#DNS Hijacking

Every story tagged DNS Hijacking, curated for CIOs and IT leaders — ranked by source credibility, engagement, and freshness.

4 stories · open in the command center

  • Security & PrivacyHacker News3m

    GoDaddy Gave a Domain to a Stranger Without Any Documentation

    A GoDaddy customer lost a 27-year-old domain to an unauthorized transfer initiated by a GoDaddy internal user despite dual two-factor authentication and paid protection services, resulting in four days of total email and website outages across a national organization. The incident revealed critical gaps in GoDaddy's security protocols, account recovery procedures, and customer support escalation processes, with the customer making 32 calls and 9.6 hours of phone time while being redirected between generic email addresses and disconnected case numbers. This case demonstrates a significant supply chain and vendor risk for any organization relying on third-party domain registrars, highlighting the need for IT leaders to implement redundancy strategies and formal incident response protocols with their critical infrastructure providers.

  • Security & PrivacyArs TechnicaDan Goodin2m

    Why are top university websites serving porn? It comes down to shoddy housekeeping.

    Hundreds of subdomains across 34+ universities, including prestigious institutions like Berkeley and Columbia, are serving malicious content and pornography due to poor DNS record management—specifically the failure to remove CNAME records when subdomains are decommissioned. This security lapse exploits a common operational gap where organizations lack comprehensive subdomain inventories and regular audits, allowing threat actors to hijack expired domains and leverage university brands for search engine visibility. For IT organizations, this represents a critical governance and security risk that demands immediate attention to DNS hygiene practices and decentralized resource management.

  • Security & PrivacyWired2m

    The Dumbest Hack of the Year Exposed a Very Real Problem

    Hackers exploited default passwords in widely-deployed crosswalk buttons across multiple cities to upload spoofed audio, exposing critical gaps in IoT security and vendor accountability in municipal infrastructure. The incident reveals systemic weaknesses where cities lack enforceable cybersecurity requirements in procurement contracts, despite increasing integration of connected devices and AI into critical infrastructure. This low-sophistication attack demonstrates how easily accessible IoT devices with poor security hygiene can create operational disruptions and reputational risk for public and private organizations.

  • Security & PrivacyArs Technica2m

    Thousands of consumer routers hacked by Russia's military

    Russian military intelligence (GRU/APT28) has compromised 18,000-40,000 consumer routers globally to conduct sophisticated man-in-the-middle attacks targeting government and enterprise credentials, exploiting unpatched legacy devices and rapidly adapting tactics after public disclosures to harvest OAuth tokens and bypass multi-factor authentication. This represents a critical supply-chain security risk where consumer-grade infrastructure becomes a pivot point for targeting high-value government and enterprise networks, exposing the vulnerability of organizations whose security postures depend on third-party devices beyond their direct control. IT leaders must recognize that network perimeter defenses are insufficient when adversary-controlled infrastructure can intercept encrypted traffic and credentials—necessitating zero-trust architecture, continuous authentication verification, and aggressive device lifecycle management.

Browse all tags