#dns
104 posts · Last used 6d
An agent used DNS to reach an external chatbot
https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot/
Comments: https://news.ycombinator.com/item?id=49853137
#HackerNews #DNS #chatbot #agent #external #AI #cybersecurity
Quiz time: which of these domains is impersonating Apple?
quizearny[.]shop, rewardquiz[.]org look like generic quiz sites. applerewards[.]net is more obvious. All of them belong to a cluster serving identical Apple impersonation content, prompting victims to claim an Apple gift card reward by handing over their personal details. testar[.]ink, "to test", was the first to be created, nearly a month before the others went live, which may say something about how this campaign got started.
What makes this cluster more interesting is what happens after you click the "Claim Your Apple Reward" button on the initial page. Different locations, different device types, different destinations. Classic TDS.
This cluster is a good reminder that brand impersonation lives in the page content, not just the domain name. A quiz site with no Apple in its name can be just as dangerous as an obvious lookalike.
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #axur #lookalike #scam #tds
validx[.]shop looked fine at first glance. "Normal" name servers, a real mail setup, nothing that immediately stood out at the apex level. One subdomain didn't quite fit, though. It was getting DNS queries that were absurdly long and frequent for a new domain that nobody was really visiting. Rather than that being web traffic, we detected it as likely tunneling.
Turns out it wasn't a one-off. The same setup shows up on hundreds of other domains.
The domain names follow a similar pattern: short, brandable and portmanteau-y (i.e., cordkit, zenithly, queuebox), spread across a long list of cheap gTLDs with the same registrar.
The tunnel itself is answering with TXT records like:
⚠️ "H2;n=5;k=3;ol=2004;sz=800;cz=gz"
As best as we can tell, that's a shard count, a reconstruction threshold, a length, a chunk size, and a compression flag. We checked the signature against a number of known DNS tunnelling tools and none of them write a header like this.
We watched two more domains get registered mid-investigation, hours apart, which was fun to see and immediately block
We've got the infrastructure and the method. We haven't got a payload, and we haven't matched this header format to anything documented publicly.
Has anyone else run into this, recognize the TXT format above, or have a sample of a possible malware source? We'd like to hear from you.
⛔ validx[.]shop
⛔ cordkit[.]online
⛔ zenithly[.]best
☠️ 95[.]179[.]159[.]229
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #c2
Replying to on mastodon.social
@h4ckernews@mastodon.social it's always #dns
I'll block a whole .tld, I don't give a fuck
#dns
RE: https://mastodon.social/@rdns/117309938052519979
A nice update!
How can one support you through Monero?
🤍 Thank you!
#dns #donation #donate
Quoting
RE: https://mastodon.social/@rdns/117303649570373025
v057 is here.
RPN screens sport cute Dolphins 🐬 chilling about... Speaking of RPN, we're winding down the offer on monthly plans ($2.5/mo -> $3/mo) in the coming days. Not 'cause we want more $$$ (which we do); but 'cause we can't afford it any longer.
Hopefully, y'all don't encounter any major bugs.
Intend to release v057 for Android TV. Not sure exactly when, but before Nov ends.
Website: https://rethinkdns.com/download
GitHub: https://github.com/celzero/rethink-app/releases/tag/v0.5.7
Reddit: https://www.reddit.com/r/rethinkdns/comments/1wmd96r/v057_redise%C3%B1ada/
Open quoted postSolicitar senha. Solicitar token. Token inválido. Aguardar.
That's the full operator menu for VX-Pack — a Brazilian-origin AiTM phishing-as-a-service kit targeting banks in Brazil and Portugal. Request password. Request token. Invalid token (ask again). Wait. One operator, one victim, one browser, in real time.
Nearly every AiTM kit — Evilginx, Tycoon 2FA, EvilProxy — is a reverse proxy. It silently relays traffic to the real bank, grabs the session cookie, and that's your 2FA bypass. VX-Pack is a different animal: a replica site, not a relay. The operator watches the victim fill each field over a WebSocket connection, replays the credentials against the real bank themselves, and if the OTP expires mid-attempt — tokeninvalido — the kit asks the victim for another one.
No session cookie theft. No relay fingerprint at the bank. The bank's anti-proxy controls see traffic from the operator's own machine. "It passed the bank's fraud detection" is not the assurance it sounds like.
Active since at least January 2025, sold as PhaaS by one developer to multiple buyers running their own campaigns. Impersonates Banco Santander and more than ten other financial institutions and payment platforms across Brazil and Portugal.
Screenshots below show one of the phishing pages impersonating Banco Santander, as well as screenshots from a walkthrough video recorded by the kit's developer. Victim flow on one side, operator panel on the other.
Phishing domains:
⛔️ pactualapp[.]com
⛔️ pactualpj[.]com
⛔️ pactual[.]live
⛔️ ativarbia[.]net
⛔️ ativarbia[.]com
⛔️ pactualapp[.]live
⛔️ centraldecancelamentos[.]pt
⛔️ verificador-cliente[.]live
⛔️ ativador-login[.]click
#dns #threatintel #threatintelligence #cybercrime #cybersecurity #infosec #infoblox #infobloxthreatintel #phishing #aitm
Boosted by @welcome@friends.deko.cloud
Hello. We make DNS Notify. It emails you when a DNS record, nameserver set, TLS certificate or domain registration changes, and shows the old value next to the new one.
We built it for our own domains first. Most of the work went into the email it does not send: TTL changes, rotated answers, SOA serial bumps and routine renewals all stay quiet.
