Security News

Cybersecurity news aggregator

CRITICAL Updates SC Media

Cloudflare adds post-quantum DNSSEC validation to 1.1.1.1

The article describes an active attack chain targeting MikroTik routers that exploits two critical vulnerabilities: CVE-2026-67276, an SSH authentication bypass, and CVE-2026-86060, an SSH session privilege escalation, with a combined CVSS score of 9.8. According to NVD data, affected versions are MikroTik RouterOS 6.0 to 6.49.20, 7.0 to 7.23.3, and 7.24 to 7.24.1. The fixed versions are RouterOS 6.49.21, 7.23.4, and 7.24.2.
Read Full Article →

Network Security Cloudflare adds post-quantum DNSSEC validation to 1.1.1.1 September 14, 2026 Share By SC Staff (Adobe Stock) As noted by Cyber Insider, Cloudflare has taken a significant step towards future-proofing the internet's domain name system by adding support for post-quantum DNSSEC signature validation to its 1.1.1.1 public DNS resolver. This move is an early measure to protect DNS from potential threats posed by quantum computing. Cloudflare is now validating signatures created with ML-DSA-44, a post-quantum algorithm standardized by NIST. This allows for testing post-quantum DNSSEC at internet scale before quantum computers can break current public-key cryptography. DNSSEC is crucial for preventing attackers from forging DNS responses and redirecting users to malicious sites. Cloudflare's 1.1.1.1 resolver checks cryptographic signatures to ensure DNS records are unaltered. A major challenge is the size of ML-DSA-44 signatures, which are significantly larger than current ones, potentially causing issues with UDP packet limits and requiring TCP retries. Another concern is avoiding downgrade attacks during the transition, where older signatures could be exploited. Cloudflare addresses this by requiring a valid post-quantum validation path if DS records indicate ML-DSA-44 support. Broad deployment will require support across the entire DNS hierarchy, with Cloudflare aiming for full post-quantum security by 2029. Users of 1.1.1.1 do not need to take any action, as the validation is applied automatically. Source: Cyber Insider An In-Depth Guide to Network Security Get essential knowledge and practical strategies to fortify your network security. Learn More SC Staff Related Network Security Web DDoS attacks more than double in 1st half of 2026, Radware report finds SC Staff September 9, 2026 The Radware H1 2026 Global Threat Analysis Report indicates a significant shift in attack methods, with direct-path volumetric floods, particularly stateless UDP floods, now comprising 73% of mitigated packets. Network Security F5 BIG-IP malware hides web shells in memory to evade detection Steve Zurier September 9, 2026 Memory-resident malware targeting F5 BIG-IP appliances can evade file-based security defenses. Network Security MikroTik routers targeted by active SSH zero-day exploitation SC Staff September 8, 2026 The MikroTrick attack chain exploits two critical vulnerabilities: CVE-2026-67276, an SSH authentication bypass, and CVE-2026-86060, an SSH session privilege escalation. Related Events Cybercast Network security: Adaptive defense, SASE, and micro-segmentation Tue Oct 13 Cybercast How to transform your SOC through XDR and MDR On-Demand Event Cybercast AI for network security: Problems and solutions On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Berkeley Internet Name Domain (BIND) Broadcast Cache Poisoning Call Admission Control (CAC) Circuit Switched Network Decapsulation Distance Vector Domain Domain Name Domain Name System (DNS) You can skip this ad in 5 seconds

Share this article