#dns

83 posts · Last used 3d

Back to Timeline
Infoblox Threat Intel @InfobloxThreatIntel@infosec.exchange · 3d ago
Season's Scammings 🔅 🎄 We've been tracking a cluster of personal loan phishing sites that work hard to look like independent lenders — different brands, different domains, even deliberately varied infrastructure. Look closely enough, though, and the seams show. Similar underlying templates. The same technology stack. And passive DNS tying their thousands of domains back to the same operator. The sites present as loan applications. Name, address, employment details, financial history. And then, at the final step: your Social Security Number. No real company name. No regulatory disclosure. Just a form — and your most sensitive personal data sent off to who-knows-where for who-knows-what. A significant portion of the domains are seasonal — Christmas cash, Thanksgiving funds, Black Friday loans. Financially stretched consumers, at exactly the moment they're most likely to reach for a quick fix. ⛔ mychristmaswallet[.]com ⛔ cashzillaloans[.]com ⛔ personalreliefwallet[.]com ⛔ thanksgivingcash-5k[.]com ⛔ christmascashhelp-direct[.]com #dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #scam
0
0
0
Tobias Schmidl @schtobia@sueden.social · Aug 04, 2026
E-Mail und #DNS. Liebs einfach. 🙄 SPF, DKIM, DMARC. Alles so super. Und halt auch gar kein Druck dabei.
0
0
0
Ryan Castellucci (they/them) :nonbinary_flag: @ryanc@infosec.exchange · Aug 03, 2026
DNS knows where it is because it knows where it isn't: LOC records #DNS
0
1
0
Bjoern @zempelitsecurity@infosec.exchange · Aug 03, 2026
🔒 Neues Wissen, mehr Sicherheit! 🎓 Ich habe die Masterclass „DomainSecurity“ der InterNexum GmbH erfolgreich absolviert! 🎉 📌 Was wurde gelernt? ✔ Grundlagen Domainmanagement & DNS ✔ E-Mail-Authentisierung (SPF, DKIM, DMARC) ✔ E-Mail-Transport-Sicherheit (MTA-STS, TLS-RPT, DANE) ✔ DNS-Sicherheit (DNSSEC, CAA, TLSA) ✔ BIMI für vertrauenswürdige E-Mails 💡 Und das Beste? Dieses Wissen wird bei Zempel IT Security bereits eingesetzt, um den eigenen E-Mail-Verkehr bestmöglich abzusichern – für mehr Schutz vor Phishing, Spoofing & Co.! 🚀 Sicherheit ist kein Zufall, sondern das Ergebnis von Wissen und Umsetzung. https://zempel-itsecurity.de/home/zis-blog/33-neues-wissen,-mehr-sicherheit-bj%C3%B6rn-zempel-erfolgreich-in-domainsecurity-zertifiziert #DomainSecurity #EmailSecurity #ZempelITSecurity #Cybersecurity #DNS #DMARC #ITSecurity #KnowledgeIsPower
0
0
0
adminForge :cloud: @adminforge@kanoa.de · Aug 01, 2026
0
0
0
jpmellojr @jpmellojr@noc.social · Jul 29, 2026
Hotel & café Wi-Fi under attack: DNS poisoning campaign redirects users to malicious sites, exposing credentials and traffic. https://jpmellojr.blogspot.com/2026/07/dns-poisoning-campaign-targets.html #ReliaQuest #DNS #Infosec #WiFiSecurity
1
1
0
The Spamhaus Project @spamhaus@infosec.exchange · Jul 30, 2026
Replying to @spamhaus@infosec.exchange
Your help in draining the swamp of orphaned internet infrastructure prone to abuse is greatly appreciated – every deleted dangling DNS record helps! 🙏 #TicketDeskTales #DomainReputation #Cybersecurity #DNS 3/3
0
0
0
indigoprivacy @indigoprivacy@infosec.exchange · Jul 29, 2026
Pi-hole is free, open-source software that blocks ads and trackers at the DNS level for every device on your network — including the TVs, thermostats, and doorbells that can't run a browser extension. It runs on a Raspberry Pi; a Pi 4 with 1GB is about $35. DNS blocking only: no firewall, no intrusion detection. #pihole #raspberrypi #dns #privacy #indigoprivacy
0
0
2
JTI @jti42@infosec.exchange · Jul 28, 2026
Looks like Flatpak discovery will move from one mostly generally accepted hub to a gazillion of repos since the performative LLM complaints have befallen the possible single hub. (Partially half-understandable arguments, partially performative fluff for my taste) Which is ok as it triggers competition that might lead to better outcomes. (bazaar vs cathedral and all, rite? 😏 ) And removes a possible single point of failure. Now what I'd like to see is an approach that does discovery of those repos and enables search across those repos without a single point of failure. As e.g. a single, centrally hosted index for repos to register to would be. Flatpak already uses a reverse-dns-namespace structure internally. Anything that would leverage that? Wouldn't help with enumeration though. Something something DHT/Gossip/...? (as the cool thing from the past) Clearly a problem that will arise with more of the expectable decentralized systems that need uniform discovery and search. What's the Fedis wisdom on current academic approaches that might be interesting around this? Or bastardized routing tech, yet another idea on how to twist DNS into a pretzel, etc? Dare I say: Blockchain (as the unpopular thing before the LLMs 🤣 ) Throw you best Arxiv posts etc. at me. I'm just curious about the state-of-the-art techn for now, all smirk and sarcasm aside. #discovery #search #decentralized #routing #dns #fedimeta #flathub #dht #cooltechfromthepast #llm #selfhosting #fossdrama #spof #singlepointoffailure
3
0
2
ARGVMI~1.PIF @argv_minus_one@mastodon.sdf.org · Jul 28, 2026
Out of curiosity, are there any nonprofit #DNS hosting providers these days? I was nostalgiaing about DynDNS and Monolith back in the day. Sadly, the latter closed up shop, and the former slowly turned into a for-profit business and then sold to Oracle.
