#dnsabuse — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #dnsabuse, aggregated by home.social.
-
👉️ IPv4 address brokers are a critical chokepoint for bulletproof hosters
👉️ Carrier and broker responses to SBL listings reveal a lot about their intentions
👉️ Clustering internet badness at specific facilitators makes them attractive to law enforcement
👉️ Evasion tactics from miscreants signal that the pressure is actually workingIn case you missed it, read the full post here:
https://www.spamhaus.org/resource-hub/bulletproof-hosting/bulletproof-hosting-cutting-off-the-facilitators/#BulletproofHosting #ThreatIntel #InfoSec #Cybercrime #IPv4 #DNSAbuse #NetSec
-
👉️ IPv4 address brokers are a critical chokepoint for bulletproof hosters
👉️ Carrier and broker responses to SBL listings reveal a lot about their intentions
👉️ Clustering internet badness at specific facilitators makes them attractive to law enforcement
👉️ Evasion tactics from miscreants signal that the pressure is actually workingIn case you missed it, read the full post here:
https://www.spamhaus.org/resource-hub/bulletproof-hosting/bulletproof-hosting-cutting-off-the-facilitators/#BulletproofHosting #ThreatIntel #InfoSec #Cybercrime #IPv4 #DNSAbuse #NetSec
-
Cybercrime Reported in June 2026
In this post, Interisle looks at cybercrime activity for the month of June 2026.
https://interisle.substack.com/p/cybercrime-reported-in-june-2026
#cybercrime #dnsabuse #hostingabuse #phishing #malware #spam
-
Cybercrime Reported in June 2026
In this post, Interisle looks at cybercrime activity for the month of June 2026.
https://interisle.substack.com/p/cybercrime-reported-in-june-2026
#cybercrime #dnsabuse #hostingabuse #phishing #malware #spam
-
Phishing Landscape 2026 – Summary Findings
In previous years, Interisle published comprehensive annual reports on phishing. This year, we’re taking a different approach and showing just the significant results of our analysis as a series of posts. Our fall study will include additional insights, findings and recommendations.
In this first post in the series, we look at the key results and compare them to those of the previous year.
https://interisle.substack.com/p/phishing-landscape-2026-summary-findings
-
Phishing Landscape 2026 – Summary Findings
In previous years, Interisle published comprehensive annual reports on phishing. This year, we’re taking a different approach and showing just the significant results of our analysis as a series of posts. Our fall study will include additional insights, findings and recommendations.
In this first post in the series, we look at the key results and compare them to those of the previous year.
https://interisle.substack.com/p/phishing-landscape-2026-summary-findings
-
Phishing Landscape 2026 – Summary Findings
In previous years, Interisle published comprehensive annual reports on phishing. This year, we’re taking a different approach and showing just the significant results of our analysis as a series of posts. Our fall study will include additional insights, findings and recommendations.
In this first post in the series, we look at the key results and compare them to those of the previous year.
https://interisle.substack.com/p/phishing-landscape-2026-summary-findings
-
Phishing Landscape 2026 – Summary Findings
In previous years, Interisle published comprehensive annual reports on phishing. This year, we’re taking a different approach and showing just the significant results of our analysis as a series of posts. Our fall study will include additional insights, findings and recommendations.
In this first post in the series, we look at the key results and compare them to those of the previous year.
https://interisle.substack.com/p/phishing-landscape-2026-summary-findings
-
Phishing Landscape 2026 – Summary Findings
In previous years, Interisle published comprehensive annual reports on phishing. This year, we’re taking a different approach and showing just the significant results of our analysis as a series of posts. Our fall study will include additional insights, findings and recommendations.
