Monday, August 25, 2025
NewsWave
No Result
View All Result
  • Home
  • World
  • USA
  • Business
  • Sports
  • Entertainment
  • Technology
Login
  • Home
  • World
  • USA
  • Business
  • Sports
  • Entertainment
  • Technology
Login
No Result
View All Result
Login
NewsWave
No Result
View All Result
Home Business

Hiding in Plain Sight: How Subdomain Attacks Use Your Email Authentication Against You

26 March 2024
in Business
0
Hiding in Plain Sight: How Subdomain Attacks Use Your Email Authentication Against You
Share on FacebookShare on Twitter


For years, analysts, security specialists, and security architects alike have been encouraging organizations to become DMARC compliant. This involves deploying email authentication to ensure their legitimate email has the best chance of getting to the intended recipients, and for domain owners to be quickly notified of any unauthorized usage of their domains. While together we are making progress thanks to DMARC adoption and reporting services such as Cisco’s OnDMARC offering, there’s an opportunity to do better particularly with on-going monitoring to address new and emerging threats, such as this Subdo campaign.

What’s happened?

Recently a totally new attack type has been seen that takes advantage of the complacency that an organization may have when they approached their DMARC rollout with a ‘ticked the box’ mindset.

The SubdoMailing (Subdo) campaign has been ongoing for about two years now. It sends malicious mail – that is typically authenticated – from domains and subdomains that have been compromised through domain takeover and dangling DNS issues.

These attacks were initially reported by Guardio Labs who reported the discovery of 8,000 domains and 13,000 subdomains being used for these types of attacks since 2022.

Several weeks before that, Cisco’s new DMARC partner, Red Sift, discovered what they initially thought was an isolated incident of bad senders passing SPF checks and sending emails fraudulently on behalf of one of their customers. In the customer’s instance of Red Sift OnDMARC, they noticed email was coming from a sender with a poor reputation and a subdomain that appeared unrelated to their customer’s main domain. But these emails had fully passed SPF checks with the customer’s current SPF record. Upon alerting the customer who then investigated all the ‘includes’ in their SPF record, several outdated CNAME addresses were found that had been taken over by attackers, which is what caused the issue.

What should I look out for?

The bad actors in this campaign are capitalizing on stale, forgotten or misconfigured records that were wrongfully included in DNS to send unauthorized emails. The attackers then send phishing emails as images to avoid text-based spam detection.

It is this oversight that has seen many notable organizations be impacted by these new subdomain attacks in the last few months, solely because they have not been actively monitoring in the right areas.

Proactive steps to start today:

Don’t let your domain names expire – these are what provide fraudsters the opportunity to carry out the attack.
Keep your DNS clean – Remove resource records from your DNS that are no longer in use and remove third-party dependencies from your DNS when they become redundant.
Use a trusted email protection provider – It makes sense to use a vendor for DMARC, DKIM and SPF requirements but be sure to use a trusted vendor with the capability to proactively identify problems, such as when part of a SPF policy is void or insecure.
Check for dangling DNS records – Have an inventory of hostnames that are monitored continuously for dangling resource records and third-party services. When identified, remove them immediately from your DNS.
Monitor what sources are sending from owned domains – If the domain or subdomain is taken over for sending, then it is important to know if mail is being sent from it as quickly as possible.

What else should I do?

If you are wondering if you have been impacted by SubdoMailing, the best place to start is Red Sift Investigate, this will provide you with a review of your domain such as can be seen below:

Should this valuable tool reveal any ‘SubdoMailers’ – also known as poisoned includes – the Red Sift SPF Checker allows you to visualize them in a dynamic ‘SPF tree’, allowing you to quickly pinpoint where they are and speed up remediation efforts, an example of a dynamic SPF tree can be seen below: –

The OnDMARC Adoption and Reporting Solution that Cisco partners with Red Sift on has already been updated to uncover exactly these issues directly within the tool to ensure our customers are protected.

If you’re a Cisco Secure Email customer, find out how you can quickly add Red Sift domain protection to your security suite and better detect that image-based spam. To check out the sophisticated threat protection capabilities of Secure Email Threat Defense, start a free trial today.

We’d love to hear what you think. Ask a Question, Comment Below, and Stay Connected with Cisco Security on social!

Cisco Security Social Channels

InstagramFacebookTwitterLinkedIn

Share:



Source link

🪄 Creating a simple explanation...