2
0
0
Erlaan :verified: @erlaan@infosec.exchange · Jul 27, 2026
Hosting your own mailserver? It easy sometimes sometimes you sitting there trying to figure why the hell will Microsoft only connect and then quit. And not sending without any change to the mail-server. Updating the server looking through the config. Looking at the certificate. And nothing. And starting to think that Microsoft is a shit mail company. Because google, yahoo and every other service i tried to send to my own server worked. Everyone else will send to my server. And I have one that send email to me that use Microsoft. After a few hours troubleshooting. I finely found the problem. Drum role ..... IT was the DNS!! 😂 #selfhosting #DNS #DNSSEc #DANE #alwaysdns
0
1
0
John Kristoff @jtk@infosec.exchange · Jul 27, 2026
#DNS root servers on an observed June 2026 traffic increase: "[...] a representative from the AS responded on July 3rd. They confirmed that the traffic originated from their networks (i.e., was not spoofed) and was the uninten4onal result of recent recursive resolver software updates." https://root-servers.org/media/news/2026-06-29-increase.pdf
10
1
6
:tor: Sicurezza Digitale @sicurezza@mastodon.uno · Jul 27, 2026
Cerchi un DNS pubblico gratuito per migliorare privacy, sicurezza o filtrare contenuti indesiderati? Ecco un confronto rapido tra alcuni dei provider più conosciuti e le funzionalità di filtraggio che offrono. 😎👇️ Scegliere un DNS significa decidere a chi affidare una parte della propria navigazione. Per chi ha a cuore la libertà digitale e la tutela della #privacy, vale la pena confrontare le alternative a #Google. 📖 Per le infografiche e news sulla sicurezza informatica: @sicurezza@diggita.com #dns
0
7
33
The New Oil @thenewoil@mastodon.thenewoil.org · Jul 26, 2026
1
2
3
kravietz 🦇 @kravietz@agora.echelon.pl · Jul 26, 2026
A sad lesson from a few years of operating local #DNS resolvers in my infrastructure - #DNSSEC validation requires enormous resources to work reliably due to vast extra records it needs to pull from DNS for each validation and required computing power. Forget about DNSSEC validation in systemd-resolved, dnsmasq or unbound on home routers, it will just cause periodic and apparently unexplained delays and choke overall DNS resolution. On firewalls like #OPNsense it also would work only server-class devices, any of the desktop-class fanless hardware won’t work reliably for DNSSEC validation even if they can perfectly handle production-class proxy and firewall traffic. Probably what only makes sense is a dedicated Unbound validation server, a separate container or jail but running within a proper hardware server with tons of memory and CPU. But then I found out that it’s much easier to use non-DNSSEC caching resolvers on perimeter devices that forward queries to Quad9 ECS resolvers[^1] which already do DNSSEC validation. The only missing bit is that I think my local resolvers don’t forward the DO bit downstream, but that I need to still check. [^1]: https://quad9.net/service/service-addresses-and-features/#ecssec
0
1
0
Cloud 🤖 @cloud@infosec.exchange · Jul 25, 2026
🤖 Hackers are tampering with DNS settings on hotel/conference Wi-Fi equipment to redirect guests to fake Microsoft 365 login pages. The attack captures authentication tokens, enabling account takeover without bypassing MFA. 🔗 https://www.bleepingcomputer.com/news/security/hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accounts/ #CyberSec #Phishing #DNS #MFA #InfoSec
0
0
0
matthew - retroedge.tech @matthew@social.retroedge.tech · Jul 24, 2026
Federated protocols of the future should consider designing themselves so that even if they use DNS, it is not the foundation of their own identity system so they are not hopelessly bound to it. Federated networks which have message relaying capability such as Bitcoin or BGP can also span across different networks such as cjdns, Yggdrasil, I2P and of course the outside internet. https://thegoodwork.substack.com/p/the-next-internet-war #federated #DNS #Internet
0
0
0