In this first post in the series, we look at the key results and compare them to those of the previous year.
https://interisle.substack.com/p/phishing-landscape-2026-summary-findings
-
Interisle Study Presented to ICANN Government Advisory Committee
On Wednesday, June 10, 2026, Karen Rose presented Interisle’s recently published study, Malicious Registrations in the Domain Name Market: An Analysis of 2025 gTLD Registrations and Cybercriminal Demand, to the ICANN GAC (Government Advisory Committee) at ICANN86 Seville Policy Forum. The GAC advises ICANN on public policy aspects of specific issues for which ICANN has responsibility, and DNS abuse has long been an issue of particular interest to the GAC.
https://interisle.substack.com/p/interisle-study-presented-to-icann
-
Interisle Study Presented to ICANN Government Advisory Committee
On Wednesday, June 10, 2026, Karen Rose presented Interisle’s recently published study, Malicious Registrations in the Domain Name Market: An Analysis of 2025 gTLD Registrations and Cybercriminal Demand, to the ICANN GAC (Government Advisory Committee) at ICANN86 Seville Policy Forum. The GAC advises ICANN on public policy aspects of specific issues for which ICANN has responsibility, and DNS abuse has long been an issue of particular interest to the GAC.
https://interisle.substack.com/p/interisle-study-presented-to-icann
-
Cybercrime Reported in May 2026
Interisle's monthly report on cybercrime activity (phishing, malware, spam) for the month of May 2026 revealed a 27% increase in phishing reported compared to April and a 35% increase in spam. While malware reported in May decreased 17% compared to April, it still represents an 11% increase over the monthly average for the 12 -month period.
https://interisle.substack.com/p/cybercrime-reported-in-may-2026
#phishing #malware #spam #dnsabuse #cybercrime #cybersecurity
-
Cybercrime Reported in May 2026
Interisle's monthly report on cybercrime activity (phishing, malware, spam) for the month of May 2026 revealed a 27% increase in phishing reported compared to April and a 35% increase in spam. While malware reported in May decreased 17% compared to April, it still represents an 11% increase over the monthly average for the 12 -month period.
https://interisle.substack.com/p/cybercrime-reported-in-may-2026
#phishing #malware #spam #dnsabuse #cybercrime #cybersecurity
-
Malicious Actors Accounted for as much as 20% of New Domain Name Registrations in 2025
A new analysis by Interisle Consulting Group finds that cybercriminals registered a significant share of new domain name registrations in 2025, representing a substantial percentage of the generic Top-Level Domain (gTLD) market.
The study establishes that malicious actors purchased at least 10 percent of all newly registered gTLD domains in 2025, with projections indicating that the actual share may be closer to 20 percent.
#domainname #domainabuse #cybercrime #maliciousdomains #dnsabuse
https://interisle.substack.com/p/malicious-actors-accounted-for-as
-
Malicious Actors Accounted for as much as 20% of New Domain Name Registrations in 2025
A new analysis by Interisle Consulting Group finds that cybercriminals registered a significant share of new domain name registrations in 2025, representing a substantial percentage of the generic Top-Level Domain (gTLD) market.
The study establishes that malicious actors purchased at least 10 percent of all newly registered gTLD domains in 2025, with projections indicating that the actual share may be closer to 20 percent.
#domainname #domainabuse #cybercrime #maliciousdomains #dnsabuse
https://interisle.substack.com/p/malicious-actors-accounted-for-as
-
Allowlisting: Exception Handling for Blocked TLDs
In this article, we discuss how to deal with blocklisting exception cases by using selective allowlisting to complement generalized blocklisting as part of an incident response.
https://interisle.substack.com/p/allowlisting-exception-handling-for
-
Allowlisting: Exception Handling for Blocked TLDs
In this article, we discuss how to deal with blocklisting exception cases by using selective allowlisting to complement generalized blocklisting as part of an incident response.
https://interisle.substack.com/p/allowlisting-exception-handling-for
-
Cybercrime Reported in April 2026
Interisle publishes quarterly data about cybercrime activity (for phishing, malware, and spam) at the Cybercrime Information Center.
Today, we look at cybercrime activity for the month of April 2026. We point out anything that strikes us as particularly interesting in overall numbers as well as significant changes in ranking for Top Level Domains (TLDs), Registrars, and Hosting Networks.
https://interisle.substack.com/p/cybercrime-reported-in-april-2026
-
Cybercrime Reported in April 2026
Interisle publishes quarterly data about cybercrime activity (for phishing, malware, and spam) at the Cybercrime Information Center.
