Mozilla Foundation has announced changes to Firefox concerning Internationalized Domain Names (IDN) to deal with homograph spoofing attacks. According to the organization, "Mozilla Foundation products now only display IDNs in a whitelist of TLDs, which have policies stating what characters are permitted, and procedures for making sure that no homographic domains are registered to two different entities." Following is a statement explaining the current status of the Mozilla changes to Firefox regarding IDN... more
IT security strategies invariably focus on maintaining impenetrable fortresses around computers and network systems. Firewalls, virtual private networks and anti-virus programs are the tools IT engineers use to create their digital security. Sophisticated defense systems can be very effective at keeping the obvious attackers at bay, yet they often create a false sense of security because the real attacks, the kind that inflict irreparable damage on a system or network, avoid the obvious routes into the secure fortress. more
CircleID recently interview Paul Vixie, Founder & Chairman of Internet Software Consortium (ISC), to discuss ISC's newly formed Operations, Analysis, and Research Center (OARC). OARC is launched in response to DDoS attacks at the Internet's core infrastructure and the vital requirement for a formal coordination system. OARC is also a part of US homeland security initiatives, such as the formation of Information Sharing and Analysis Centers (ISACs).
"Registries and registrars, ccTLD operators, large corporate NOCs, ISPs and ecommerce companies that host many domain names are all likely candidates. This is also a natural for law enforcement groups that are worried about attacks on the Internet." more
Yet another DNS blacklist has been taken down out of fear of the DDoS attacks that took down Osirusoft, Monkeys.com, and the OpenRBL. Blackholes.compu.net suffered a Joe-Job (A Joe-Job is essentially spam designed to look like it's coming from someone else.) earlier this week. Apparently the Joe-Jobing was enough to convince some extremely ignorant mail administrators that Compu.net is spamming and blocked mail from compu.net. Compu.net has also seen the effects of DDoS attacks on other DNS blacklist maintainers. They've decided that the risk to their actual business is too great and they are pulling the plug on their DNS blacklist before they come under the gun by spammers. more
A Russian attack disrupted Internet access for about 100,000 Kyiv-area households and affected data centers, hosting and court services, exposing disruptions across multiple infrastructure layers while leaving possible shared dependencies unclear. more
Rule-based container security can miss attacks that evade predefined patterns, prompting an argument for behavioral detection that models activity across Kubernetes workloads and control planes while retaining rules for known threats. more
AWS says Iranian strikes caused permanent customer data loss in Bahrain and the UAE, exposing the limits of Availability Zone redundancy when physical destruction affects multiple cloud facilities within a region. more
Anthropic says attackers are increasingly using AI agents to orchestrate cyber operations, automating reconnaissance, exploitation, data theft and malware adaptation while lowering the expertise and resources previously required for sophisticated attacks. more
Authorities disrupted the decades-old Sality botnet by targeting its decentralized peer-to-peer network and supporting domains, cutting infected machines off from malicious payloads while beginning the longer task of identifying and remediating compromised systems. more
Dangling DNS records can expose trusted corporate subdomains to takeover, while AI-assisted reconnaissance makes abandoned resources easier to find, increasing the need for continuous DNS monitoring rather than periodic audits. more
FulcrumSec claims it stole 86 GB from Manchester Airports Group, including detailed booking and travel data, while the operator has confirmed a breach but not the group's account of its scale or method. more
More than 100 organizations are calling for wider use of AI in cyber defense, urging governments, technology providers and AI developers to expand funding, tools, model access and practical support for under-resourced critical infrastructure operators. more
Britain's cyber agency warns that attackers are increasingly targeting internet-exposed industrial systems, routers and other edge devices, with some intrusions causing real-world disruption and highlighting the growing risks of poorly secured operational technology worldwide. more
The Trump administration will allow vetted American companies to conduct surveillance and offensive cyber operations against foreign criminal groups, extending private-sector capabilities into cybercrime enforcement while keeping missions subject to federal approval, oversight and legal safeguards. more
A study of 309 universities, museums and sports brands finds DNS security follows visible threats rather than technical risk, leaving organisations well protected against familiar attacks while quieter weaknesses in critical infrastructure persist unnoticed. more