<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Dns-Hijacking on CuraSec</title><link>https://curasec.metacog.co.kr/tags/dns-hijacking/</link><description>Recent content in Dns-Hijacking on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Wed, 29 Jul 2026 13:07:14 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/dns-hijacking/index.xml" rel="self" type="application/rss+xml"/><item><title>CubePilot drone software dev hit by DNS hijacking</title><link>https://curasec.metacog.co.kr/insights/2026-07-29-cubepilot-drone-software-dev-hit-by-dns-hijacking-to-interce/</link><pubDate>Wed, 29 Jul 2026 13:07:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-29-cubepilot-drone-software-dev-hit-by-dns-hijacking-to-interce/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> DNS hijacking against a hardware/firmware vendor is a supply-chain attack vector worth understanding — audit your own domain registrar MFA and DNS provider controls, but no direct patch or action unless you&amp;rsquo;re a CubePilot customer integrating their software.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> No IOCs or TTPs published; file as a supply-chain DNS hijack case study for future detection design around suspicious DNS changes or unexpected certificate issuance for vendor domains.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Relevant as a vendor-risk illustration — DNS hijacking can compromise a software supplier&amp;rsquo;s delivery pipeline — but CubePilot is niche enough that most enterprise security leaders have no direct exposure to assess.&lt;/li>
&lt;/ul></description></item><item><title>Hotel Wi-Fi DNS hijacked to phish Microsoft 365 credentials</title><link>https://curasec.metacog.co.kr/insights/2026-07-25-hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accoun/</link><pubDate>Sat, 25 Jul 2026 12:08:50 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-25-hackers-hijack-hotel-wi-fi-dns-to-steal-microsoft-365-accoun/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Review whether corporate travel policy requires VPN enforcement on untrusted Wi-Fi; audit M365 tenant for conditional access policies that would block logins from non-compliant networks or flag impossible-travel anomalies.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Hunt for M365 sign-ins from hotel/conference-center IP ranges or unexpected geolocations since this campaign began; tune Conditional Access or SIEM rules to flag credential use immediately after untrusted-network logins.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> A reminder that credential phishing via rogue DNS is an ongoing risk for traveling employees; no board-level action warranted without evidence of organizational impact, but useful context for travel security awareness programs.&lt;/li>
&lt;/ul></description></item></channel></rss>