Today, we look at cybercrime activity for the month of April 2026. We point out anything that strikes us as particularly interesting in overall numbers as well as significant changes in ranking for Top Level Domains (TLDs), Registrars, and Hosting Networks.
https://interisle.substack.com/p/cybercrime-reported-in-april-2026
-
WEBINAR 7 MAY 07:00 UTC – APRALO Policy Forum + EURALO – Understanding the Role of Trusted Notifiers in DNS Abuse Mitigation
REGISTER | ADD TO CALENDAR | PERMALINK
On 7 May 2026, at 07:00 UTC, the APRALO Policy Forum and EURALO will host a joint webinar 'Understanding the Role of Trusted Notifiers in DNS Abuse Mitigation'. The selection of this topic was motivated by the recent At-Large Webinar: Overview on DNS A
-
WEBINAR 7 MAY 07:00 UTC – APRALO Policy Forum + EURALO – Understanding the Role of Trusted Notifiers in DNS Abuse Mitigation
REGISTER | ADD TO CALENDAR | PERMALINK
On 7 May 2026, at 07:00 UTC, the APRALO Policy Forum and EURALO will host a joint webinar 'Understanding the Role of Trusted Notifiers in DNS Abuse Mitigation'. The selection of this topic was motivated by the recent At-Large Webinar: Overview on DNS A
-
WEBINAR 29 APR 12:00 UTC – ICANN EMEA: Phishing and DNS Abuse – Operational Blindspots
REGISTER | ADD TO CALENDAR | PERMALINK
On Wednesday 29 April 2026 at 12:00-13:00 UTC the Internet Corporation for Assigned Names and Numbers (ICANN) will host a technical webinar 'EMEA: Phishing and DNS Abuse - Operational Blindspots'.
This presentation examines phishing and DNS abuse through real-world attack cases — traci
-
WEBINAR 29 APR 12:00 UTC – ICANN EMEA: Phishing and DNS Abuse – Operational Blindspots
REGISTER | ADD TO CALENDAR | PERMALINK
On Wednesday 29 April 2026 at 12:00-13:00 UTC the Internet Corporation for Assigned Names and Numbers (ICANN) will host a technical webinar 'EMEA: Phishing and DNS Abuse - Operational Blindspots'.
This presentation examines phishing and DNS abuse through real-world attack cases — traci
-
How to Protect Against Phishy Top-level Domains, Part 2
In a previous article, we explained that risk-averse organizations routinely adopt TLD blocking as a defense against cyber-attacks.
We EMPHASIZED why this is a last resort measure and offered examples of TLDs that were persistently associated with major phishing and scam attacks in CY2025. We also describe how to make an informed TLD blocking decision.
In our earlier post, we explained how organizations or individuals could use Cisco’s OpenDNS service to adopt TLD blocking. Today, we’ll be taking a look at how NextDNS could be used to block TLDs.
https://interisle.substack.com/p/how-to-protect-against-phishy-top-b41
#phishing #cybercrime #blocklisting #tld #domainnames #dnsabuse
-
How to Protect Against Phishy Top-level Domains, Part 2
In a previous article, we explained that risk-averse organizations routinely adopt TLD blocking as a defense against cyber-attacks.
We EMPHASIZED why this is a last resort measure and offered examples of TLDs that were persistently associated with major phishing and scam attacks in CY2025. We also describe how to make an informed TLD blocking decision.
In our earlier post, we explained how organizations or individuals could use Cisco’s OpenDNS service to adopt TLD blocking. Today, we’ll be taking a look at how NextDNS could be used to block TLDs.
