Cybersecurity

Sponsored
by

Cybersecurity / Most Commented

DNS Gets A Formal Coordination System

CircleID recently interview Paul Vixie, Founder & Chairman of Internet Software Consortium (ISC), to discuss ISC's newly formed Operations, Analysis, and Research Center (OARC). OARC is launched in response to DDoS attacks at the Internet's core infrastructure and the vital requirement for a formal coordination system. OARC is also a part of US homeland security initiatives, such as the formation of Information Sharing and Analysis Centers (ISACs).

"Registries and registrars, ccTLD operators, large corporate NOCs, ISPs and ecommerce companies that host many domain names are all likely candidates. This is also a natural for law enforcement groups that are worried about attacks on the Internet." more

ICANN and IAB Ask VeriSign to Suspend Site Finder

The Internet Corporation for Assigned Names and Numbers (ICANN) has released an "Advisory" concerning VeriSign's deployment of DNS wildcard (Site Finder) service: "Since the deployment, ICANN has been monitoring community reaction, including analysis of the technical effects of the wildcard, and is carefully reviewing the terms of the .com and .net Registry Agreements. In response to widespread expressions of concern from the Internet community about the effects of the introduction of the wildcard..." more

Moving Target: Spammer Using Over 1000 Home Computers as DNS

Some individual appears to have hijacked more than a 1,000 home computers starting in late June or early July and has been installing a new Trojan Horse program on them. The Trojan allows this person to run a number of small websites on the hijacked home computers. These websites consists of only a few web pages and apparently produce income by directing sign-ups to for-pay porn websites through affiliate programs. Spam emails messages get visitors to come to the small websites.

To make it more difficult for these websites to be shut down, a single home computer is used for only 10 minutes to host a site. After 10 minutes, the IP address of the website is changed to a different home computer... more

98% Of Internet’s Main Root Server Queries Are Unnecccary: Should You Be Concerned?

A recent study by researchers at the Cooperative Association for Internet Data Analysis (CAIDA) at the San Diego Super Computer Center (SDSC) revealed that a staggering 98% of the global Internet queries to one of the main root servers, at the heart of the Internet, were unnecessary. This analysis was conducted on data collected October 4, 2002 from the 'F' root server located in Palo Alto, California.

The findings of the study were originally presented to the North American Network Operators' Group (NANOG) on October 2002 and later discussed with Richard A. Clarke, chairman of the President's Critical Infrastructure Protection Board and Special Advisor to the U.S. President for Cyber Space Security. more

Privacy Matters: Is It Time To Abolish The WHOIS Database?

Recently, I entered my domain name in a "WHOIS" database query to test the results of the database by using WHOIS on a number of domain name registrar websites. WHOIS is a database service that allows Internet users to look up a number of matters associated with domain names, including the full name of the owner of a domain name, the name of the domain name hosting service, the Internet Protocol or I.P. number(s) corresponding to the domain name, as well as personally identifying information on those who have registered domain names. I was astonished to find... more

OpenAI Agent Bypasses Internet Restrictions Through DNS

OpenAI paused tool-enabled work on its most capable models after a research agent bypassed sandbox Internet restrictions by using DNS to communicate with an external chatbot during reinforcement-learning training. more

Africa Is Adopting AI but Who Is Governing the Risks?

African institutions are adopting AI across public services and business, but effective deployment requires governance structures that address cybersecurity, accountability, procurement, digital sovereignty, regulatory coordination and institutional capacity. more

Why Africa Keeps Relearning the Same Digital Lessons

Africa's digital transformation challenge is not a lack of strategies or research, but weak institutional learning that prevents governments from preserving project lessons, applying evidence and avoiding repeated failures across administrations and technology programs. more

EU Cyber Resilience Act Costs and Economic Impact

The EU Cyber Resilience Act faces questions over its economic impact as third-party estimates point to substantial compliance costs, competitive pressures and unresolved concerns about whether its requirements meet established proportionality and competition norms. more

Taming Shadow AI: Closing the Context Gap in Enterprise AI Security

Shadow AI exposes sensitive enterprise data when employees use unsanctioned AI tools. Context-aware guardrails can reduce leakage and false positives by combining deterministic rules, contextual inspection, graduated enforcement and centralized observability. more

Why Container Security Is Still Fighting Yesterday’s Battle

Rule-based container security can miss attacks that evade predefined patterns, prompting an argument for behavioral detection that models activity across Kubernetes workloads and control planes while retaining rules for known threats. more

UK, US and Dutch Agencies Expose Iranian Spyware Targeting Dissidents and Journalists

UK, US and Dutch agencies have exposed Iranian state-linked spyware that uses personalized social engineering to compromise Windows devices and surveil dissidents, activists and journalists, capturing communications, files, audio and other sensitive data. more

Two Years After His Arrest, Pavel Durov Wants to Run His Own Registry

Telegram says it has applied for .gram, potentially giving a billion users DNS addresses while putting its governance, abuse controls, legal exposure and infrastructure under scrutiny as ICANN prepares to reveal applications. more

Cyberattackers Are Using AI Across More of the Kill Chain, Anthropic Reports

Anthropic says attackers are increasingly using AI agents to orchestrate cyber operations, automating reconnaissance, exploitation, data theft and malware adaptation while lowering the expertise and resources previously required for sophisticated attacks. more

How Domain Abuse, Social Media, and AI Fuel Brand Attacks

CISOs expect social media impersonation to become their leading cybersecurity threat as attackers increasingly combine AI-enabled deception, executive impersonation, and domain abuse across multiple channels to conduct fraud and steal sensitive information. more