logo

DNSSEC Denial-of-Service Attacks Show Technology's Fragility

ID: 6a7b4f57-93e2-5550-bbd8-e4b42938676e

STIX ID: report--6a7b4f57-93e2-5550-bbd8-e4b42938676e

Feed Name: Dark Reading

Threat Score
65/100

Date Published: 2024-12-24

Date Updated: 2026-04-21

Author: Robert Lemos, Contributing Writer

...
...

Researchers disclosed two classes of DNS/DNSSEC weaknesses in 2024 — KeyTrap, which forces resolvers to perform excessive cryptographic validations causing resource exhaustion, and TuDoor, which exposes logic vulnerabilities enabling cache poisoning, DoS, and resource-consumption attacks across multiple DNS implementations. Major providers and vendors have applied patches and operational limits, but the report warns the core systemic issues in DNS/DNSSEC remain and that further coordinated fixes are required to prevent broad disruption of critical Internet infrastructure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.