https://interisle.substack.com/p/how-to-protect-against-phishy-top-b41
#phishing #cybercrime #blocklisting #tld #domainnames #dnsabuse
-
Feb 26 2026 – At-Large Meets OCTO-SSR
VIDEO | AUDIO | RECAP | SLIDES | ARCHIVE | PERMALINK
On February 26, 2026, ICANN At-Large hosted a webinar 'At-Large Meets OCTO-SSR'. Siôn Lloyd of Office of the Chief Technology Officer (OCTO) Internet Identifier System Security, Stability, and Resiliency Research (SSR) team recapped an ICANN 83 session introducing OCTO-SSR's work. Topics include tools such as ICANN Domain Me
-
Feb 26 2026 – At-Large Meets OCTO-SSR
VIDEO | AUDIO | RECAP | SLIDES | ARCHIVE | PERMALINK
On February 26, 2026, ICANN At-Large hosted a webinar 'At-Large Meets OCTO-SSR'. Siôn Lloyd of Office of the Chief Technology Officer (OCTO) Internet Identifier System Security, Stability, and Resiliency Research (SSR) team recapped an ICANN 83 session introducing OCTO-SSR's work. Topics include tools such as ICANN Domain Me
-
WEBINAR 27 MAY 12:00 UTC – What Makes a DNS Abuse Complaint to ICANN Actionable: Insights and Common Challenges
REGISTER | ADD TO CALENDAR | PERMALINK
On 27 May 2026, at 12:00-13:00 UTC, ICANN Contractual Compliance will host a webinar 'What Makes a DNS Abuse Complaint to ICANN Actionable: Insights and Common Challenges'. Case studies will be explored, plus there will be a walkthrough of ICANN's Step-by-Step Guid
-
WEBINAR 27 MAY 12:00 UTC – What Makes a DNS Abuse Complaint to ICANN Actionable: Insights and Common Challenges
REGISTER | ADD TO CALENDAR | PERMALINK
On 27 May 2026, at 12:00-13:00 UTC, ICANN Contractual Compliance will host a webinar 'What Makes a DNS Abuse Complaint to ICANN Actionable: Insights and Common Challenges'. Case studies will be explored, plus there will be a walkthrough of ICANN's Step-by-Step Guid
-
WEBINAR APR 14 – At-Large – Overview on DNS Abuse Mitigation
REGISTER | ADD TO CALENDAR | PERMALINK
On Tuesday, 14 April 2026, at 13:00-14:15 UTC, ICANN At-Large will host a webinar 'Overview on DNS Abuse Mitigation' to discuss and help shape the At-Large agenda in its combat against DNS Abuse.
DNS Abuse mitigation remains as a key focus area for the ALAC and At-Large community. It is generally accepted that D
-
WEBINAR APR 14 – At-Large – Overview on DNS Abuse Mitigation
REGISTER | ADD TO CALENDAR | PERMALINK
On Tuesday, 14 April 2026, at 13:00-14:15 UTC, ICANN At-Large will host a webinar 'Overview on DNS Abuse Mitigation' to discuss and help shape the At-Large agenda in its combat against DNS Abuse.
DNS Abuse mitigation remains as a key focus area for the ALAC and At-Large community. It is generally accepted that D
-
Cybercrime Reported in March 2026: Where Criminals are Acquiring Resources for Phishing, Malware and Spam Attacks.
Interisle publishes quarterly data about cybercrime activity (for phishing, malware, and spam) at the Cybercrime Information Center.
Here we look at cybercrime activity for the month of March 2026. We point out anything that strikes us as particularly interesting in overall numbers as well as significant changes in ranking for Top Level Domains (TLDs), Registrars, and Hosting Networks.
https://interisle.substack.com/p/cybercrime-reported-in-march-2026
-
Cybercrime Reported in March 2026: Where Criminals are Acquiring Resources for Phishing, Malware and Spam Attacks.
Interisle publishes quarterly data about cybercrime activity (for phishing, malware, and spam) at the Cybercrime Information Center.
Here we look at cybercrime activity for the month of March 2026. We point out anything that strikes us as particularly interesting in overall numbers as well as significant changes in ranking for Top Level Domains (TLDs), Registrars, and Hosting Networks.
https://interisle.substack.com/p/cybercrime-reported-in-march-2026
-
Mar 9 2026 – ICANN 85 – GNSO: ISPCP Outreach Session
VIDEO | RECAP | ARCHIVE | PERMALINK
On March 9 2026, the Internet Service Provider and Connectivity Provider Constituency (ISPCP ) of the Generic Name Supporting Organization (GNSO) organized an Outreach Session at the ICANN 85 Community Forum in Mumbai. AI-driven analytics are transforming abuse detection and incident response. Thi
#post #2026 #ai #DnsAbuse #GNSO #ICANN #ispcp #UniversalAcceptance
-
Mar 9 2026 – ICANN 85 – GNSO: ISPCP Outreach Session
VIDEO | RECAP | ARCHIVE | PERMALINK
On March 9 2026, the Internet Service Provider and Connectivity Provider Constituency (ISPCP ) of the Generic Name Supporting Organization (GNSO) organized an Outreach Session at the ICANN 85 Community Forum in Mumbai. AI-driven analytics are transforming abuse detection and incident response. Thi
#post #2026 #ai #DnsAbuse #GNSO #ICANN #ispcp #UniversalAcceptance
-
If you’re using data from URLAbuse (urlabuse.com), don’t miss our upcoming topDNS Best Practice Series webinar! 🚀
📅 Date & Time: 08 October 2025
🌐 Topic: How is DNS Abuse actually measured?
