<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"
  xmlns:dc="http://purl.org/dc/elements/1.1/"
  xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
  xmlns:admin="http://webns.net/mvcb/"
  xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
  xmlns:content="http://purl.org/rss/1.0/modules/content/">

Third segment: dns-security
  
  <channel>

  <title><![CDATA[CircleID]]></title>
  <link>https://circleid.com/topics/dns-security</link>
  <description>CircleID - DNS Security</description>
  <dc:language>en</dc:language>
  <dc:rights>Copyright 2026, unless where otherwise noted.</dc:rights>
  <dc:date>2026-07-29T16:28:00+00:00</dc:date>

  
    <item>
      <title><![CDATA[The 2024-2026 Root Zone KSK Rollover: Updates and Observations]]></title>
      <link>https://circleid.com/posts/the&#45;2024&#45;2026&#45;root&#45;zone&#45;ksk&#45;rollover&#45;updates&#45;and&#45;observations</link>
      <guid isPermaLink="true">https://circleid.com/posts/the&#45;2024&#45;2026&#45;root&#45;zone&#45;ksk&#45;rollover&#45;updates&#45;and&#45;observations</guid>

      <description><![CDATA[Roughly a year and a half ago, Verisign and ICANN began the important, multi-year process of updating the cryptographic key that secures the authoritative DNS root zone. This work has been largely invisible to the public, but vital to the security of many everyday online activities.]]></description>
      <dc:date>2026-07-28T08:30:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Inside a TDS-Powered ClickFix Malware Ecosystem: A DNS Deep Dive]]></title>
      <link>https://circleid.com/posts/inside&#45;a&#45;tds&#45;powered&#45;clickfix&#45;malware&#45;ecosystem&#45;a&#45;dns&#45;deep&#45;dive</link>
      <guid isPermaLink="true">https://circleid.com/posts/inside&#45;a&#45;tds&#45;powered&#45;clickfix&#45;malware&#45;ecosystem&#45;a&#45;dns&#45;deep&#45;dive</guid>

      <description><![CDATA[DNS analysis of a malware distribution ecosystem uncovered thousands of linked artifacts, exposing typosquatting, malicious infrastructure and victim connections that broaden detection opportunities beyond Check Point Research's original indicators through expanded DNS intelligence correlation efforts.]]></description>
      <dc:date>2026-07-27T12:51:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Digital Sovereignty Is More Than Data Sovereignty: Understanding Africa&#8217;s Digital Dependency Stack]]></title>
      <link>https://circleid.com/posts/digital&#45;sovereignty&#45;is&#45;more&#45;than&#45;data&#45;sovereignty&#45;understanding&#45;africas&#45;digital&#45;dependency&#45;stack</link>
      <guid isPermaLink="true">https://circleid.com/posts/digital&#45;sovereignty&#45;is&#45;more&#45;than&#45;data&#45;sovereignty&#45;understanding&#45;africas&#45;digital&#45;dependency&#45;stack</guid>

      <description><![CDATA[Africa's pursuit of digital sovereignty demands more than keeping data at home. True resilience depends on controlling the infrastructure, platforms, cybersecurity capabilities, governance, and human expertise that underpin an increasingly interconnected digital economy across Africa.]]></description>
      <dc:date>2026-07-20T08:52:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[DNS Investigation: Threat Actor TA4922 Goes Global]]></title>
      <link>https://circleid.com/posts/dns&#45;investigation&#45;threat&#45;actor&#45;ta4922&#45;goes&#45;global</link>
      <guid isPermaLink="true">https://circleid.com/posts/dns&#45;investigation&#45;threat&#45;actor&#45;ta4922&#45;goes&#45;global</guid>

      <description><![CDATA[TA4922 is expanding beyond nearby targets, deploying a fast-changing malware arsenal across Europe and Africa. A DNS investigation uncovered thousands of connected domains, dozens of malicious assets and signs of compromised victim infrastructure worldwide today.]]></description>
      <dc:date>2026-07-17T08:56:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[The Question Isn&#8217;t Whether the Harm Is Real - It&#8217;s Who Should Act]]></title>
      <link>https://circleid.com/posts/the&#45;question&#45;isnt&#45;whether&#45;the&#45;harm&#45;is&#45;real&#45;its&#45;who&#45;should&#45;act</link>
      <guid isPermaLink="true">https://circleid.com/posts/the&#45;question&#45;isnt&#45;whether&#45;the&#45;harm&#45;is&#45;real&#45;its&#45;who&#45;should&#45;act</guid>

