Cybersecurity

Sponsored
by

Blogs

The Missing Privacy Debate Around IPv6

IPv6 solves the Internet's address shortage and simplifies networking, but its technical elegance may carry a hidden cost: shifting privacy protections from architectural constraints toward policies controlled by Internet providers, corporations and governments.

Publishing DMARC Is Not the Same as Operating It

Publishing a DMARC record is only the beginning. New data show that many domains lack enforcement or reporting, exposing a gap between adopting email authentication and operating it effectively enough to detect problems and deter impersonation.

Beyond Protocol and Policy: Why Project Jake is Reshaping the Architecture of Internet Trust

Project Jake aims to bridge the divide between internet protocols and policy, offering registries, law enforcement and rights holders a decentralised framework for accessing domain-registration data securely while navigating privacy laws and institutional gridlock.

Open-Weight AI: Open to Whom?

The push for open-weight AI promises broader access and competition, but true openness requires more than releasing model weights. Compute, infrastructure, training data, security, and control ultimately determine who can meaningfully benefit from open AI.

DNS Abuse and Criminal Infrastructure: Beyond Definitions and Blocklists

Research suggests criminals may control a striking share of newly registered gTLD domains, raising questions about whether ICANN's definitions, contractual safeguards and enforcement mechanisms are keeping pace with the industrial scale of technology-facilitated harm.

AI Duties Are Being Written but the Protocol Layer Is Missing

Recent AI containment failures expose a governance gap: harmful model behavior is often visible at the network boundary but poorly monitored. Adapting proven internet protocols could give governments and companies practical tools to enforce accountability.

DNSSEC Doesn’t Need a Better Story - It Needs a Better Tuesday

DNSSEC adoption is stronger than headline figures suggest, yet uneven across industries. New data indicate the bigger obstacle is not reputation but operational friction, especially key rollovers, registrar coordination and automation still missing across major domains.

What Reagan-Era Cyber Strategists Can Teach America Today

Reagan-era cyber strategists anticipated today's transnational threats, proposing international treaties, public-private cooperation and infrastructure protections. As America again considers aggressive action against cybercriminals, their largely forgotten blueprint offers both lessons and warnings.

The Dual-Front Challenge: Why Route Security (RPKI) is the Prerequisite for Quantum Readiness (PQC)

Internet security risks advancing unevenly: post-quantum cryptography may protect data while vulnerable routing still enables hijacks. Universal RPKI adoption, paired with cryptographic agility, is essential to build an Internet trust architecture ready for quantum threats.

DNS Security Gets Fixed When Someone Notices - Not Before

A study of 309 universities, museums and sports brands finds DNS security follows visible threats rather than technical risk, leaving organisations well protected against familiar attacks while quieter weaknesses in critical infrastructure persist unnoticed.

The Web Has Become a Content Delivery Network

Cyberattacks, AI scraping and relentless bot traffic have transformed CDNs from performance tools into the Web's defensive gatekeepers, reshaping Internet architecture, governance and control as private intermediaries increasingly determine which requests reach origin servers first.

Safe for Whom? A Pilot’s Take on the AI Incident-Reporting System

Drawing on aviation's trusted incident-reporting model, a former pilot argues AI safety needs confidential reporting paired with public learning, and that legitimacy, international participation and transparency must be built into SAFE from the outset.

Phantom Squatting: When LLMs’ Hallucination Becomes an Attacker’s Best Friend

As AI reshapes cybersecurity, attackers are exploiting a fundamental weakness in large language models. Phantom squatting turns hallucinated domain names into trusted attack vectors, creating a new class of DNS abuse that defenders cannot solve by eliminating hallucinations alone.

Call for Participation: DNSSEC and Security Workshop at ICANN87 (21 October 2026)

ICANN is inviting proposals for its DNSSEC and Security Workshop at ICANN 87, offering experts and practitioners a platform to share insights on DNS security, routing security, browser security, and emerging Internet infrastructure challenges.

The EU Cyber Resilience Act Regime: A Failure to Know Your Limitations

A cybersecurity historian argues the EU Cyber Resilience Act overreaches through unworkable mandates, sprawling jurisdiction and outdated assumptions, urging a streamlined successor that embraces AI, existing standards and practical enforcement instead of bureaucratic complexity today.

