Business Wire

New CSC Research Finds One in Five DNS Records are Susceptible to Subdomain Hijacking Due to Insufficient Cyber Hygiene

Share

CSC, an enterprise-class domain registrar and world leader in mitigating domain and domain name system (DNS) threats, today released its “Subdomain Hijacking Vulnerabilities Report” that reviewed over 440,000 DNS records and found that over 21% of DNS records point to content that does not resolve, leaving many companies vulnerable to subdomain hijacking. Additionally, over 277,000 (63%) show error status codes such as “404 not found” or “502 bad gateway.”

DNS records housekeeping is historically one of the most frequently neglected tasks due to a long history of different owners, policies, and vendors. Digital records accumulate over time, and administrators who may be unaware of each domain’s history are hesitant to delete legacy records fearing they may be tied to critical infrastructure. This buildup of inactive zones that do not point to content are known as “dangling DNS” and are at risk of subdomain hijacking. Subdomain hijacking is where an attacker gains control of a legitimate subdomain that is no longer in use to host their own fraudulent or malicious content. This opens a gateway for other cyberattacks such as phishing, malware, and ransomware.

“With 21% of major organizations vulnerable to subdomain hijacking, we needed to ensure a way for our clients to secure their online ecosystem from an array of threats that could jeopardize long-term brand integrity,” says Ihab Shraim, chief technology officer of CSC’s Digital Brand Services. “This is why CSC is introducing its new Subdomain Monitoring and Enforcement product—the first and only technology in the market to ease the burden of tracking and maintaining DNS records and purging unused zone records to prevent a subdomain hijack. With this technology, enterprises can proactively disrupt criminals who previously attempted to target their customers, employees, and partners, and mitigate the threat targeting their brands.”

The Subdomain Monitoring and Enforcement technology is powered by CSC’s one-of-a-kind DomainSecSM threat intelligence platform, and alerts DNS administrators and security engineers when changes to their zone records are detected. It also provides context on those changes so organizations can take informed actions to prevent future subdomain hijacking and conduct enforcement takedowns. With this solution, enterprises can clean up legacy records over time, and easily integrate with the DomainSec platform. This solution for domain management, brand protection, and anti-fraud solutions provides greater visibility on threat vectors targeting global domain portfolios.

“Organizations with diverse brand portfolios and global operations are often unaware of the scale of their digital footprint as digital records accumulate over time, and this makes maintaining cyber hygiene a real challenge,” said Mark Calandra, president of CSC’s Digital Brand Services. “Many do not realize that critical vulnerabilities exist with subdomains. With our new Subdomain Monitoring technology, enterprises will have the visibility necessary to strengthen their DNS cyber hygiene and attack surface management while also having more effective measures in place to protect against cyberattacks.”

To learn more about CSC’s approach to domain security, visit cscdbs.com. Download the “Subdomain Hijacking Vulnerabilities Report” here.

About CSC

CSC is the trusted security and threat intelligence provider of choice for the Forbes Global 2000 and the 100 Best Global Brands® in enterprise domain names, domain name system (DNS), digital certificate management, as well as digital brand and fraud protection. As global companies make significant investments in their security posture, CSC can help them understand known cybersecurity oversights that exist, and help them secure their online digital assets and brands. By leveraging CSC’s proprietary technology, companies can solidify their security posture to protect against cyber threat vectors targeting their online assets and brand reputation, helping them avoid devastating revenue loss, and significant financial penalties because of policies like the General Data Protection Regulation (GDPR). CSC also provides online brand protection—the combination of online brand monitoring and enforcement activities—taking a holistic approach to digital asset protection, along with fraud protection services to combat phishing. Headquartered in Wilmington, Delaware, USA, since 1899, CSC has offices throughout the United States, Canada, Europe, and the Asia-Pacific region. CSC is a global company capable of doing business wherever our clients are—and we accomplish that by employing experts in every business we serve. Visit cscdbs.com.

To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.

Contact information

For more information:
W2 Communications
CSC@w2comm.com
CSC News Room

About Business Wire

For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

BYD Unleashes FANG CHENG BAO, A New Brand that Specializes in Professional and Personalized Identities9.6.2023 06:41:00 EEST | Press release

On June 9, BYD, the world’s leading manufacturer of new energy vehicles, officially announced its new sub-brand FANG CHENG BAO. The brand, as the fifth in the row of the BYD brand matrix, will meet the increasingly personalized needs of consumers by offering a series of unique and professional-grade new energy vehicle models. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20230608005841/en/ SF (Photo: Business Wire) FANG CHENG BAO is a significant addition to BYD’s diversified brand matrix, following its Dynasty series, Ocean series, Denza, and Yangwang. The vehicle lineup of FANG CHENG BAO ranges from off-road vehicles to sports cars, and its initial model, a hardcore SUV codenamed SF, is expected to launch this year. The brand name FANG CHENG BAO translates literally as “Formula” and “Leopard” from Chinese, symbolizing the pursuit of the transformative rise and the exploration of digital realms. It blends the standards and r

