Cyber Security News

Dangling DNS Attack Let Hackers Gain Control Over Organization’s Subdomain

Cybersecurity experts have identified a growing threat vector where attackers exploit improperly configured or abandoned DNS records to hijack organizational subdomains.

These “Dangling DNS” attacks occur when DNS records, particularly canonical name (CNAME) records, point to resources that no longer exist or have been deprovisioned, creating an opportunity for attackers to register and control these subdomains for malicious purposes.

The vulnerability typically manifests when organizations migrate services, discontinue SaaS subscriptions, or decommission cloud resources without properly updating their DNS configurations.

For instance, if a company stops using Zendesk for customer support but fails to remove the CNAME record pointing support.YourBiz.com to YourBiz.zendesk.com, attackers can register the abandoned Zendesk subdomain and gain control over it.

SentinelOne researchers identified over 1,250 instances of subdomain takeover risks related to deprovisioned cloud resources in the past year alone.

These vulnerabilities are particularly concerning when they affect assets that serve as part of software supply chains, potentially transforming a simple configuration oversight into a devastating supply chain attack.

“What makes these attacks particularly insidious is that they exploit trust relationships that have been previously established,” noted SentinelOne researchers in their April 2025 analysis.

“When users or systems continue to request resources from what they believe are legitimate organizational subdomains, they’re actually connecting to attacker-controlled infrastructure.”

A common example involves cloud storage services like AWS S3 buckets.

Renaming a Zendesk trial to the subdomain of choice (Source – SentinelOne)

When a bucket used to host content on a subdomain is deleted but its DNS record remains, it creates a perfect attack opportunity. Consider the following scenario:-

support.YourBiz.com. 3600 IN CNAME YourBiz.zendesk.com.

When the zendesk account is abandoned but the DNS record remains, visitors to support.YourBiz.com may encounter error messages indicating the resource is unavailable.

Example error message alerting users of a potential for takeover on sites mapped to YourBiz.zendesk.com (Source – SentinelOne)

However, attackers who register that same Zendesk subdomain can now control content served through the legitimate organizational domain.

The danger escalates substantially when these subdomains are used for delivering software components or updates.

In a recent investigation spanning from October 2024 to January 2025, security researchers discovered approximately 150 deleted S3 buckets that received over 8 million requests for container images, software updates, and even VPN configurations.

Had attackers controlled these resources, they could have distributed malicious code through trusted channels.

The distinctive error message from a missing AWS S3 bucket, a key indicator of subdomain takeover vulnerability.

Organizations can protect themselves by implementing regular DNS auditing, promptly removing stale DNS records, and deploying runtime security to detect unexpected behavior even when prevention fails.

Find this News Interesting! Follow us on Google NewsLinkedIn, & X to Get Instant Updates!

Also Read:

Tushar Subhra Dutta

Tushar is a senior cybersecurity and breach reporter. He specializes in covering cybersecurity news, trends, and emerging threats, data breaches, and malware attacks. With years of experience, he brings clarity and depth to complex security topics.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

59 minutes ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

11 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

12 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

12 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

12 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

13 hours ago