      <description><![CDATA[Measuring online abuse can reveal its scale, but not who should intervene. Effective policy must distinguish harm from contractual responsibility, identify the actors best placed to act, and target remedies where they can work effectively.]]></description>
      <dc:date>2026-07-17T08:05:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[Under the DNS Hood of an Ongoing Legacy MSHTA Tool Attack]]></title>
      <link>https://circleid.com/posts/under&#45;the&#45;dns&#45;hood&#45;of&#45;an&#45;ongoing&#45;legacy&#45;mshta&#45;tool&#45;attack</link>
      <guid isPermaLink="true">https://circleid.com/posts/under&#45;the&#45;dns&#45;hood&#45;of&#45;an&#45;ongoing&#45;legacy&#45;mshta&#45;tool&#45;attack</guid>

      <description><![CDATA[A DNS analysis of infrastructure behind ongoing MSHTA abuse uncovered malicious registrations, typosquatting clusters, victim activity, and hundreds of linked indicators, revealing how legacy Windows tooling continues enabling modern malware campaigns through interconnected DNS intelligence.]]></description>
      <dc:date>2026-07-10T09:16:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[macOS ClickFix Campaign Delivers AMOS and Other Infostealers: A DNS Deep Dive]]></title>
      <link>https://circleid.com/posts/macos&#45;clickfix&#45;campaign&#45;delivers&#45;amos&#45;and&#45;other&#45;infostealers&#45;a&#45;dns&#45;deep&#45;dive</link>
      <guid isPermaLink="true">https://circleid.com/posts/macos&#45;clickfix&#45;campaign&#45;delivers&#45;amos&#45;and&#45;other&#45;infostealers&#45;a&#45;dns&#45;deep&#45;dive</guid>

      <description><![CDATA[A DNS deep dive into Microsoft's macOS ClickFix campaign uncovered victim infrastructure, typosquatting clusters, malicious registrations, and hundreds of linked indicators, exposing a broader infostealer ecosystem beyond the original 140 network IoCs identified by Microsoft.]]></description>
      <dc:date>2026-07-06T08:58:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[What the Interisle Report Reveals, and What It Doesn&#8217;t, About DNS Abuse]]></title>
      <link>https://circleid.com/posts/what&#45;the&#45;interisle&#45;report&#45;reveals&#45;and&#45;what&#45;it&#45;does&#45;not&#45;about&#45;dns&#45;abuse</link>
      <guid isPermaLink="true">https://circleid.com/posts/what&#45;the&#45;interisle&#45;report&#45;reveals&#45;and&#45;what&#45;it&#45;does&#45;not&#45;about&#45;dns&#45;abuse</guid>

      <description><![CDATA[Interisle's report illuminates malicious registration trends, but its broad blocklist methodology measures different questions than DNS Abuse, complicating conclusions about registry and registrar accountability by conflating reputation signals with actionable domain enforcement decisions for policymakers.]]></description>
      <dc:date>2026-06-30T08:34:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[DNS Deep Dive: TA416 European Government Espionage Campaigns]]></title>
      <link>https://circleid.com/posts/dns&#45;deep&#45;dive&#45;ta416&#45;european&#45;government&#45;espionage&#45;campaigns</link>
      <guid isPermaLink="true">https://circleid.com/posts/dns&#45;deep&#45;dive&#45;ta416&#45;european&#45;government&#45;espionage&#45;campaigns</guid>

      <description><![CDATA[An extensive DNS analysis of TA416's renewed European espionage campaign uncovered malicious infrastructure, typosquatting clusters, historical network activity, and thousands of connected artifacts that expand defenders' visibility beyond Proofpoint's original indicators for proactive threat hunting.]]></description>
      <dc:date>2026-06-29T13:10:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[DNS Deep Dive: GHOST STADIUM Takes Advantage of FIFA 2026]]></title>
      <link>https://circleid.com/posts/dns&#45;deep&#45;dive&#45;ghost&#45;stadium&#45;takes&#45;advantage&#45;of&#45;fifa&#45;2026</link>
      <guid isPermaLink="true">https://circleid.com/posts/dns&#45;deep&#45;dive&#45;ghost&#45;stadium&#45;takes&#45;advantage&#45;of&#45;fifa&#45;2026</guid>

