news.mlab.sh
21 results
threat-intel

Obfuscating IP Addresses as Hostnames, (Tue, Aug 25th)

Attackers are increasingly using hostname-based IP address obfuscation, specifically leveraging services like 1u.ms to bypass security measures. This tactic is used to exploit vulnerabilities like Server Side Request Forgery (SSRF) and requires careful monitoring of DNS logs and blocklists.

SANS Internet Storm Center · 5d ago Medium
threat-intel

Hacking Public Wi-Fi DNS to Steal Credentials

Attackers are exploiting vulnerabilities in public Wi-Fi networks to hijack DNS settings, leading to users being redirected to fraudulent login pages and having their credentials stolen. This technique bypasses standard…

Schneier on Security · Aug 17, 2026 Medium
threat-intel

Almost Half of Malware Samples Communicate Direct to IP

Almost half (45.32%) of malware samples with Command & Control (C2) activity bypass DNS entirely, communicating directly to IP addresses. This behavior, known as D2IP, is prevalent across various threat types, including…

Palo Alto Unit 42 · Aug 4, 2026 High
threat-intel

More Odd DNS Records: NIMLOC, (Tue, Jul 7th)

This article discusses the continued use of NIMLOC DNS records, an obsolete record type originally designed for the Nimrod routing architecture. Despite the demise of NetBIOS and the shift to modern DNS and SMB protocols…

SANS Internet Storm Center · Jul 7, 2026 Info
threat-intel

RCS and DNS: The NAPTR Record, (Mon, Jul 6th)

This article details the observation of NAPTR records being utilized in RCS (Rich Communication Services) communications, specifically within Verizon’s network. NAPTR records, defined in RFC 2915, are typically used to r…

SANS Internet Storm Center · Jul 6, 2026 Medium