{
  "version": "https://jsonfeed.org/version/1.1",
  "title": "News tagged “dns-security” · tldlog",
  "home_page_url": "https://tldlog.com/t/dns-security/",
  "feed_url": "https://tldlog.com/t/dns-security/feed.json",
  "description": "Every article and link on tldlog tagged “dns-security”, newest first.",
  "language": "en",
  "items": [
    {
      "id": "https://tldlog.com/l/rare-cyrillic-latin-letters-let-attackers-spoof-urls/",
      "url": "https://tldlog.com/l/rare-cyrillic-latin-letters-let-attackers-spoof-urls/",
      "external_url": "https://www.theregister.com/security/2026/10/10/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers/5302383?utm_source=tldlog.com&utm_medium=referral",
      "title": "Rare Cyrillic and Latin letters let attackers spoof URLs in Chromium browsers",
      "content_html": "<p>Researchers Ian Muscat and Leanne Briffa of Have I Been Squatted found that two uncommon characters, a Cyrillic barred o and a Latin K with hook, can bypass Chromium’s anti-spoofing checks, letting lookalike domains display as trusted brand names.</p><p>Source: <a href=\"https://www.theregister.com/security/2026/10/10/two-characters-open-up-a-world-of-typosquatting-opportunities-in-chromium-browsers/5302383?utm_source=tldlog.com&amp;utm_medium=referral\">theregister.com</a></p>",
      "summary": "Researchers Ian Muscat and Leanne Briffa of Have I Been Squatted found that two uncommon characters, a Cyrillic barred o and a Latin K with hook, can bypass Chromium’s anti-spoofing checks, letting lookalike domains display as trusted brand names.",
      "date_published": "2026-10-11T14:01:28Z",
      "date_modified": "2026-10-11T14:01:28Z",
      "tags": [
        ".security"
      ],
      "language": "en"
    },
    {
      "id": "https://tldlog.com/l/icann-reminds-resolver-operators-check-new-dnssec-root-key/",
      "url": "https://tldlog.com/l/icann-reminds-resolver-operators-check-new-dnssec-root-key/",
      "external_url": "https://www.icann.org/resources/pages/ksk-rollover-en?utm_source=tldlog.com&utm_medium=referral",
      "title": "ICANN reminds resolver operators to check new DNSSEC root key ahead of rollover",
      "content_html": "<p>ICANN has urged operators of DNSSEC-validating resolvers to confirm that KSK-2024, identified by Key Tag 38696, is present in their trust anchor configuration before the root zone KSK rollover scheduled for 11 October 2026.</p><p>Source: <a href=\"https://www.icann.org/resources/pages/ksk-rollover-en?utm_source=tldlog.com&amp;utm_medium=referral\">icann.org</a></p>",
      "summary": "ICANN has urged operators of DNSSEC-validating resolvers to confirm that KSK-2024, identified by Key Tag 38696, is present in their trust anchor configuration before the root zone KSK rollover scheduled for 11 October 2026.",
      "date_published": "2026-10-11T07:26:48Z",
      "date_modified": "2026-10-11T15:35:47Z",
      "tags": [
        ".security"
      ],
      "language": "en"
    },
    {
      "id": "https://tldlog.com/l/gobalance-bug-lets-attackers-hijack-tor-onion-addresses/",
      "url": "https://tldlog.com/l/gobalance-bug-lets-attackers-hijack-tor-onion-addresses/",
      "external_url": "https://thehackernews.com/2026/10/gobalance-flaw-lets-attackers-hijack.html?m=1&utm_source=tldlog.com&utm_medium=referral",
      "title": "GoBalance bug lets attackers hijack Tor .onion addresses, researchers say",
      "content_html": "<p>Searchlight Cyber disclosed a flaw in GoBalance, a load balancer used by dark-web sites, that lets attackers recover a site&#39;s private key from public data and hijack its .onion address, as seen in the Dread forum takeover.</p><p>Source: <a href=\"https://thehackernews.com/2026/10/gobalance-flaw-lets-attackers-hijack.html?m=1&amp;utm_source=tldlog.com&amp;utm_medium=referral\">thehackernews.com</a></p>",
      "summary": "Searchlight Cyber disclosed a flaw in GoBalance, a load balancer used by dark-web sites, that lets attackers recover a site's private key from public data and hijack its .onion address, as seen in the Dread forum takeover.",
      "date_published": "2026-10-10T22:55:43Z",
      "date_modified": "2026-10-10T22:55:43Z",
