Tag: dns
-
New NatJack NAT Attack Lets Hackers Hijack TCP Connections and DNS Responses
A newly disclosed attack class, NatJack, reveals significant weaknesses in the implementation of Network Address Translation (NAT) across modern network infrastructures. This vulnerability allows attackers to hijack TCP connections, tamper with DNS responses, and disrupt traffic flow. NatJack specifically targets the NAT state table, highlighting that traditional assumptions about cooperative network behavior are no longer…
-
New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables.Presented at Black Hat USA 2026, the research found affected behavior across independently developed implementations, including Windows and First seen on…
-
Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables.Presented at Black Hat USA 2026, Stagg said the techniques were demonstrated across network infrastructure devices First…
-
Researchers Find Three Ways Apple Traffic Can Bypass iCloud Private Relay
Researchers found three Apple request paths that may bypass iCloud Private Relay, potentially exposing users’ IP addresses or DNS activity. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/cybersecurity/news-apple-icloud-private-relay-ip-address-leaks/
-
The 12 Best Protective DNS (PDNS) Services, Compared and Priced (2026)
Protective DNS is the rare control where the cheap options are genuinely good so this comparison leads with value. The verdict: DNSFilter is the best published-price PDNS for most organizations, Cloudflare Gateway owns the free-to-enterprise arc (and now runs the UK’s national PDNS with Accenture), N-able and ScoutDNS serve MSPs at fair rates, CIRA gives…
-
OSINT collection techniques using legitimate tools
Open source intelligence, usually shortened to OSINT, is the practice of collecting and analysing information that is already publicly available. In a defensive context, that can include company websites, social media posts, public registers, DNS records, certificate logs, archived web pages, document metadata, and other sources that are accessible without bypassing controls or impersonating anyone….…
-
Flooding Dropper Hits npm With 850 Malicious Packages
Tags: attack, automation, cloud, container, control, credentials, cvss, data-breach, detection, dns, endpoint, github, guide, infrastructure, linux, macOS, malicious, malware, monitoring, software, threat, windows<div cla TL;DR Sonatype Research Labs is tracking an active malicious package campaign, dubbed ‘Flooding Dropper,’ spreading on npm, currently impacting 846 software components. The attacker appears to be automating parts of the npm account and package creation process, combining terms such as bigops and bnpl with other words and recurring version patterns, such as releases…
-
Four Million Malware Reports Reveal a Widespread No-DNS C2 Blind Spot
A long”‘running supply chain compromise of the QuickFox VPN accelerator that quietly delivered an FDMTP backdoor to carefully profiled Windows systems, exposing a major blind spot in defenders’ visibility where command”‘and”‘control (C2) traffic never touches traditional DNS. The attackers added just two lines of JavaScript to an internal Electron renderer HTML file, causing the app…
-
Uptime Kuma 2.5.0 waits two weeks before trusting a new npm package
Uptime Kuma checks whether a website, a Docker container, a DNS record, or a Steam game server is still answering, and pushes a message to Telegram, Slack, or email when one … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/04/uptime-kuma-2-5-0-cooldown-npm-updates/
-
ChocoShell Steals Microsoft 365 Tokens and Browser Sessions From Travelers
ChocoShell is a PowerShell-based infostealer used in Microsoft’s newly disclosed “CaptiveCrunch” campaign to steal Microsoft 365 tokens, browser sessions, and Wi”‘Fi credentials from travelers connecting to compromised hospitality networks worldwide. The operation, dubbed “CaptiveCrunch,” poisons DNS and HTTP flows on guest networks so that travelers attempting to reach legitimate Microsoft 365 or update endpoints are…
-
âš¡ Weekly Recap: Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks
This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended.Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned…
-
Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens
Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS…
-
CubePilot drone software dev hit by DNS hijacking to intercept traffic
CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cubepilot-drone-software-dev-hit-by-dns-hijacking-to-intercept-traffic/
-
hBlock sperrt Werbung ohne PiDatei
Tags: dnshBlock blockiert Werbung und Tracker über die Hosts-Datei und ergänzt Pi-hole, DNS Forge, NextDNS, AdGuard DNS und andere DNS-Adblocker. First seen on tarnkappe.info Jump to article: tarnkappe.info/tutorials/hblock-sperrt-werbung-ohne-pi-hole-ueber-die-hosts-datei-331796.html
-
DNS wird kritischer Bestandteil resilienter IT-Umgebungen – Wie NIST mit SP 800-81r3 die DNS-Sicherheit neu definiert
