CERT mailing list archives

NCSC Releases Advisory on Ongoing DNS Hijacking Campaign


From: "US-CERT" <US-CERT () ncas us-cert gov>
Date: Fri, 12 Jul 2019 21:14:03 -0500

Cybersecurity and Infrastructure Security Agency Logo

National Cyber Awareness System:

NCSC Releases Advisory on Ongoing DNS Hijacking Campaign [ 
https://www.us-cert.gov/ncas/current-activity/2019/07/12/ncsc-releases-advisory-ongoing-dns-hijacking-campaign ] 
07/12/2019 09:44 PM EDT 
Original release date: July 12, 2019

The United Kingdoms National Cyber Security Centre (NCSC) has released an advisory about an ongoing Domain Name System 
(DNS) hijacking campaign. The advisory details risks and mitigations for organizations to defend against this campaign, 
in which attackers use compromised credentials to modify the location to which an organizations domain name resources 
resolve to redirect users, obtain sensitive information, and cause man-in-the-middle attacks.

The Cybersecurity and Infrastructure Security Agency (CISA) encourages administrators to review the NCSC Advisory [ 
https://www.ncsc.gov.uk/news/ongoing-dns-hijacking-and-mitigation-advice ], apply the recommended mitigations, and 
refer to CISAs Alert AA19-024A  DNS Infrastructure Hijacking Campaign [ https://www.us-cert.gov/ncas/alerts/AA19-024A ] 
for more information.

This product is provided subject to this Notification [ https://www.us-cert.gov/privacy/notification ] and this Privacy 
& Use [ https://www.dhs.gov/privacy-policy ] policy.

body { font-size: 1em; font-family: Arial, Verdana, sans-serif; font-weight: normal; font-style: normal; color: 
#333333; } ________________________________________________________________________

A copy of this publication is available at www.us-cert.gov [ https://www.us-cert.gov ]. If you need help or have 
questions, please send an email to info () us-cert gov. Do not reply to this message since this email was sent from a 
notification-only address that is not monitored. To ensure you receive future US-CERT products, please add US-CERT () 
ncas us-cert gov to your address book. 

OTHER RESOURCES: Contact Us [ http://www.us-cert.gov/contact-us/ ] | Security Publications [ 
http://www.us-cert.gov/security-publications ] | Alerts and Tips [ http://www.us-cert.gov/ncas ] | Related Resources [ 
http://www.us-cert.gov/related-resources ]  

STAY CONNECTED: Sign up for email updates [ http://public.govdelivery.com/accounts/USDHSUSCERT/subscriber/new ] 


Current thread: