Cyberattack

Cyberattack / Most Commented

DNS Gets A Formal Coordination System

CircleID recently interview Paul Vixie, Founder & Chairman of Internet Software Consortium (ISC), to discuss ISC's newly formed Operations, Analysis, and Research Center (OARC). OARC is launched in response to DDoS attacks at the Internet's core infrastructure and the vital requirement for a formal coordination system. OARC is also a part of US homeland security initiatives, such as the formation of Information Sharing and Analysis Centers (ISACs).

"Registries and registrars, ccTLD operators, large corporate NOCs, ISPs and ecommerce companies that host many domain names are all likely candidates. This is also a natural for law enforcement groups that are worried about attacks on the Internet." more

Blacklists Down from Fear of DDoS

Yet another DNS blacklist has been taken down out of fear of the DDoS attacks that took down Osirusoft, Monkeys.com, and the OpenRBL. Blackholes.compu.net suffered a Joe-Job (A Joe-Job is essentially spam designed to look like it's coming from someone else.) earlier this week. Apparently the Joe-Jobing was enough to convince some extremely ignorant mail administrators that Compu.net is spamming and blocked mail from compu.net. Compu.net has also seen the effects of DDoS attacks on other DNS blacklist maintainers. They've decided that the risk to their actual business is too great and they are pulling the plug on their DNS blacklist before they come under the gun by spammers. more

Trump Enlists Private Firms for Offensive Cyber Operations

The Trump administration will allow vetted American companies to conduct surveillance and offensive cyber operations against foreign criminal groups, extending private-sector capabilities into cybercrime enforcement while keeping missions subject to federal approval, oversight and legal safeguards. more

DNS Security Gets Fixed When Someone Notices - Not Before

A study of 309 universities, museums and sports brands finds DNS security follows visible threats rather than technical risk, leaving organisations well protected against familiar attacks while quieter weaknesses in critical infrastructure persist unnoticed. more

Phantom Squatting: When LLMs’ Hallucination Becomes an Attacker’s Best Friend

As AI reshapes cybersecurity, attackers are exploiting a fundamental weakness in large language models. Phantom squatting turns hallucinated domain names into trusted attack vectors, creating a new class of DNS abuse that defenders cannot solve by eliminating hallucinations alone. more

ZEGO’s Cyberattack Pushes Bavarian Textile Firm Into Insolvency

A cyberattack forced Bavarian textile specialist ZEGO into insolvency after a six-week production shutdown. The company is pursuing restructuring efforts to preserve jobs, customer relationships and its future amid growing cyber risks. more

FBI Warns of Russian Cyber Campaign Targeting Vulnerable Routers

The FBI and international partners warn that Russia's FSB Center 16 is exploiting vulnerable routers worldwide, highlighting persistent weaknesses in network security and urging organizations to adopt stronger protections to safeguard critical infrastructure against intrusion. more

.PK ccTLD Governance Issues and Pakistan’s Digital Future

Pakistan's .pk domain has long been controlled by a private company abroad, raising concerns over digital sovereignty, cybersecurity and accountability. Repeated breaches, offshore infrastructure and weak governance have left a critical national asset exposed and contested. more

From Uptime to Trust: The Domain Security Strategy Behind Business Continuity

Domains and DNS underpin modern business operations, yet security gaps remain widespread. CSC's latest research shows why stronger domain protections are essential to resilience, helping companies reduce disruption, safeguard trust, and maintain continuity when attacks strike. more

dotBrand Domains as Trust Infrastructure in the Age of AI

As AI agents automate phishing, impersonation and domain abuse at machine scale, the Brand Registry Group argues that dotBrand domains are evolving from marketing assets into trust infrastructure underpinning cybersecurity, identity and interactions across the internet. more

Time Sovereignty: Internet Policy and Defense Frameworks for Critical Infrastructure Synchronization Under Geopolitical Conflict

As power grids depend on microsecond precision, states must treat time synchronization as sovereign infrastructure, hardening satellite, fiber and orbital defenses against hybrid attacks that could trigger catastrophic blackouts through resilient sovereign time defense frameworks. more

AI-Driven Cyber Threats Are Growing, Google Warns

Google says cybercriminals and state-backed hackers are rapidly adopting generative AI to automate attacks, disguise malware, exploit vulnerabilities and spread disinformation, marking a shift from experimental use to industrial-scale cyber operations across the global threat landscape. more

The Illusion of Digital Sovereignty (Part I) - Cloud Infrastructure, Survivability, and the Territorialization of the Internet

Missile strikes on Gulf data centres exposed a deeper contradiction at the heart of digital sovereignty: governments seek territorial control over internet infrastructure whose resilience still depends upon globally distributed coordination and interdependence across borders. more

Africa’s Digital Transformation Is Outpacing Its Cybersecurity Governance

Africa's digital boom is accelerating, but safeguards lag. Governments and firms deploy systems at speed, while weak enforcement and fragmented oversight leave economies exposed to mounting cyber risks. more

The Kinetic Frontier: Lessons From Geopolitical Violence and the Bunkerization of AI Infrastructure

Kinetic attacks on Gulf data centres expose the cloud's physical fragility, recasting AI infrastructure as strategic targets and accelerating bunkerisation, while outdated data laws leave firms choosing between legal compliance and digital survival. more