DNS Security

Sponsored
by

Noteworthy

Domain Research and Monitoring: Keeping an Eye on the Web for You

Reverse WHOIS: A Powerful Process in Cybersecurity

WHOIS History API: Powering Domain Investigations

Blogs

The Reporting Gap: What Happens Between a DNS Abuse Complaint and a Takedown

DNS abuse enforcement can stop abusive domains and drive systemic registrar reforms, but reporting barriers, inconsistent response times, and poorly documented complaints leave many phishing sites active before actionable cases ever reach enforcement.

Caribbean-Born Niel Harper Joins ICANN Board, Sets Out Priorities in Q&A

Barbados-born cybersecurity specialist Niel Harper joins ICANN's board in October, aiming to strengthen Latin American and Caribbean participation, improve DNS security and abuse mitigation, and expand developing-economy access to the next gTLD round.

15th Registration Operations Workshop, September 29, 2026, 13:00 - 17:00 UTC

The 15th Registration Operations Workshop convenes domain name and DNS professionals September 29 for technical sessions on mTLS, RPKI, DNS resilience, delegations, DNSSEC, registrar concentration, dispute proceedings and alternative naming systems.

Proposed New DNS Resource Record Types for AI Agent Discovery

For more than three decades, domain names have served as a foundational identity layer for internet applications. Initially used to identify early network services such as TELNET, FTP, and email, they later became essential to web browsing and a growing range of online services.

From Forgotten to Exploited: How AI Changes the Dangling DNS Threat

Dangling DNS records can expose trusted corporate subdomains to takeover, while AI-assisted reconnaissance makes abandoned resources easier to find, increasing the need for continuous DNS monitoring rather than periodic audits.

Beyond Protocol and Policy: Why Project Jake is Reshaping the Architecture of Internet Trust

Project Jake aims to bridge the divide between internet protocols and policy, offering registries, law enforcement and rights holders a decentralised framework for accessing domain-registration data securely while navigating privacy laws and institutional gridlock.

Open-Weight AI: Open to Whom?

The push for open-weight AI promises broader access and competition, but true openness requires more than releasing model weights. Compute, infrastructure, training data, security, and control ultimately determine who can meaningfully benefit from open AI.

DNS Abuse and Criminal Infrastructure: Beyond Definitions and Blocklists

Research suggests criminals may control a striking share of newly registered gTLD domains, raising questions about whether ICANN's definitions, contractual safeguards and enforcement mechanisms are keeping pace with the industrial scale of technology-facilitated harm.

DNSSEC Doesn’t Need a Better Story - It Needs a Better Tuesday

DNSSEC adoption is stronger than headline figures suggest, yet uneven across industries. New data indicate the bigger obstacle is not reputation but operational friction, especially key rollovers, registrar coordination and automation still missing across major domains.

DNS Security Gets Fixed When Someone Notices - Not Before

A study of 309 universities, museums and sports brands finds DNS security follows visible threats rather than technical risk, leaving organisations well protected against familiar attacks while quieter weaknesses in critical infrastructure persist unnoticed.

Phantom Squatting: When LLMs’ Hallucination Becomes an Attacker’s Best Friend

As AI reshapes cybersecurity, attackers are exploiting a fundamental weakness in large language models. Phantom squatting turns hallucinated domain names into trusted attack vectors, creating a new class of DNS abuse that defenders cannot solve by eliminating hallucinations alone.

Call for Participation: DNSSEC and Security Workshop at ICANN87 (21 October 2026)

ICANN is inviting proposals for its DNSSEC and Security Workshop at ICANN 87, offering experts and practitioners a platform to share insights on DNS security, routing security, browser security, and emerging Internet infrastructure challenges.

The 2024-2026 Root Zone KSK Rollover: Updates and Observations

Roughly a year and a half ago, Verisign and ICANN began the important, multi-year process of updating the cryptographic key that secures the authoritative DNS root zone. This work has been largely invisible to the public, but vital to the security of many everyday online activities.

Digital Sovereignty Is More Than Data Sovereignty: Understanding Africa’s Digital Dependency Stack

Africa's pursuit of digital sovereignty demands more than keeping data at home. True resilience depends on controlling the infrastructure, platforms, cybersecurity capabilities, governance, and human expertise that underpin an increasingly interconnected digital economy across Africa.

