‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale

https://www.securityweek.com/wp-content/uploads/2024/02/DNS.jpeg

A ‘dangling DNS takeover’ is a known attack method that allows a bad actor to take over a subdomain whenever a DNS record points to a cloud resource after the resource has been deleted. The link is left ‘dangling’, pointing to nothing. It is a simple case of poor security hygiene, but not uncommon.

If an attacker can find that link – which is not difficult with internet scans – and reconstruct the cloud resource but now under his own control, he can then gain access to the subdomain. Historically, the attack has primarily been used by cybercriminals for financial gain.

Security firm Silent Push asked itself, “What if we looked at it the same way a trained nation-state attacker would?” Nation states prioritize the generation of chaos and disruption over monetization; and have a new tool at their disposal – artificial intelligence. The result of its consequent researchhas...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE

Read more