Hacker News with Generative AI: Internet Security

Backdooring your backdoors – Another $20 domain, more governments (watchtowr.com)
After the excitement of our .MOBI research, we were left twiddling our thumbs. As you may recall, in 2024, we demonstrated the impact of an unregistered domain when we subverted the TLS/SSL CA process for verifying domain ownership to give ourselves the ability to issue valid and trusted TLS/SSL certificates for any .MOBI domain.
Phishers Love New TLDs Like .shop, .top and .xyz (krebsonsecurity.com)
Phishing attacks increased nearly 40 percent in the year ending August 2024, with much of that growth concentrated at a small number of new generic top-level domains (gTLDs) — such as .shop, .top, .xyz — that attract scammers with rock-bottom prices and no meaningful registration requirements, new research finds. Meanwhile, the nonprofit entity that oversees the domain name industry is moving forward with plans to introduce a slew of new gTLDs.
2024 U.S. Election: Exploring the Surge in Cyber Activity and Cyber Attacks (cloudflare.com)
Elections are not just a matter of casting ballots. They depend on citizens being able to register to vote and accessing information about candidates and the election process, which in turn depend on the strength and security of the Internet. Despite the risks posed by potential cyberattacks aimed to disrupt democracy, Cloudflare did not observe any significant disruptions to campaigns or local government websites from cyberattack.
The Alarming Prevalence of Zone Transfers (reconwave.com)
We found that 8% of all nameservers still have zone transfers enabled for all authorized zones, potentially exposing sensitive information to malicious actors.
Cloudflare auto-mitigated world record 3.8 Tbps DDoS attack (cloudflare.com)
Cloudflare's DDoS protection systems have been combating a month-long campaign of hyper-volumetric L3/4 DDoS attacks.
Ephemeral IDs: a new tool for fraud detection (cloudflare.com)
In the early days of the Internet, a single IP address was a reliable indicator of a single user. However, today’s Internet is more complex. Shared IP addresses are now common, with users connecting via mobile IP address pools, VPNs, or behind CGNAT (Carrier Grade Network Address Translation). This makes relying on IP addresses alone a weak method to combat modern threats like automated attacks and fraudulent activity.
White House Cyber Director Releases Roadmap to Enhance Internet Routing Security (whitehouse.gov)
White House's New Roadmap to Enhance Internet Routing Security [pdf] (whitehouse.gov)
Malaysian ISPs Hijack Cloudflare/Google DNS Requests (torrentfreak.com)
Phish-friendly domain registry ".top" put on notice (krebsonsecurity.com)
Intent to end OCSP service (letsencrypt.org)
Cloudflare reports almost 7% of internet traffic is malicious (zdnet.com)
FCC pushes ISPs to fix security flaws in Internet routing (arstechnica.com)
US Post Office phishing sites get as much traffic as the real one (bleepingcomputer.com)
Hackers infect users of antivirus service that delivered updates over HTTP (arstechnica.com)
We ensure Cloudflare customers aren't affected by LE's certificate chain change (cloudflare.com)