#ICYMI we’re nearing the end of the #DNS root zone key rollover process 📢 After Oct. 11, any DNSSEC-validating resolver that hasn’t added KSK-2024 to its trust anchor set will experience DNS resolution failures. #SysAdmins, are you ready? Learn more about the rollover process and a couple tips for preparing your systems in our recent joint blog with ICANN: https://vrsn.cc/6048B1E7fs
DNS Root Zone Key Rollover Update
More Relevant Posts
-
If you are managing network infrastructure, you know how hard it is to troubleshoot DNSSEC failures when registries mess up key rollovers. We recently handled a major .AL outage by deploying a Negative Trust Anchor, but we paired it with a brand-new error code, EDE 33, to keep the bypass completely transparent. It is officially assigned by IANA, and tools like kdig already support it. Check out the technical breakdown and our Internet-Draft:
To view or add a comment, sign in
-
What happens when an agent needs something mid-call, but the server can't stay alive waiting for the answer? The server returns early. It packages resumption state into a requestState token. The client fulfills the request and comes back. A new request lands on any available instance. The server resumes exactly where it left off. That's MRTR in MCP 2026-07-28. Max Körbächer's new post on the AAIF blog covers how the pattern works, how to design requestState correctly, and the security model you need to build explicitly: integrity protection, expiry, principal binding, and replay handling. Read more: https://lnkd.in/e-5RFQuP
To view or add a comment, sign in
-
-
WHMCS just shipped an emergency-grade fix for hosting operators. CVE-2026-67399 lets an unauthenticated attacker run code on the WHMCS host, the box that holds your customer data, payment config, and server credentials. Affects all 9.x before 9.0.8 and 8.x before 8.13.7. No workaround. Patch now, then check for files and staff accounts you did not create. Read the full analysis: https://lnkd.in/ecZviCHJ
To view or add a comment, sign in
-
-
A valid TLS certificate delivered a malicious software update. The connection was encrypted. The hostname matched. No warning appeared. Yet a BGP route hijack had sent some Virtualizor servers to an attacker-controlled machine, and the update client did not verify the package itself. The memorable distinction is simple: TLS verified the road, not the release. If an updater runs with root authority, the artifact needs an identity independent of the server that delivers it. Sign the package. Anchor verification in a release key kept away from public delivery systems. Fail closed before extraction or execution. For operators, installing the fixed release is only half the response. Code that already ran as root may have changed accounts, keys, services, or managed workloads. Preserve evidence, map the server's reach, rotate exposed authority from a clean system, and rebuild when cleanup cannot restore enough confidence. #SupplyChain #SecurityEngineering #DevSecOps
A valid TLS certificate delivered a malicious software update. The connection was encrypted. The hostname matched. No warning appeared. Yet a BGP route hijack had sent some Virtualizor servers to an attacker-controlled machine, and the update client did not verify the package itself. The memorable distinction is simple: TLS verified the road, not the release. If an updater runs with root aut...
To view or add a comment, sign in
-
Most teams learn about a bad DNS change from an outage. The best teams learn about it from an alert. ZoneWatcher watches your DNS Made Easy records continuously, saves every version, and notifies you the moment anything changes. https://lnkd.in/gcarzDBf
To view or add a comment, sign in
-
When was the last unexpected DNS change in your Vercel account? If you can't answer that, ZoneWatcher can. Continuous monitoring, instant alerts, automatic backups, and a complete audit history for every record. https://lnkd.in/eEd839qA
To view or add a comment, sign in
-
A reseller once opened a support ticket, convinced their server was down. 😬 The server was fine. The actual problem: a stale A record still pointing at an IP from a migration two months earlier. The most expensive DNS mistakes aren't dramatic. They're quiet — a record nobody remembered to update, sitting there for months until a client notices before you do. Full breakdown here 👇 https://lnkd.in/ePN47hTw
To view or add a comment, sign in
-
-
The risky part of a DNS change is rarely typing the new value. It is understanding who controls the zone and what still depends on the old answer. Before touching Save, map the registrant, registrar, registry, DNS host, resolver, CDN, web host, and email provider. Record the current state. Define verification, stop conditions, and a path back. DNS is wonderfully literal. It will publish exactly what you configured, including the configuration you regret five seconds later. ClueDNS helps teams trace DNS from the root to the final answer and make changes with evidence and a rollback plan: https://cluedns.com/ #DNS #WebOperations
To view or add a comment, sign in
-
Someone announced a /24 out of Hetzner's address space for 33 hours last weekend, and traffic meant for the Virtualizor update servers went somewhere else. What makes it worth reading is that every safety mechanism in the chain worked correctly and none of them helped. The TLS certificate was real. A certificate authority proves you own a domain by connecting to it. That connection took the hijacked route, reached the attacker, and came back satisfied, so a valid certificate got issued and nothing showed a warning. RPKI passed too. The attacker never appeared as the origin, and Hetzner's signed record had allowed subdivision down to /24 since 2021. Correct origin, permitted prefix length. The route didn't sneak past validation, it satisfied it. The one check that would have caught this was the one nobody had built. Update packages weren't signed, so clients installed what arrived. Hetzner has since capped the record at /16. Worth noticing the trade, because their own response during the incident was to announce the /24 themselves and outcompete the hijacker, and under the new record that move is no longer available to them. Encryption in transit was never the question here. The question is whether your update client verifies a signature before it installs anything, and most of them don't.
To view or add a comment, sign in
-
-
Pen tester found our internal admin panel accessible via a subdomain that wasn't in our asset inventory. The subdomain was created two years ago for a vendor integration, the integration was decommissioned, but nobody removed the DNS record or the server behind it. The server was running an outdated framework version with known CVEs. Attack surface you don't know about is attack surface you can't protect.
To view or add a comment, sign in