dns
99 articles with this tag
INFO
HIGH
HIGH
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
LOW
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
MEDIUM
INFO
INFO
MEDIUM
MEDIUM
HIGH
INFO
INFO
HIGH
INFO
INFO
INFO
HIGH
HIGH
MEDIUM
INFO
HIGH
HIGH
HIGH
HIGH
HIGH
INFO
HIGH
HIGH
HIGH
HIGH
MEDIUM
MEDIUM
HIGH
MEDIUM
MEDIUM
MEDIUM
MEDIUM
LOW
LOW
MEDIUM
HIGH
MEDIUM
HIGH
MEDIUM
MEDIUM
HIGH
HIGH
INFO
LOW
HIGH
HIGH
HIGH
HIGH
HIGH
HIGH
LOW
HIGH
HIGH
INFO
HIGH
INFO
HIGH
HIGH
HIGH
INFO
INFO
MEDIUM
MEDIUM
MEDIUM
HIGH
HIGH
MEDIUM
HIGH
MEDIUM
INFO
INFO
MEDIUM
MEDIUM
HIGH
MEDIUM
Infoblox joins crowded EASM market with DNS-centric approach
[NEU] [mittel] Unbound: Mehrere Schwachstellen
CVE-2026-55973 'dns-error-reporting: yes' leads to stack buffer overflow
CVE-2026-44687 Off-by-one error in 'harden-below-nxdomain' logic can shadow a stub/forward zone by a legitimate parent's NXDOMAIN
CVE-2026-50248 BOGUS configured primary hostname accepted for XFR in auth/rpz zones
CVE-2026-55717 'serve-expired-client-timeout' and 'response-ip' CNAME redirect could lead to a crash
CVE-2026-40691 Packet of death for DNSCrypt over TCP
CVE-2026-32665 Remote DNS-over-QUIC denial of service due to `quic-size` budget bypass
CVE-2026-46582 A wildcard replay, as another piece of data, triggers poisoning in the serve expired reply path
CVE-2026-42955 Extra fix for CVE-2026-40622 to also clamp the TTL of A/AAAA records disallowing a one-time 'ghost domain' delegation renewal via glue records
CVE-2026-50046 Possible heap use-after-free in an error path when a DoT forwarded query is jostled out
CVE-2026-55990 Packet of death for a DNSCrypt misconfigured Unbound
CVE-2026-55991 Remote DNS-over-QUIC (DoQ) flow-control assertion failure in libngtcp2
CVE-2026-50251 Attacker supplied '0.0.0.0'/'::' glue triggers defensive full-cache flush
CVE-2026-50252 Possible cache poisoning attack by mapping source port population per thread
CVE-2026-50243 'response-ip'/'rpz' can rewrite BOGUS answers instead of returning SERVFAIL
CVE-2026-62994 CoreDNS `k8s_external` headless AXFR can emit an empty transfer batch that panics the `transfer` plugin
CVE-2026-50045 'max-global-quota' reset by DNSSEC validation restarts
CVE-2026-44690 Cross-zone wildcard cache poisoning via RRSIG.labels manipulation
CVE-2026-56416 Possible heap buffer overflow when validator canonicalizes RDATA that contains domain name
CVE-2026-56444 Degradation of resolution service when 'discard-timeout' and 'serve-expired-client-timeout' are combined in unusual configuration
CVE-2026-54478 DNS Cookie bypass when combined with proxy-protocol use
CVE-2026-41637 Degradation of resolution service from improperly accounted client-terminated DNS-over-QUIC queries
TrickBot variant uses DNS tunneling for command and control
Cloudflare Internal DNS is now generally available
Keeping private namespaces private - Quad9 blog
Telegram's t.me short-link domain inaccessible globally
CVE-2026-50495 DNS Client Tampering Vulnerability
CVE-2026-49169 Windows DNS Server Remote Code Execution Vulnerability
Censys Internet Map links real-time DNS data to internet infrastructure
Playing Around With ADIDNS RPC Internals
Playing Around With ADIDNS RPC Internals
Encrypted DNS still tells an eavesdropper where to look
Threat tactic spotlight: Subdomain takeover
Cloudflare DMARC Management is now generally available
RHSA-2026:24934: Important: bind9.18 security update
RHSA-2026:25214: Important: bind security update
CVE-2026-10846 Insufficient verification that responses belong to a query
RHSA-2026:25083: Important: bind9.16 security update
RHSA-2026:24368: Important: bind9.18 security update
RHSA-2026:24339: Important: bind security update