Tags: AttacksAuthenticationEmailHidingPlainsightSubdomain
Previous Post

British High Court wants more U.S. assurances on Julian Assange, extending his extradition fight

Next Post

Dubai Culture launches several community events and cultural activities as part of #RamadanInDubai campaign – Arts & culture

Related Posts

4 Reasons to Buy Shiba Inu Before 2026
Business

4 Reasons to Buy Shiba Inu Before 2026

by My News Wave
25 August 2025
0

Shiba Inu (CRYPTO: SHIB), a meme coin created as a parody of Dogecoin (CRYPTO: DOGE), has seen a remarkable increase in value, turning a $100 investment in November 2020 into $2.35 million today, fueled by its association with Dogecoin, listings on major exchanges like Coinbase and Binance, and endorsements from celebrities like Elon Musk. Want More Context? 🔎

Read more
What Is the Highest Apple Stock Has Ever Been?
Business

What Is the Highest Apple Stock Has Ever Been?

by My News Wave
25 August 2025
0

Apple (NASDAQ: AAPL) hit an all-time high of $260.10 per share on December 26, 2024, but has since declined to around $228, reflecting a drop of over 12%. Meanwhile, the S&P 500 has risen by 7%, indicating that Apple has significantly underperformed compared to the broader market since its peak. Want More Context? 🔎

Read more
Walmart Shares Sink Despite Solid Sales Outlook. Should Investors Buy the Dip?
Business

Walmart Shares Sink Despite Solid Sales Outlook. Should Investors Buy the Dip?

by My News Wave
25 August 2025
0

Walmart (NYSE: WMT) experienced a decline in its stock despite reporting strong revenue growth and raising its guidance, primarily due to lower-than-expected profits attributed to increased workers' compensation claims costs. The stock is currently up about 8% for the year, prompting discussions about whether this dip presents a buying opportunity. Want More Context? 🔎

Read more
3 Must-Know Facts About Roku Before You Buy the Stock
Business

3 Must-Know Facts About Roku Before You Buy the Stock

by My News Wave
24 August 2025
0

Investors are drawn to Roku (NASDAQ: ROKU) due to its potential for strong returns, yet long-term shareholders have faced challenges, with the stock trading 80% below its peak despite a 27% rise in 2025. Before adding Roku to their portfolios, investors should consider three critical factors regarding the company's current position and future outlook. Want More Context? 🔎

Read more
Alphabet Just Scored Big With Meta: Is GOOGL Stock Poised for Another Leg Higher?
Business

Alphabet Just Scored Big With Meta: Is GOOGL Stock Poised for Another Leg Higher?

by My News Wave
24 August 2025
0

Alphabet (NASDAQ: GOOGL, GOOG) and Meta Platforms (NASDAQ: META) saw significant stock gains on Friday, driven by a Federal Reserve hint at a September interest rate cut and a crucial $10 billion cloud deal between the two companies. This partnership may provide a vital boost for Alphabet amid the current state of the artificial intelligence market. Want More Context? 🔎

Read more
2 Growth Stocks With Sky-High Potential to Hold for Decades
Business

2 Growth Stocks With Sky-High Potential to Hold for Decades

by My News Wave
24 August 2025
0

Investors seeking long-term growth should consider Intuitive Surgical (NASDAQ: ISRG) and Amazon.com (NASDAQ: AMZN), both of which feature strong, scalable business models with recurring revenue. While neither stock is cheap, their robust growth potential makes them solid buy-and-hold options for the future, emphasizing the importance of quality over entry price. Want More Context? 🔎

Read more
NewsWave

News Summarized. Time Saved. Bite-sized news briefs for busy people. No fluff, just facts.

CATEGORIES

  • Africa
  • Asia Pacific
  • Australia
  • Business
  • Canada
  • Entertainment
  • Europe
  • India
  • Middle East
  • New Zealand
  • Sports
  • Technology
  • UK
  • USA
  • World

LATEST NEWS STORIES

  • Oklahoma man arrested after 11-year-old stepdaughter gives birth, mother charged with enabling abuse
  • Helicopter tackling forest fire crashes into lake while scooping water
  • Sherrone Moore quick-hitters: Michigan starting QB, OL, potential All-Big Ten defensive tackle, more
  • About Us
  • Disclaimer
  • Privacy Policy
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2025 News Wave
News Wave is not responsible for the content of external sites.

No Result
View All Result
  • Home
  • World
  • USA
  • Business
  • Sports
  • Entertainment
  • Technology

Copyright © 2025 News Wave
News Wave is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In