Researchers: Weak Security Defaults Enabled Squarespace Domains Hijacks
ID: 9cd63d82-3524-58f0-b205-7f495dc44020
STIX ID: report--9cd63d82-3524-58f0-b205-7f495dc44020
Feed Name: Krebs on Security
Threat Score
- Between July 9 and July 12, attackers exploited account-creation and migration weaknesses during Squarespace’s takeover of Google Domains to claim uninitialized domain-associated email accounts, hijack at least a dozen domains (notably crypto businesses), and in some cases redirect them to phishing sites; researchers point to missing email verification and disabled MFA during migration as root causes while Squarespace later reported an OAuth-related issue.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