FDA Accepts Biologics License Applications for exagamglogene autotemcel (exa-cel) for Severe Sickle Cell Disease and Transfusion-Dependent Beta Thalassemia9.6.2023 02:40:00 EEST | Press release

Vertex Pharmaceuticals Incorporated (Nasdaq: VRTX) and CRISPR Therapeutics (Nasdaq: CRSP) today announced that the U.S. Food and Drug Administration (FDA) has accepted the Biologics License Applications (BLAs) for the investigational treatment exagamglogene autotemcel (exa-cel) for severe sickle cell disease (SCD) and transfusion-dependent beta thalassemia (TDT). The FDA has granted Priority Review for SCD and Standard Review for TDT and assigned Prescription Drug User Fee Act (PDUFA) target action dates of December 8, 2023, and March 30, 2024, respectively. Updated data from the pivotal trials supporting the regulatory submissions will be presented at the Annual European Hematology Association Congress on June 11, 2023. “We are very pleased with the acceptance of the submissions and the Priority Review designation for SCD by the FDA, as well as the progress of the exa-cel filings in the EU and U.K.,” said Reshma Kewalramani, M.D., Chief Executive Officer and President of Vertex. “Exa-

Citi Global Wealth Investments Issues Mid-Year Wealth Outlook 2023 - Opportunities on the Horizon: Investing Through a Slowing Economy9.6.2023 00:59:00 EEST | Press release

Citi Global Wealth Investments today released its Mid-Year Wealth Outlook 2023 report - Opportunities on the Horizon: Investing Through a Slowing Economy. This biannual report sets out Citi Global Wealth’s outlook on how investors should approach developments in the global economy, markets and geopolitics. Though 2023 has been full of extraordinary events, Citi Global Wealth sees the remainder of the year as an opportunity. We are in a “rolling recession” where parts of the US economy are growing even as others contract. As inflation slowly eases following a period of rapid Fed rate hikes, the group believes that keeping portfolios invested is imperative. While the current asset allocation strategy remains defensive, Citi Global Wealth see numerous opportunities to adjust their portfolios over time, as the Fed shifts from interest rate hikes to cuts. We believe that current markets will lead into a meaningful potential recovery in 2024. “Though the broader bear market is not yet over,

Verisign Reports Internet Has 354.0 Million Domain Name Registrations at the End of the First Quarter of 20238.6.2023 23:55:00 EEST | Press release

VeriSign, Inc. (NASDAQ: VRSN), a global provider of domain name registry services and internet infrastructure, today announced that the first quarter of 2023 closed with 354.0 million domain name registrations across all top-level domains (TLDs), an increase of 3.5 million domain name registrations, or 1.0%, compared to the fourth quarter of 2022.1,2 Domain name registrations also increased by 3.5 million, or 1.0%, year over year.1,2 The .com and .net TLDs had a combined total of 174.8 million domain name registrations in the domain name base3 at the end of the first quarter of 2023, an increase of 1.0 million domain name registrations, or 0.6%, compared to the fourth quarter of 2022. The .com and .net TLDs had a combined increase of 0.1 million domain name registrations, or 0.1%, year over year. As of March 31, 2023, the .com domain name base totaled 161.6 million domain name registrations, and the .net domain name base totaled 13.2 million domain name registrations. New .com and .net

Momcozy Introduces the Revolutionary M5 All-in-one Hands-free Breast Pump - Empowering Busy Moms with the Ultimate Maternity Solution8.6.2023 23:00:00 EEST | Press release

Momcozy, the esteemed maternity and baby brand favored by over two million moms worldwide, proudly unveils the revolutionary M5 all-in-one hands-free breast pump. Designed to provide the ultimate pumping experience for busy breastfeeding moms, this cutting-edge device showcases Momcozy's commitment to meeting the needs of mothers worldwide. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20230608005079/en/ M5 All-in-one Handsfree Breast Pump (Graphic: Business Wire) Renowned for its position as a leader in the North American electric breast pump market, Momcozy distinguishes itself yet again with the M5 all-in-one hands-free breast pump. Driven by a user research team that believes in "cozy designs born from love" and strives to cater to customer needs, Momcozy has conducted extensive interviews with thousands of mothers over the past two years. The team's latest findings highlight "comfort" as the most frequently mentioned req

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom