
Dangling CNAMEs: The Critical DNS Misconfiguration Most Organizations Still Miss
In cybersecurity, not all damaging attacks stem from complex techniques; some originate from overlooked issues like forgotten DNS records. This was highlighted by researchers who identified a significant campaign that exploited abandoned CNAME records across several universities, including UC Berkeley, Columbia University, and Washington University in St. Louis. Attackers hijacked these subdomains, leveraging the trust associated with .edu domains to facilitate malicious activities.