RHSA-2026:24338: Important: bind security update
RHSA-2026:23360: Important: bind9.16 security update
RHSA-2026:23231: Important: unbound security update
DNS-AID will make AI agents easier to discover, says Linux Foundation
‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains
CVE-2026-3039 BIND 9 server memory exhaustion during GSS-API TKEY negotiation
CVE-2026-3593 Heap use-after-free vulnerability in BIND 9 DNS-over-HTTPS implementation
CVE-2026-5946 Invalid handling of CLASS != IN
CVE-2026-5950 Unbounded resend loop in BIND 9 resolver
CVE-2026-5947 SIG(0) validation during query flood may lead to undefined behavior
USN-8293-1: Bind vulnerabilities
Multiples vulnérabilités dans ISC BIND (21 mai 2026)
CVE-2026-42960 Possible cache poisoning via promiscuous records for the authority section
CVE-2026-44608 Use after free and crash under special conditions in RPZ code
CVE-2026-42923 Degradation of service with unbounded NSEC3 hash calculations
CVE-2026-41292 Long list of incoming EDNS options degrades performance
CVE-2026-42534 Jostle logic bypass degrades resolution performance
CVE-2026-40622 Another 'ghost domain names' attack variant
CVE-2026-42944 Heap overflow with multiple NSID, COOKIE, PADDING EDNS options
Multiples vulnérabilités dans ISC BIND (20 mai 2026)
RHSA-2026:18786: Important: bind security update
RHSA-2026:18931: Moderate: unbound security update
CVE-2026-42304 Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
Six new dnsmasq vulnerabilities open the door to DNS cache poisoning, local root
RHSA-2026:15890: Important: bind security update
CVE-2026-6238 Buffer overread in ns_printrrf with corrupted RDATA field
CVE-2026-5435 Potential buffer overflow in ns_sprintrrf TSIG handling path
DSA-6235-1 dnsdist - security update
DSA-6234-1 pdns-recursor - security update
DSA-6233-1 pdns - security update
RHSA-2026:11371: Important: bind security update
RHSA-2026:11372: Important: bind security update
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse
CVE-2026-1519 Excessive NSEC3 iterations cause high CPU load during insecure delegation validation
Russia Hacked Routers to Steal Microsoft Office Tokens
Russia's Fancy Bear still attacking routers to boost fake sites, NCSC warns
Our ongoing commitment to privacy for the 1.1.1.1 public DNS resolver
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse
Week in review: NIST updates DNS security guidance, compromised LiteLLM PyPI packages
DSA-6181-1 bind9 - security update
BIND Updates Patch High-Severity Vulnerabilities
[NEU] [mittel] Internet Systems Consortium BIND: Mehrere Schwachstellen
NIST updates its DNS security guidance for the first time in over a decade
The one BIG mistake you are making with DNS security today
The one BIG mistake you are making with DNS security today
AWS Bedrock’s ‘isolated’ sandbox comes with a DNS escape hatch
Security Flaw in AWS Bedrock Code Interpreter Raises Alarms
[UPDATE] [mittel] Internet Systems Consortium BIND: Mehrere Schwachstellen ermöglichen Denial of Service
Hackers Exploit .arpa and IPv6 Infrastructure to Evade Phishing Defenses
Hacker abusing .arpa domain to evade phishing detection, says Infoblox
Internet Infrastructure TLD .arpa Abused in Phishing Attacks
Hackers abuse .arpa DNS and ipv6 to evade phishing defenses
UK govermnent's Vulnerability Monitoring System is working - fixes flow far faster
Is It Always DNS? Wireshark Packet Analysis
Microsoft Warns of ClickFix Attack Abusing DNS Lookups
New ClickFix attack abuses nslookup to retrieve PowerShell payload via DNS
[UPDATE] [hoch] Internet Systems Consortium BIND: Mehrere Schwachstellen
[UPDATE] [mittel] Unbound: Schwachstelle ermöglicht Manipulation von Dateien