The scanner and lookups are free, no account: https://dnsnotify.com
#DNS #sysadmin #introduction
Replying to
@daniel@gultsch.social Ich habe in deinem Vortrag die Abhängigkeit des #XMPP Ökosystems von #DNS vermisst, derren Root-Server von #Trump abhängig sind.
The Internet Last Week
- Central Asia regional connectivity https://labs.ripe.net/author/anastasiya-pak/capif-5-regional-interconnectivity-in-central-asia/
- DNSSEC-anchored stateless encrypted auth DNS https://arxiv.org/abs/2609.14210
- Router compromise walk-through https://blog.j2sw.com/netops/mikrotik-router-compromise-forensic-walkthrough/
- Russia changed domain name registration rules https://riposte.levelflow.org/2026/09/rururu/
- Weaponizing digital choke points https://www.foreignaffairs.com/china/new-chinese-way-cyberwar-ai
Boosted by @trending@homestead.social
We recently published our LLM policy, requiring all code and documentation contributions to be authored by a human. We do accept reports of vulnerabilities found with LLMs.
It has drawn a lot of feedback, both positive and negative. In this article we want to explain the background and motivation behind our choices.
#OpenSource #DNS #BGP #RPKI #softwaredevelopment
https://blog.nlnetlabs.nl/maintaining-the-love-for-coding-in-the-time-of-ai/
1.1.1.1 prüft DNS jetzt mit Post-Quanten-Kryptografie
Cloudflare hat ML-DSA-44-Validierung für seinen DNS-Resolver 1.1.1.1 aktiviert. Das soll DNS-Antworten vor Quanten-Angriffen schützen.
https://www.heise.de/news/1-1-1-1-prueft-DNS-jetzt-mit-Post-Quanten-Kryptografie-11453315.html?wt_mc=sm.red.ho.mastodon.mastodon.md_beitraege.md_beitraege&utm_source=mastodon
#DNS #DNSSEC #IT #NIST #Quantencomputer #RSA #Security #news
Replying to
Ah well, unbound prepared for the toggle.
# Mullvad No-Filter DoT
forward-addr: 194.242.2.3@853#dns.mullvad.net
# AdGuard Default Ad-Blocking DoT
forward-addr: 94.140.14.14@853#dns.adguard-dns.com
#Quad9 DoT
#forward-addr: 9.9.9.9@853#dns9.quad9.net
#Quad9 no threatblocker DoT
#forward-addr: 9.9.9.10@853#dns10.quad9.net
Boosted by @Dragofix@veganism.social
At the core of the global internet are the DNS root servers. These 13 go-to places are at the top of authority when it comes to making sure you can connect to any server with a domain name. What you might not know is that 10 of these 13 root servers are ultimately under US jurisdiction. Should that worry you? I guess not, the current system is quite robust. But I deal in risk assessment and probabilities. And I think this isn't an ideal setup.
https://en.wikipedia.org/wiki/Root_name_server
#DNS #Centralisation
Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy
Cybercriminals are exploiting legitimate Google infrastructure in a sophisticated phishing operation that bypasses email security gateways and enterprise firewalls. The attack chains together six distinct Google properties including Meet, Search, DoubleClick, Custom Search, Tag Manager and Analytics to proxy malicious traffic through trusted domains. Victims' email addresses are encoded in URL fragments and stripped before server-side logging. Landing pages dynamically impersonate target organizations by pulling live logos from Clearbit, capturing real-time website screenshots, and validating domains via Google's DNS API. The operation includes multilingual support for 16 languages and dual execution tracks: credential harvesting with immediate Telegram exfiltration, or silent ScreenConnect remote access tool installation. Lures span document reviews, credential expiry notices, package delivery, payment notifications, government benefits and voicemail themes targeting manufacturing, government, finance and...
Pulse ID: 6a9ef40735b49c55dc7166c9
Pulse Link: https://otx.alienvault.com/pulse/6a9ef40735b49c55dc7166c9
Pulse Author: AlienVault
Created: 2026-09-07 17:27:35
Be advised, this data is unverified and should be considered preliminary. Always do further verification.
#CredentialHarvesting #CyberSecurity #DNS #DoubleClick #Email #Google #Government #ICS #InfoSec #Manufacturing #OTX #OpenThreatExchange #Phishing #Proxy #RAT #Rust #ScreenConnect #Telegram #bot #AlienVault
Boosted by @trending@homestead.social
In the light of recent events, I've been trying to work out if country-specific top level domain names (ccTLDs) are controlled by the US government, but it is frustratingly opaque.
All domains including ccTLDs are controlled by the Internet Assigned Numbers Authority (IANA), a US organisation which is controlled by a US corporation called Public Technical Identifiers (PTI). PTI is "an affiliate" of the Internet Corporation for Assigned Names & Numbers (ICANN).
🧵 Thread page 1 of 3
#DNS #ccTLD
So...
What _would_ happen if, say, Montenegro (the country behind ".me” -- https://domain.me/about-me/) decides to get the attention of the US and suspend id.me, which is used for logging in at a ton (most?) of federal and state websites?
https://id.me/government?source=wallet-homepage-v2
It would be no more unilateral than the autistici.org domain being suspended out of fear of US legal threats, or certain M365 accounts being disabled as a result of US sanctions, surely?
#me #DNS #Chaos #AutisticiInventati
🔗 Mullvad will shut down public DNS servers and sponsoring Quad9 instead
MIGRATING
🔗 If you use MullvadDNS, you must switch before November 2, 2026.
You can manually configure the DNS of your choice
🔗 quad9
🔗 NextDNS
🔗 AdGuard
~
#cybersecurity #privacy #dns #technews



