Cybersecurity

Sponsored
by

Cybersecurity / Most Commented

Moving Target: Spammer Using Over 1000 Home Computers as DNS

Some individual appears to have hijacked more than a 1,000 home computers starting in late June or early July and has been installing a new Trojan Horse program on them. The Trojan allows this person to run a number of small websites on the hijacked home computers. These websites consists of only a few web pages and apparently produce income by directing sign-ups to for-pay porn websites through affiliate programs. Spam emails messages get visitors to come to the small websites.

To make it more difficult for these websites to be shut down, a single home computer is used for only 10 minutes to host a site. After 10 minutes, the IP address of the website is changed to a different home computer... more

98% Of Internet’s Main Root Server Queries Are Unnecccary: Should You Be Concerned?

A recent study by researchers at the Cooperative Association for Internet Data Analysis (CAIDA) at the San Diego Super Computer Center (SDSC) revealed that a staggering 98% of the global Internet queries to one of the main root servers, at the heart of the Internet, were unnecessary. This analysis was conducted on data collected October 4, 2002 from the 'F' root server located in Palo Alto, California.

The findings of the study were originally presented to the North American Network Operators' Group (NANOG) on October 2002 and later discussed with Richard A. Clarke, chairman of the President's Critical Infrastructure Protection Board and Special Advisor to the U.S. President for Cyber Space Security. more

Privacy Matters: Is It Time To Abolish The WHOIS Database?

Recently, I entered my domain name in a "WHOIS" database query to test the results of the database by using WHOIS on a number of domain name registrar websites. WHOIS is a database service that allows Internet users to look up a number of matters associated with domain names, including the full name of the owner of a domain name, the name of the domain name hosting service, the Internet Protocol or I.P. number(s) corresponding to the domain name, as well as personally identifying information on those who have registered domain names. I was astonished to find... more

AI Duties Are Being Written but the Protocol Layer Is Missing

Recent AI containment failures expose a governance gap: harmful model behavior is often visible at the network boundary but poorly monitored. Adapting proven internet protocols could give governments and companies practical tools to enforce accountability. more

DNSSEC Doesn’t Need a Better Story - It Needs a Better Tuesday

DNSSEC adoption is stronger than headline figures suggest, yet uneven across industries. New data indicate the bigger obstacle is not reputation but operational friction, especially key rollovers, registrar coordination and automation still missing across major domains. more

Trump Enlists Private Firms for Offensive Cyber Operations

The Trump administration will allow vetted American companies to conduct surveillance and offensive cyber operations against foreign criminal groups, extending private-sector capabilities into cybercrime enforcement while keeping missions subject to federal approval, oversight and legal safeguards. more

DNS Security Gets Fixed When Someone Notices - Not Before

A study of 309 universities, museums and sports brands finds DNS security follows visible threats rather than technical risk, leaving organisations well protected against familiar attacks while quieter weaknesses in critical infrastructure persist unnoticed. more

Phantom Squatting: When LLMs’ Hallucination Becomes an Attacker’s Best Friend

As AI reshapes cybersecurity, attackers are exploiting a fundamental weakness in large language models. Phantom squatting turns hallucinated domain names into trusted attack vectors, creating a new class of DNS abuse that defenders cannot solve by eliminating hallucinations alone. more

Call for Participation: DNSSEC and Security Workshop at ICANN87 (21 October 2026)

ICANN is inviting proposals for its DNSSEC and Security Workshop at ICANN 87, offering experts and practitioners a platform to share insights on DNS security, routing security, browser security, and emerging Internet infrastructure challenges. more

Microsoft Launches AI Cybersecurity Model to Boost MDASH Performance and Cut Costs

Microsoft has unveiled a specialist cybersecurity AI model powering MDASH, claiming higher benchmark performance and lower costs while launching Project Perception, an agentic security platform designed to help defenders counter increasingly automated cyber threats. more

The EU Cyber Resilience Act Regime: A Failure to Know Your Limitations

A cybersecurity historian argues the EU Cyber Resilience Act overreaches through unworkable mandates, sprawling jurisdiction and outdated assumptions, urging a streamlined successor that embraces AI, existing standards and practical enforcement instead of bureaucratic complexity today. more

Who Registers the Domain That Steals Your Data? The Registrar Accountability Gap in India’s DNS Abuse Crisis

India's DNS abuse crisis exposes a registrar accountability gap: malicious domains remain online while vulnerable users bear the cost. Concentrated abuse patterns suggest stronger oversight and faster mitigation could significantly reduce predictable harms nationwide today. more

Digital Sovereignty Is More Than Data Sovereignty: Understanding Africa’s Digital Dependency Stack

Africa's pursuit of digital sovereignty demands more than keeping data at home. True resilience depends on controlling the infrastructure, platforms, cybersecurity capabilities, governance, and human expertise that underpin an increasingly interconnected digital economy across Africa. more

The Question Isn’t Whether the Harm Is Real - It’s Who Should Act

Measuring online abuse can reveal its scale, but not who should intervene. Effective policy must distinguish harm from contractual responsibility, identify the actors best placed to act, and target remedies where they can work effectively. more

ZEGO’s Cyberattack Pushes Bavarian Textile Firm Into Insolvency

A cyberattack forced Bavarian textile specialist ZEGO into insolvency after a six-week production shutdown. The company is pursuing restructuring efforts to preserve jobs, customer relationships and its future amid growing cyber risks. more