home.social

#fastflux — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #fastflux, aggregated by home.social.

fetched live
  1. I know people like using wildcard domains, but don't.🫠 They're a constant attack vector.

    Newest callrd even uses MX to do discovery. Very clever. Terrible if impacted. ⚰️

    arstechnica.com/security/2025/

  2. I know people like using wildcard domains, but don't.🫠 They're a constant attack vector.

    Newest callrd #fastflux even uses MX to do discovery. Very clever. Terrible if impacted. ⚰️

    arstechnica.com/security/2025/

  3. 🤖 CYBERSECURITY
    🔴 NSA Warns of “Fast Flux” Botnets

    🔸 Rapidly rotating IPs & domains make detection harder.
    🔸 Nation-states & ransomware groups use it to evade takedowns.
    🔸 Wildcard DNS creates fake subdomains for hidden C2 servers.

    #Cybersecurity #NSA #Botnets #FastFlux #DNS #NationalSecurity #Malware #Ransomware

  4. 🤖 CYBERSECURITY
    🔴 NSA Warns of “Fast Flux” Botnets

    🔸 Rapidly rotating IPs & domains make detection harder.
    🔸 Nation-states & ransomware groups use it to evade takedowns.
    🔸 Wildcard DNS creates fake subdomains for hidden C2 servers.

    #Cybersecurity #NSA #Botnets #FastFlux #DNS #NationalSecurity #Malware #Ransomware

  5. CISA: NSA, CISA, FBI, and International Partners Release Cybersecurity Advisory on “Fast Flux,” a National Security Threat. “Today, CISA … released joint Cybersecurity Advisory Fast Flux: A National Security Threat (PDF, 841 KB). This advisory warns organizations, internet service providers (ISPs), and cybersecurity service providers of the ongoing threat of fast flux enabled malicious […]

    https://rbfirehose.com/2025/04/05/cisa-nsa-cisa-fbi-and-international-partners-release-cybersecurity-advisory-on-fast-flux-a-national-security-threat/

  6. #NSA warns “fast flux” threatens national #security. What is fast flux anyway?

    A technique that hostile nation-states & financially motivated #ransomware groups are using to hide their operations poses a threat to critical #infrastructure & national security, the NSA has warned.

    The technique is known as #FastFlux. It allows decentralized networks operated by threat actors to hide their infrastructure and survive takedown attempts that would otherwise succeed
    #privacy

    arstechnica.com/security/2025/

  7. #NSA warns “fast flux” threatens national #security. What is fast flux anyway?

    A technique that hostile nation-states & financially motivated #ransomware groups are using to hide their operations poses a threat to critical #infrastructure & national security, the NSA has warned.

    The technique is known as #FastFlux. It allows decentralized networks operated by threat actors to hide their infrastructure and survive takedown attempts that would otherwise succeed
    #privacy

    arstechnica.com/security/2025/

  8. NSA warns “fast flux” threatens national security. What is fast flux anyway? - A technique that hostile nation-states and financially motivated ransomwar... - arstechnica.com/security/2025/ #security #fastflux #biz&it

  9. NSA warns “fast flux” threatens national security. What is fast flux anyway? - A technique that hostile nation-states and financially motivated ransomwar... - arstechnica.com/security/2025/ #security #fastflux #biz&it

  10. In case you're not up-to-speed on what #FastFlux #DNS is, it's part of the arms race between attackers and defenders:

    THREAT ACTOR: This is my C2 IP
    BLUE TEAMER: Blocked at the firewall

    TA: Ok, well then, here's my C2 domain. I've rented 50k botnet nodes to use as proxies to my real C2 infrastructure, and I'm going to keep changing the IP the domain points to basically forever. Good luck blocking that. [FAST FLUX]
    BT: Blocked the domain's nameserver's IPs at the firewall

    🧵

    #cybersecurity

  11. In case you're not up-to-speed on what #FastFlux #DNS is, it's part of the arms race between attackers and defenders:

    THREAT ACTOR: This is my C2 IP
    BLUE TEAMER: Blocked at the firewall

    TA: Ok, well then, here's my C2 domain. I've rented 50k botnet nodes to use as proxies to my real C2 infrastructure, and I'm going to keep changing the IP the domain points to basically forever. Good luck blocking that. [FAST FLUX]
    BT: Blocked the domain's nameserver's IPs at the firewall

    🧵

    #cybersecurity

  12. 🛡️ NSA and global cybersecurity agencies warn that #FastFlux, a tactic used to hide malicious servers, is now a national security threat.

    Read: hackread.com/nsa-allies-fast-f

    #CyberSecurity #DNS #InfoSec #NSA

  13. 🛡️ NSA and global cybersecurity agencies warn that #FastFlux, a tactic used to hide malicious servers, is now a national security threat.

    Read: hackread.com/nsa-allies-fast-f

    #CyberSecurity #DNS #InfoSec #NSA

  14. Friendly reminder that you should be blocking all newly registered domains for your end users. Free lists like the NRD (github.com/xRuffKez/NRD) exist. Microsoft Defender for Endpoint also has a built in list you can enable via policy.

    IMO everyone should do 365 days but even 30 or 90 will save you so much headache.
    #DNS #ThreatIntel #FastFlux

  15. Friendly reminder that you should be blocking all newly registered domains for your end users. Free lists like the NRD (github.com/xRuffKez/NRD) exist. Microsoft Defender for Endpoint also has a built in list you can enable via policy.

    IMO everyone should do 365 days but even 30 or 90 will save you so much headache.
    #DNS #ThreatIntel #FastFlux