We’ll cover:
✅ The latest updates to the URLAbuse system
✅ How DNS abuse is measured in practice
✅ A first look at our brand-new platform 🎉Speakers:
Maciej Korczynski (KOR Labs)
Sourena Maroofi (URLAbuse)
Rowena Schoo (NetBeacon Institute)
🔹 Moderated by Lars Steffen (eco – Association of the Internet Industry)
🔗 More details & registration: https://topdns.eco.de/events-archive/topdns-best-practice-series-how-is-dns-abuse-actually-measured/If you work in cybersecurity, DNS operations, or anti-abuse, this is a great opportunity to learn, ask questions, and get a first look at what’s next.
#DNS #DNSAbuse #CyberSecurity #Infosec #Webinar #URLAbuse #topDNS
-
Phishing Domain Lifecycles
Phishers use a lot of domain names.
Our research shows that most phishing domains are registered by the phishers, often in bulk.
Phishers only have one purpose for these names: point them to fake pages and profit from victims lured there for as long as they can.
Investigators are constantly reporting phishing domains and these are blocklisted or shut down. Ideally, phishing domains have short lifetimes.
Is this conclusion fact or folklore?
Matt Piscitello begins a series of articles that look phishing domain lifecycles and lifetimes in https://interisle.substack.com/p/phishing-domain-lifecycles?r=59cehk
-
Phishing Domain Lifecycles
Phishers use a lot of domain names.
Our research shows that most phishing domains are registered by the phishers, often in bulk.
Phishers only have one purpose for these names: point them to fake pages and profit from victims lured there for as long as they can.
Investigators are constantly reporting phishing domains and these are blocklisted or shut down. Ideally, phishing domains have short lifetimes.
Is this conclusion fact or folklore?
Matt Piscitello begins a series of articles that look phishing domain lifecycles and lifetimes in https://interisle.substack.com/p/phishing-domain-lifecycles?r=59cehk
-
Phishing in the 2020s: What Can be Done to Reduce Phishing Attacks?
In this post we’ll look at what users can do to avoid becoming victims of phishing and, importantly, what domain name, subdomain, and hosting providers need to be doing to prevent criminals from using their services for malicious activities.
https://interisle.substack.com/p/phishing-in-the-2020s-what-can-be
You'll find more detailed recommendations in our Phishing Landscape Study
-
Phishing in the 2020s: What Can be Done to Reduce Phishing Attacks?
In this post we’ll look at what users can do to avoid becoming victims of phishing and, importantly, what domain name, subdomain, and hosting providers need to be doing to prevent criminals from using their services for malicious activities.
https://interisle.substack.com/p/phishing-in-the-2020s-what-can-be
You'll find more detailed recommendations in our Phishing Landscape Study
-
Phishing in the 2020s: Hosting Networks
In previous posts we looked at top-level domains and domain registrars that phishers most exploited over the past 5 years. In this post, we look at the hosting networks (ASNs) with the highest numbers of phishing attacks reported.
https://interisle.substack.com/p/phishing-in-the-2020s-hosting-networks
#phishing #ASN #hosting #cybercrime #dnsabuse #cybersecurity
If you like what you've been reading, subscribe.
-
Phishing in the 2020s: Hosting Networks
In previous posts we looked at top-level domains and domain registrars that phishers most exploited over the past 5 years. In this post, we look at the hosting networks (ASNs) with the highest numbers of phishing attacks reported.
https://interisle.substack.com/p/phishing-in-the-2020s-hosting-networks
#phishing #ASN #hosting #cybercrime #dnsabuse #cybersecurity
If you like what you've been reading, subscribe.
