DNS attacks “imminent,” warns Microsoft
Microsoft has issued a second warning about DNS spoofing, saying that the publication of exploit code has increased the risk of attack.
DNS attacks are "likely imminent," Microsoft has warned in a security bulletin.
A massive domain name system (DNS) spoofing attack hit earlier this month, which took advantage of vulnerabilities in DNS clients and servers, which enable an attacker to redirect traffic. For Microsoft, it affects Windows 2000 and XP, as well as Windows Server 2003 and 2008.
Microsoft said that the publication online of the detailed exploit code has increased the risk, writing that "attacks are likely imminent due to the publicly posted proof of concept".
But the warning noted that Microsoft has not seen any of its customers hit by attacks using the exploit code.
The software giant warned its customers to update their systems using a previously released patch.
Last week, the researcher who found the DNS hole warned that system administrators have not done enough to protect users.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
Freelance journalist Nicole Kobie first started writing for ITPro in 2007, with bylines in New Scientist, Wired, PC Pro and many more.
Nicole the author of a book about the history of technology, The Long History of the Future.
-
Cognizant launches dedicated EMEA AI unit to accelerate enterprise adoptionThe new business unit will help organizations move agentic AI projects from pilot into production
-
Geekom IT13 Max (2026) reviewReviews There's plenty of power and a breadth of connectivity options in this small but mighty mini PC – all underlined by an aggressively attractive price
-
DNS loophole could allow hackers to carry out “nation-state level spying”News Sensitive data could be accessed from corporate networks using vulnerability
-
What is DMARC and how can it improve your email security?In-depth Protect your customers and brand rep with this email authentication protocol for domain spoofing
-
Cloudflare and Apple launch privacy-focused DNS protocolNews Oblivious DNS-over-HTTPS safeguards users' browsing habits from third parties
-
D-Link routers under siege from months-long DNS hackNews The attackers are running malicious IPs through a Google Cloud Platform virtual machine
-
SMBs warned over corrupted SOHO router riskNews Team Cymru researchers claim 300,000 routers may have had their DNS settings changed by cyber criminals.
-
Will the FBI close down your online business this March?In-depth In tackling the DNSChanger botnet, the FBI may take a load of businesses offline. Davey Winder is, unsurprisingly, anxious...
-
DNS Changer botnet smashed in major cyber crime bustNews A botnet that is thought to have earned its controllers $14 million is dismantled.
-
‘Climate of fear’ is best weapon against cyber crimeNews A member of the Serious Organised Crime Agency has claimed cyber criminals are best tackled through fear of prosecution.