News Briefs

UK Warns of Rising Cyberattacks on Exposed Industrial Systems

Trump Enlists Private Firms for Offensive Cyber Operations

Microsoft Launches AI Cybersecurity Model to Boost MDASH Performance and Cut Costs

ZEGO’s Cyberattack Pushes Bavarian Textile Firm Into Insolvency

FBI Warns of Russian Cyber Campaign Targeting Vulnerable Routers

UK Unveils AI Cyber Shield to Counter Machine-Speed Digital Threats

Spain to Require Four Hours of Mobile Service During Power Blackouts

CENTR Warns Against Excessive Burdens in EU Cybersecurity Overhaul

Researchers Uncover Browser-Based SSD Side Channel That Can Track User

Iran Threatens Subsea Internet Cables in the Strait of Hormuz

AI-Driven Cyber Threats Are Growing, Google Warns

Steven Bellovin Takes Aim at Cybersecurity Myths in New Book

Iran-Linked Cyberattacks Expose Fragility of America’s Industrial Nerve System

U.S. Blocks Foreign-Made Routers Over Cybersecurity Fears

Iran Targeted by Self-Propagating Malware in Supply-Chain Cyberattacks

ICANN Probes “Parked Domains” and Zero-Click Redirects Amid Growing Internet Governance Concerns

Kadnap Malware Infects 14,000 Routers Worldwide, Designed to Resist Takedowns Experts Warn

Iran Expands Digital Dragnet After Crushing Protests

Governing the Invisible: AI Risks in Telecom Infrastructure Outpace Global Legal Frameworks

NANOG 95: From Faster Fibre to Route Leaks, Operators Face Old Problems with New Tools

Most Viewed

Most Commented

Taking Back the DNS

Fake Bank Site, Fake Registrar

When Registrars Look the Other Way, Drug-Dealers Get Paid

Who Is Blocking WHOIS? Part 2

ICANN Complaint System Easily Gamed

Verisign Updates – Sponsor

Industry Insights: Verisign, ICANN and Industry Partners Collaborate to Combat Botnets

Addressing DNS abuse and maintaining a healthy DNS ecosystem are important components of Verisign's commitment to being a responsible steward of the internet. We continuously engage with the Internet Corporation for Assigned Names and Numbers (ICANN) and other industry partners to help ensure the secure, stable and resilient operation of the DNS. more

Q2 2018 DDoS Trends Report: 52 Percent of Attacks Employed Multiple Attack Types

Verisign just released its Q2 2018 DDoS Trends Report, which represents a unique view into the attack trends unfolding online, through observations and insights derived from distributed denial of service (DDoS) attack mitigations enacted on behalf of customers of Verisign DDoS Protection Services. more

Operational Update Regarding the KSK Rollover for Administrators of Recursive Name Servers

Currently scheduled for October 11, 2018, the Internet Corporation for Assigned Names and Numbers (ICANN) plans to change the cryptographic key that helps to secure the internet's Domain Name System (DNS) by performing a Root Zone Domain Name System Security Extensions (DNSSEC) key signing key (KSK) rollover. more

Q1 2018 DDoS Trends Report: 58 Percent of Attacks Employed Multiple Attack Types

Verisign has released its Q1 2018 DDoS Trends Report, which represents a unique view into the attack trends unfolding online, through observations and insights derived from distributed denial of service (DDoS) attack mitigations enacted on behalf of Verisign DDoS Protection Services, and security research conducted by Verisign Security Services. more

DNS-Based Threats: Cache Poisoning

As DNS attacks grow in frequency and impact, organizations can no longer afford to overlook DNS security as part of their overall defense-in-depth strategy. As with IT security in general, no single tactic can address the entire DNS threat landscape or secure the complete DNS ecosystem. more

Q4 2017 DDoS Trends Report: Financial Sector Experienced 40 Percent of Attacks

Verisign has released its Q4 2017 DDoS Trends Report, which represents a unique view into the attack trends unfolding online, through observations and insights derived from distributed denial of service (DDoS) attack mitigations enacted on behalf of Verisign DDoS Protection Services and security research conducted by Verisign Security Services. more

DNS-Based Threats: DNS Reflection and Amplification Attacks

Cybercriminals recognize the value of DNS availability and look for ways to compromise DNS uptime and the DNS servers that support it. As such, DNS becomes an important point of security enforcement and a potential point in the Cyber Kill Chain for many cyber-attacks. more

Industry Updates

Participants – Random Selection