack, dubbed "DNSBomb."
This attack leverages the inherent mechanisms of the Domain Name System (DNS) to create a powerful pulsing DoS attack that poses a significant threat...
Hackers exploit DNS vulnerabilities to redirect users to malicious websites, launch distributed denial-of-service (DDoS) attacks by overwhelming DNS servers, and manipulate domain resolutions to intercept traffic for surveillance or data theft purposes.
Infoblox researchers recently revealed "Muddling Meerkat," a highly...
A new keylogging server and client tool have been released on GitHub for pentesters. The tool utilizes DNS tunneling to transmit keystrokes through firewalls, potentially evading detection covertly.
The tool, DNS-Tunnel-Keylogger, was designed for post-exploitation activities for pentesters and...
DNS flaws are very common on web applications where the DNS resolvers are vulnerable to Kaminsky attacks.
If threat actors are able to predict portions of a DNS query and the source ports, they can exploit these vulnerabilities and...
The Internet Systems Consortium (ISC) released security advisories on January 25, 2023, to address flaws in the DNS software suite BIND. A denial of service could occur if these vulnerabilities are exploited.
The flaws that were resolved have the potential...
Roaming Mantis is a cyberattack campaign that has been active for an extended period of time. The attackers behind this campaign use malicious APK files, which are the files used to install apps on Android devices, to gain control...
Recently a very new set of vulnerabilities has been detected by cybersecurity researchers, and according to their report, this vulnerability is continuously affecting the major DNS-as-a-Service (DNSaaS) providers.
This vulnerability is quite critical and it might enable the threat actors...
Researchers identified a DNS vulnerability called “TsuNAME”. This vulnerability affects DNS resolvers and can be exploited to attack authoritative servers.
The authoritative DNS servers translate web domains to IP addresses and pass this information to recursive DNS servers that get...
JSOF team together with Forescout Research Labs, have revealed a set of nine vulnerabilities related to Domain Name System (DNS) implementations, causing either Denial of Service (DoS) or Remote Code Execution (RCE).
This vulnerability set, known as NAME: WRECK, could...