The Question Isn’t Whether the Harm Is Real - It’s Who Should Act

Measuring online abuse can reveal its scale, but not who should intervene. Effective policy must distinguish harm from contractual responsibility, identify the actors best placed to act, and target remedies where they can work effectively.

News Briefs

G7 Cyber Agencies Urge Immediate Post-Quantum Migration Planning

ICANN Terminates Two Registrars as DNS Abuse and Compliance Failures Escalate

ICANN’s New Data Sharpens the Picture of DNS-abuse Enforcement

NANOG 95: From Faster Fibre to Route Leaks, Operators Face Old Problems with New Tools

AWS Unveils Route 53 “Accelerated Recovery” to Bolster DNS Resilience

DNS Under Strain: Technical and Policy Challenges in Supporting the Internet of Autonomous Things

14th Registration Operations Workshop Set for September 30, 2025

The Edgemoor Research Institute and TWNIC Launch Project Jake to Advance DNS Security and Data Transparency

DNSSEC Failure Causes Massive Website Outages on Russian Internet

Analysis of 7.5 Trillion DNS Queries Reveals Public Resolvers Dominate the Internet

EU-based DNS Internet Infrastructure Beginning to Take Shape, Planned to Onboard 100 Million Users

DNS Abuse Institute Launches Centralized DNS Abuse Reporting Service

CENTR Publishes Comment on the European Commission’s DNS Abuse Study

InternetNZ Has Disclosed a Vulnerability That Can Be Weaponized Against Authoritative DNS Servers

Security Researcher Dan Kaminsky Has Died

PIR Launches New Institute to Combat DNS Abuse

DNSSEC Now Deployed in all Generic Top-Level Domains, Says ICANN

Firefox Starts the Roll Out of DNS Over HTTPS (DoH) by Default for US-Based Users

Microsoft Announces Plans to Adopt DoH in Windows

EFF: For ISPs to Retain Power to Censor the Internet, DNS Needs to Remain Leaky

Most Viewed

Security Researcher Dan Kaminsky Has Died

DNSSEC: Once More, With Feeling!

CircleID’s Top 10 Posts of 2017

Internationalizing the Internet

DNS, DNSSEC and Google’s Public DNS Service

Most Commented

WhoisXML API Updates – Sponsor

DNS Footprinting: SourTrade Distributes Unfinished Malware through Malvertising

DNS analysis of 96 SourTrade domains uncovered hundreds of connected domains and IP addresses, many flagged as malicious, while identifying indicators that appeared months before researchers formally linked them to the malvertising campaign. more

DNS Spotlight: 2026’s 5 Most Notorious Ransomware

DNS analysis of 84 network indicators tied to LockBit, Cl0p, Akira, Medusa, and Qilin uncovered thousands of connected domains and IP addresses, including additional artifacts already identified as malicious. more

A DNS Infrastructure Analysis of a Microsoft 365 Device Code Phishing Campaign

A DNS investigation into a Microsoft 365 device code phishing campaign uncovered coordinated, disposable infrastructure, including 290 indicators of compromise, 87 malicious IP addresses and hundreds of connected domains, suggesting the operation remains active. more

5 of the Biggest Cyber Attacks in 2026 So Far: DNS Deep Dive

A DNS deep dive into five major cyber attacks of 2026 uncovers infrastructure linked to Cisco, Ivanti, Stryker and ShinyHunters incidents, revealing hundreds of connected domains and IP addresses that could sharpen threat detection efforts. more

Massive Photo ZIP Campaign Targets Booking.com Partner and Other Hotels across Japan and Europe

A sprawling phishing campaign targeting hotels in Japan and Europe used deceptive photo ZIP files and legitimate web services to establish persistent access, while researchers uncovered thousands of potentially connected infrastructure artifacts and victim IP addresses. more

Global Domain Activity Trends Seen in Q2 2026

WhoisXML API's Q2 2026 analysis reveals rising domain registrations, shifting TLD rankings, growing DNS infrastructure concentration, and evolving malicious domain activity, based on billions of DNS records and millions of newly registered and confirmed malicious domains. more

APT37 Strikes Again, This Time with NarwhalRAT

North Korea's APT37 has launched a new NarwhalRAT campaign using spearphishing emails and malicious LNK files to deploy data-stealing malware. Researchers also uncovered infrastructure links and fresh indicators that expand the group's known operational footprint. more

Industry Updates

Participants – Random Selection