Russia takes aim at Sitting Ducks domains, bags 30,000+
ID: f38d9db4-0129-59c5-bde1-4d593dc09919
STIX ID: report--f38d9db4-0129-59c5-bde1-4d593dc09919
Feed Name: The Register (Security)
Infoblox and Eclypsium warn that a long-standing DNS misconfiguration vulnerability—nicknamed "Sitting Ducks"—is being actively exploited by Russia-affiliated criminals to hijack orphaned or weakly managed domains. The flaw, known since 2016 and resurfacing in multiple major providers and registrars, has enabled an estimated ~30,000 domain takeovers since 2019 and is being used for phishing, scams, spam, porn distribution, and as command-and-control infrastructure; the researchers urge domain owners, registrars, DNS providers, and regulators to take both immediate mitigations and pursue long-term standards changes to reduce the DNS attack surface.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