      "tags": [
        ".security"
      ],
      "language": "en"
    },
    {
      "id": "https://tldlog.com/l/doj-fbi-seize-domains-tied-alleged-chinese-cyber-espionage/",
      "url": "https://tldlog.com/l/doj-fbi-seize-domains-tied-alleged-chinese-cyber-espionage/",
      "external_url": "https://circleid.com/posts/us-seizes-seven-domains-linked-to-alleged-chinese-cyber-espionage-operation?utm_source=tldlog.com&utm_medium=referral",
      "title": "DOJ and FBI seize domains tied to alleged Chinese cyber espionage tools",
      "content_html": "<p>The US Justice Department and FBI seized seven domains linked to two alleged Chinese cyber espionage tools, Microscan and FishHub, which they say were used by actors tied to Integrity Technology Group to target critical infrastructure in the US, Asia and Europe.</p><p>Source: <a href=\"https://circleid.com/posts/us-seizes-seven-domains-linked-to-alleged-chinese-cyber-espionage-operation?utm_source=tldlog.com&amp;utm_medium=referral\">circleid.com</a></p>",
      "summary": "The US Justice Department and FBI seized seven domains linked to two alleged Chinese cyber espionage tools, Microscan and FishHub, which they say were used by actors tied to Integrity Technology Group to target critical infrastructure in the US, Asia and Europe.",
      "date_published": "2026-10-10T13:28:32Z",
      "date_modified": "2026-10-10T13:28:32Z",
      "tags": [
        ".security"
      ],
      "language": "en"
    },
    {
      "id": "https://tldlog.com/l/internets-root-zone-dnssec-key-rotates-october-11/",
      "url": "https://tldlog.com/l/internets-root-zone-dnssec-key-rotates-october-11/",
      "external_url": "https://blog.nic.cz/2026/10/09/rotace-klice-korenove-zony-jiz-11-rijna-zkontrolujte-si-sve-resolvery/?utm_source=tldlog.com&utm_medium=referral",
      "title": "Internet's root zone DNSSEC key rotates October 11",
      "content_html": "<p>The DNS root zone&#39;s signing key changes on October 11, 2026, switching from KSK-2017 to KSK-2024, CZ.NIC&#39;s Ondřej Filip explains, urging DNS resolver operators to verify support beforehand to avoid outages. Cloudflare offers a test tool to check resolvers.</p><p>Source: <a href=\"https://blog.nic.cz/2026/10/09/rotace-klice-korenove-zony-jiz-11-rijna-zkontrolujte-si-sve-resolvery/?utm_source=tldlog.com&amp;utm_medium=referral\">blog.nic.cz</a></p>",
      "summary": "The DNS root zone's signing key changes on October 11, 2026, switching from KSK-2017 to KSK-2024, CZ.NIC's Ondřej Filip explains, urging DNS resolver operators to verify support beforehand to avoid outages. Cloudflare offers a test tool to check resolvers.",
      "date_published": "2026-10-09T09:56:46Z",
      "date_modified": "2026-10-11T15:36:35Z",
      "tags": [
        ".policy"
      ],
      "language": "en"
    },
    {
      "id": "https://tldlog.com/l/google-chrome-blocks-rogue-certificates-cctld-hijacks-ghana/",
      "url": "https://tldlog.com/l/google-chrome-blocks-rogue-certificates-cctld-hijacks-ghana/",
      "external_url": "https://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/?utm_source=tldlog.com&utm_medium=referral",
      "title": "Google Chrome blocks rogue certificates after ccTLD hijacks in Ghana, Sierra Leone, American Samoa",
      "content_html": "<p>Chrome says attackers hijacked the .gh, .sl, and .as ccTLD registries, altering DNS records and obtaining unauthorized HTTPS certificates for Google and other organizations&#39; domains, prompting Chrome to block the certificates via CRLSets.</p><p>Source: <a href=\"https://blog.google/security/chromes-response-to-recent-cctld-registry-hijacks/?utm_source=tldlog.com&amp;utm_medium=referral\">Google Security</a></p>",
      "summary": "Chrome says attackers hijacked the .gh, .sl, and .as ccTLD registries, altering DNS records and obtaining unauthorized HTTPS certificates for Google and other organizations' domains, prompting Chrome to block the certificates via CRLSets.",
      "date_published": "2026-10-07T07:47:12Z",
      "date_modified": "2026-10-09T14:33:21Z",
      "tags": [
        ".cctld"
      ],
      "language": "en"
    }
  ]
}