-
Case study: How a single spam campaign affects service provider reputation
Matt Piscitello takes a close look at a spam campaign involving bulk registrations during the month of August 2025. He explains how #Interisle establishes evidence of bulk registration behavior, identifies what operators were affected, and discusses aspects of reputational harm resulting from the campaign.
https://interisle.substack.com/p/case-study-how-a-single-spam-campaign
#spam #bulkregistrations #dnsabuse #reputation #cybercrime #interisle
-
Case study: How a single spam campaign affects service provider reputation
Matt Piscitello takes a close look at a spam campaign involving bulk registrations during the month of August 2025. He explains how #Interisle establishes evidence of bulk registration behavior, identifies what operators were affected, and discusses aspects of reputational harm resulting from the campaign.
https://interisle.substack.com/p/case-study-how-a-single-spam-campaign
#spam #bulkregistrations #dnsabuse #reputation #cybercrime #interisle
-
Cybercrime Activity Reported in August 2025
Interisle's monthly look at cybercrime activity during August 2025 is now posted. We point out anything that strikes us as particularly interesting in overall numbers as well as significant changes in ranking for Top Level Domains (TLDs), Registrars, and Hosting Networks.
https://interisle.substack.com/p/cybercrime-reported-in-august-2025
-
Cybercrime Activity Reported in August 2025
Interisle's monthly look at cybercrime activity during August 2025 is now posted. We point out anything that strikes us as particularly interesting in overall numbers as well as significant changes in ranking for Top Level Domains (TLDs), Registrars, and Hosting Networks.
https://interisle.substack.com/p/cybercrime-reported-in-august-2025
-
Phishing Landscape 2025 Report Released
Phishing Rises to New High of Nearly 2 Million Attacks over 12 Months According to New Interisle Report
Key report findings include:
Phishing attacks rose to 1.96 million a year, a 182% increase since 2021.
Domain Name Abuse Surges to New High: The total number of domain names used in phishing attacks rose 38% to over 1.5 million—the highest ever recorded.
Cybercriminal Domain Purchasing Soars: 77% of all domain names used in phishing attacks were maliciously registered by cybercriminals.
Bulk Registration Enables More Attacks: 37% of all phishing domains were acquired through bulk domain name registration services.
Over half of all phishing sites were hosted by U.S.-based companies. The U.S. has been the top hosting location for phishing for five consecutive years.
The report also examines how domain registration requirements and pricing affect phishing scores in gTLDs and ccTLDs.
https://interisle.substack.com/p/phishing-landscape-2025-report-released
-
Phishing Landscape 2025 Report Released
Phishing Rises to New High of Nearly 2 Million Attacks over 12 Months According to New Interisle Report
Key report findings include:
Phishing attacks rose to 1.96 million a year, a 182% increase since 2021.
Domain Name Abuse Surges to New High: The total number of domain names used in phishing attacks rose 38% to over 1.5 million—the highest ever recorded.
Cybercriminal Domain Purchasing Soars: 77% of all domain names used in phishing attacks were maliciously registered by cybercriminals.
Bulk Registration Enables More Attacks: 37% of all phishing domains were acquired through bulk domain name registration services.
Over half of all phishing sites were hosted by U.S.-based companies. The U.S. has been the top hosting location for phishing for five consecutive years.
The report also examines how domain registration requirements and pricing affect phishing scores in gTLDs and ccTLDs.
https://interisle.substack.com/p/phishing-landscape-2025-report-released
-
Phishing Trends: May - July 2025
Results for Phishing activity for the period May 1– July 31, 2025, are now available at the Cybercrime Information Center.
Phishing activity modestly declined in in early 2025, but it returned with vengeance in the spring and early summer:
- Phishing activity more than doubled to a staggering 1.3M attacks.
- Domains reported for phishing activity nearly doubled to just over 1M.
- Malicious domain registrations increased by 81%.
We take a long, hard look at ICANN's problem child... Dominet (HK).
https://interisle.substack.com/p/phishing-trends-may-july-2025
-
Phishing Trends: May - July 2025
Results for Phishing activity for the period May 1– July 31, 2025, are now available at the Cybercrime Information Center.
Phishing activity modestly declined in in early 2025, but it returned with vengeance in the spring and early summer:
- Phishing activity more than doubled to a staggering 1.3M attacks.
- Domains reported for phishing activity nearly doubled to just over 1M.
- Malicious domain registrations increased by 81%.
We take a long, hard look at ICANN's problem child... Dominet (HK).
https://interisle.substack.com/p/phishing-trends-may-july-2025