<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Dependency-Hijacking on CuraSec</title><link>https://curasec.metacog.co.kr/tags/dependency-hijacking/</link><description>Recent content in Dependency-Hijacking on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Fri, 18 Sep 2026 14:58:07 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/dependency-hijacking/index.xml" rel="self" type="application/rss+xml"/><item><title>Abandoned CDN Domain Re-Registered; Thousands of Sites Still Reference It</title><link>https://curasec.metacog.co.kr/insights/2026-09-18-an-abandoned-cdn-domain-was-re-registered-thousands-of-sites/</link><pubDate>Fri, 18 Sep 2026 14:58:07 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-09-18-an-abandoned-cdn-domain-was-re-registered-thousands-of-sites/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> This mirrors the Polyfill.io hijack pattern — any hard-coded reference to the re-registered CDN hostnames in your repos, docs, or build artifacts now loads content from an untrusted owner. Audit all codebases, IaC, and documentation for references to the named CDN hostnames and replace or remove them immediately.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Plan:&lt;/strong> No confirmed malicious payload delivery is noted yet, but the new owner could begin serving malicious scripts at any time. Build a detection rule for outbound DNS/HTTP connections to the re-registered domain, and queue a proxy-log hunt back to the re-registration date of July 2025.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> This is a recurring supply-chain risk class — abandoned third-party asset domains re-registered for abuse (analogous to Polyfill.io). Use this as a trigger to establish or reaffirm a policy requiring engineering teams to audit hard-coded external CDN dependencies on a regular cadence.&lt;/li>
&lt;/ul></description></item></channel></rss>