logo

DNS OverDoS: Are Private Endpoints Too Private?

ID: 06037e0a-481d-550e-b695-c68614d4e538

STIX ID: report--06037e0a-481d-550e-b695-c68614d4e538

Feed Name: Palo Alto Networks Unit 42

Threat Score
60/100

Date Published: 2026-01-20

Date Updated: 2026-04-28

Author: Unit 42

...
...

This Unit 42 report describes a design/configuration weakness in Azure Private Link where linking Private DNS zones to virtual networks can cause forced name resolution to private endpoints that lack A records, producing DNS failures and partial denial-of-service for Azure resources (notably storage accounts, Key Vault, CosmosDB, ACR, Function Apps, and OpenAI). The authors quantify exposure (over 5% of storage accounts susceptible), explain attack/accidental scenarios (internal, vendor, malicious), provide detection queries (Azure Resource Graph) and recommend mitigations including DNS fallback to internet and manual DNS record creation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.