Cybersecurity |
Sponsored by |
|
CircleID recently interview Paul Vixie, Founder & Chairman of Internet Software Consortium (ISC), to discuss ISC's newly formed Operations, Analysis, and Research Center (OARC). OARC is launched in response to DDoS attacks at the Internet's core infrastructure and the vital requirement for a formal coordination system. OARC is also a part of US homeland security initiatives, such as the formation of Information Sharing and Analysis Centers (ISACs).
"Registries and registrars, ccTLD operators, large corporate NOCs, ISPs and ecommerce companies that host many domain names are all likely candidates. This is also a natural for law enforcement groups that are worried about attacks on the Internet." more
The Internet Corporation for Assigned Names and Numbers (ICANN) has released an "Advisory" concerning VeriSign's deployment of DNS wildcard (Site Finder) service: "Since the deployment, ICANN has been monitoring community reaction, including analysis of the technical effects of the wildcard, and is carefully reviewing the terms of the .com and .net Registry Agreements. In response to widespread expressions of concern from the Internet community about the effects of the introduction of the wildcard..." more
Some individual appears to have hijacked more than a 1,000 home computers starting in late June or early July and has been installing a new Trojan Horse program on them. The Trojan allows this person to run a number of small websites on the hijacked home computers. These websites consists of only a few web pages and apparently produce income by directing sign-ups to for-pay porn websites through affiliate programs. Spam emails messages get visitors to come to the small websites.
To make it more difficult for these websites to be shut down, a single home computer is used for only 10 minutes to host a site. After 10 minutes, the IP address of the website is changed to a different home computer... more
A recent study by researchers at the Cooperative Association for Internet Data Analysis (CAIDA) at the San Diego Super Computer Center (SDSC) revealed that a staggering 98% of the global Internet queries to one of the main root servers, at the heart of the Internet, were unnecessary. This analysis was conducted on data collected October 4, 2002 from the 'F' root server located in Palo Alto, California.
The findings of the study were originally presented to the North American Network Operators' Group (NANOG) on October 2002 and later discussed with Richard A. Clarke, chairman of the President's Critical Infrastructure Protection Board and Special Advisor to the U.S. President for Cyber Space Security. more
Recently, I entered my domain name in a "WHOIS" database query to test the results of the database by using WHOIS on a number of domain name registrar websites. WHOIS is a database service that allows Internet users to look up a number of matters associated with domain names, including the full name of the owner of a domain name, the name of the domain name hosting service, the Internet Protocol or I.P. number(s) corresponding to the domain name, as well as personally identifying information on those who have registered domain names. I was astonished to find... more
G7 cybersecurity agencies are pressing governments and organizations to inventory cryptographic dependencies and accelerate post-quantum migration as long transition timelines and future quantum attacks threaten Internet security infrastructure. more
Authorities disrupted the decades-old Sality botnet by targeting its decentralized peer-to-peer network and supporting domains, cutting infected machines off from malicious payloads while beginning the longer task of identifying and remediating compromised systems. more
Dangling DNS records can expose trusted corporate subdomains to takeover, while AI-assisted reconnaissance makes abandoned resources easier to find, increasing the need for continuous DNS monitoring rather than periodic audits. more
FulcrumSec claims it stole 86 GB from Manchester Airports Group, including detailed booking and travel data, while the operator has confirmed a breach but not the group's account of its scale or method. more
Estonia's data embassy model offers African governments a different approach to digital sovereignty, combining cross-border infrastructure, legal safeguards and geographic redundancy to keep critical state systems secure, recoverable and operational during major disruptions. more
ICANN has terminated two registrar accreditation agreements after unresolved compliance failures, citing Trustname's handling of DNS abuse and IPIP's failures involving RDAP, registration data escrow, accreditation fees, and access to non-public registration data. more
More than 100 organizations are calling for wider use of AI in cyber defense, urging governments, technology providers and AI developers to expand funding, tools, model access and practical support for under-resourced critical infrastructure operators. more
IPv6 solves the Internet's address shortage and simplifies networking, but its technical elegance may carry a hidden cost: shifting privacy protections from architectural constraints toward policies controlled by Internet providers, corporations and governments. more
Britain's cyber agency warns that attackers are increasingly targeting internet-exposed industrial systems, routers and other edge devices, with some intrusions causing real-world disruption and highlighting the growing risks of poorly secured operational technology worldwide. more
Publishing a DMARC record is only the beginning. New data show that many domains lack enforcement or reporting, exposing a gap between adopting email authentication and operating it effectively enough to detect problems and deter impersonation. more