First seen on security-insider.de Jump to article: www.security-insider.de/nist-sp-800-81r3-dns-sicherheit-a-59634f631e7fe216d1220ef15453c453/
-
Hacker manipulieren Hotel-WLANs für Microsoft-365-Diebstahl
Angreifer manipulieren DNS-Einstellungen in Hotel-WLANs, um Nutzer auf gefälschte Microsoft-365-Seiten umzuleiten und Zugangsdaten abzugreifen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/microsoft-365-diebstahl-hotel-wlan
-
Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts
Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/
-
Hotel Wi-Fi Routers Compromised to Steal Corporate Login Credentials From Visitors
Researchers at ReliaQuest warned of widespread DNS poisoning attacks targeting the hospitality sector as part of a cyber espionage campaign First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hotel-wifi-dns-poisoning/
-
Hotel Wi-Fi DNS Poisoning Attacks Hijack Microsoft 365 Accounts Without Phishing
Adversaries are silently hijacking Microsoft 365 accounts by compromising hotel and conference-center Wi-Fi gateways and poisoning DNS no phishing emails, malicious attachments, or endpoint malware required. ReliaQuest assesses that the tradecraft closely mirrors prior APT28-linked router campaigns, extending them into captive-portal infrastructure used by traveling corporate staff. Since at least June 2026, threat actors have…
-
New TrickBot Variant Spotted Using DNS to Control Infected Windows PCs
Fortinet has found a new TrickBot variant hiding commands in DNS traffic and using scheduled tasks and added modules to maintain access on infected Windows PCs. First seen on hackread.com Jump to article: hackread.com/new-trickbot-variant-dns-control-infected-windows-pcs/
-
New TrickBot Malware Variant Uses DNS Tunneling for CommandControl
A new TrickBot malware variant that significantly evolves its command-and-control (C2) communication by leveraging DNS tunneling, replacing the traditional HTTP-based mechanisms observed in earlier campaigns. The discovery highlights a continued shift among financially motivated threat actors toward stealthier communication channels designed to evade network detection and security controls. However, the newly analyzed samples demonstrate a…
-
TrickBot variant uses DNS tunneling for command and control
First seen on scworld.com Jump to article: www.scworld.com/brief/trickbot-variant-uses-dns-tunneling-for-command-and-control
-
TrickBot Ditches HTTP for DNS Tunneling in Latest Variant
Tags: dnsNew TrickBot variant hides C2 communication inside DNS queries, replacing decade-old HTTP pattern First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/trickbot-dns-tunneling-c2/
-
New CAV3RN Module Replaces WebSocket C2 With Outlook Calendar Dead Drops
In a significant evolution of the Project CAV3RN tooling, a new .NET Native AOT communication module dubbed AzureCommunication.dll has been deployed to replace the framework’s earlier HTTP/WebSocket C2 component. A stealthy channel that abuses Outlook calendar events over Microsoft Graph and a DNS-based recovery mechanism for Microsoft 365 credentials. This shift reinforces CAV3RN’s positioning as…
-
Telegram’s t.me Domain Suspended, Breaking Invite and Channel Links Worldwide
Telegram’s core short-link domain, t.me, has been placed under a serverHold status at the .me registry. This action can remove the domain from the global DNS, making all associated links inaccessible. The incident affects various Telegram features, including invite links, public channel previews, bot URLs, usernames, and shared message links that rely on the t.me…
-
TechnitiumDNS App bringt Technitium aufs Smartphone
TechnitiumDNS App und Technito verwalten Technitium DNS auf Android und iOS. Dazu kommen Tailscale Funnel und der eigene Resolver. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/it-sicherheit/datenschutz/technitiumdns-app-bringt-technitium-aufs-smartphone-331395.html
-
Fake 7-Zip Installers Turn Devices Into Residential Proxy Nodes
Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains.The activity dates back to at least August 2022, according to DNS threat intelligence firm Infoblox. Once such campaign, observed earlier this year, involved…
-
Government and Healthcare Are the Weakest Links in Global Email Security
Government and healthcare sectors have weak email security. Many domains lack SPF, DMARC, DKIM, and MTA-STS, leaving them open to phishing attacks. Comparitech analyzed live DNS records for 5,849 domains across 13 sectors and scored each one out of 8 points based on four standard email authentication protocols: SPF, DMARC, DKIM, and MTA-STS. The results…
-
SEO-Poisoned Software Sites Abuse ScreenConnect to Deploy AsyncRAT
Unknown threat actors are leveraging the ScreenConnect remote access tool as a way to deploy and execute AsyncRAT.Kaspersky said the activity is part of a “massive, multi-domain, multi-language” campaign that distributes malicious installer archives hosted on spoofed websites.These installers masquerade as popular software like OBS Studio, DNS Jumper, DS4Windows, and Bandicam, among others. First seen…