      <description><![CDATA[A DNS investigation of the GHOST STADIUM phishing operation uncovered typosquatting clusters, malicious infrastructure, victim-linked IP activity, and thousands of connected domains, revealing the scale of a FIFA 2026 ticket fraud ecosystem.]]></description>
      <dc:date>2026-06-24T09:09:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[.PK ccTLD Governance Issues and Pakistan&#8217;s Digital Future]]></title>
      <link>https://circleid.com/posts/dot&#45;pk&#45;cctld&#45;governance&#45;issues&#45;and&#45;pakistan&#45;digital&#45;future</link>
      <guid isPermaLink="true">https://circleid.com/posts/dot&#45;pk&#45;cctld&#45;governance&#45;issues&#45;and&#45;pakistan&#45;digital&#45;future</guid>

      <description><![CDATA[Pakistan's .pk domain has long been controlled by a private company abroad, raising concerns over digital sovereignty, cybersecurity and accountability. Repeated breaches, offshore infrastructure and weak governance have left a critical national asset exposed and contested.]]></description>
      <dc:date>2026-06-23T09:51:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[When AI Writes the Scam: How Artificial Intelligence Is Making DNS Abuse Harder to Detect]]></title>
      <link>https://circleid.com/posts/when&#45;ai&#45;writes&#45;the&#45;scam&#45;how&#45;artificial&#45;intelligence&#45;is&#45;making&#45;dns&#45;abuse&#45;harder&#45;to&#45;detect</link>
      <guid isPermaLink="true">https://circleid.com/posts/when&#45;ai&#45;writes&#45;the&#45;scam&#45;how&#45;artificial&#45;intelligence&#45;is&#45;making&#45;dns&#45;abuse&#45;harder&#45;to&#45;detect</guid>

      <description><![CDATA[Artificial intelligence is transforming phishing and DNS abuse, erasing the linguistic clues that once exposed scams. As attacks become personalised, automated and multilingual, governance frameworks are struggling to keep pace with a rapidly expanding threat surface.]]></description>
      <dc:date>2026-06-22T08:51:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[A DNS Investigation of Shadow-Earth-053]]></title>
      <link>https://circleid.com/posts/a&#45;dns&#45;investigation&#45;of&#45;shadow&#45;earth&#45;053</link>
      <guid isPermaLink="true">https://circleid.com/posts/a&#45;dns&#45;investigation&#45;of&#45;shadow&#45;earth&#45;053</guid>

      <description><![CDATA[A DNS investigation of Shadow-Earth-053 uncovered hundreds of victim-linked connections and a sprawling infrastructure tied to China-aligned cyber-espionage. Analysis of known indicators exposed additional domains, IP addresses, and registration patterns that broaden the campaign's suspected footprint.]]></description>
      <dc:date>2026-06-19T12:17:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[DNS Deep Diving into FakeWallet Crypto Stealer]]></title>
      <link>https://circleid.com/posts/dns&#45;deep&#45;diving&#45;into&#45;fakewallet&#45;crypto&#45;stealer</link>
      <guid isPermaLink="true">https://circleid.com/posts/dns&#45;deep&#45;diving&#45;into&#45;fakewallet&#45;crypto&#45;stealer</guid>

      <description><![CDATA[A DNS-focused investigation of the FakeWallet crypto-stealer campaign uncovered links to malicious infrastructure, potential victims, and thousands of connected domains, revealing signs of pre-staged operations and suggesting the wallet-phishing scheme was broader and longer-running than first reported.]]></description>
      <dc:date>2026-06-15T11:22:00-07:00</dc:date>
    </item>
  
    <item>
      <title><![CDATA[DNS Deep Dive: Pushpaganda Network IoCs]]></title>
      <link>https://circleid.com/posts/dns&#45;deep&#45;dive&#45;pushpaganda&#45;network&#45;iocs</link>
      <guid isPermaLink="true">https://circleid.com/posts/dns&#45;deep&#45;dive&#45;pushpaganda&#45;network&#45;iocs</guid>

      <description><![CDATA[A DNS investigation into Pushpaganda, an AI-powered scam network that infiltrated Google Discovery feeds, uncovered more than 1,000 connected domains, 162 linked IP addresses, and evidence that several infrastructure assets were registered with malicious intent.]]></description>
      <dc:date>2026-06-10T11:43:00-07:00</dc:date>
    </item>
  

  </channel>
  

</rss>