Skip to main content
  1. Home
  2. Computing
  3. News

Hackers begin attack using simple web flaw which affects most of the Internet

Add as a preferred source on Google

Last week reports began to appear that a new vulnerability had been found in the Bind DNS server software. It was said to be such a simple denial of service exploit, and one that could affect so many different servers around the world, that unless those responsible for keeping systems updated patched it in short order, many of the most popular Internet destinations could be downed. It’s now just a few days later, and attacks have already begun.

“Because of its severity we’ve been actively monitoring to see when the exploit would be live,” Daniel Cid, founder and CTO of security firm Sucuri said in a blog post. He went on to point out that with the DNS server being such a major component of the Internet’s infrastructure, any downing of them on a large scale could see people’s ability to not only visit certain sites disappear, but could also affect email accounts.

Recommended Videos

Related: Logjam HTTPS exploit downgrades security to get at your data

Fortunately for those only just now discovering the problem, there is a simple fix. A patch was recently released that corrects the issue (available via Ars) and is currently the only method available to shore up a server’s defenses.

There is a method to discover if your server has been affected by the bug. To do so, check your logs for any mentions of “ANY TKEY.” If that turns up, chances are the DNS has been affected.

In reality, searching the logs for any mention of a TKEY request isn’t a bad plan, since they are not a common occurrence and are likely to indicate the exploitation of the security loop hole.

Keeping software up to date is always the best practice for protecting systems, but it’s not always easy with the way these flaws pop up.

Jon Martindale
Jon Martindale covers how to guides, best-of lists, and explainers to help everyone understand the hottest new hardware and…
OpenAI’s powerful AI agents ran amok and hacked multiple services on their own
The agents escaped their testing constraints, raided Hugging Face for answers and used compromised accounts across four services to support the attack
The ChatGPT name next to an OpenAI logo on a black and white background.

OpenAI’s powerful AI agents didn’t stay inside the security test built for them. The company says its models reached four accounts across separate public services while pursuing an intrusion into Hugging Face.

Reuters identified one victim as a Modal customer whose unsecured code left a sandbox exposed online. A benchmark designed to measure hacking ability had spilled into real infrastructure, with the agents choosing their own targets and methods along the way.

Read more
Mark Zuckerberg wants AI superintelligence in everyone’s hands
Meta says it can bring advanced AI to billions of people, though access won’t give users control over the infrastructure, safeguards, or limits behind it
Body Part, Finger, Hand

In an opinion essay for The Wall Street Journal, Mark Zuckerberg lays out a modest ambition for Meta’s AI. He wants to put superintelligence in everyone’s hands, giving ordinary people technology powerful enough to improve their health or help them work.

Zuckerberg presents personal superintelligence as an alternative to advanced AI being controlled by a few institutions. Meta can certainly distribute it on a scale few companies could match. What users would receive is an assistant built and governed somewhere else, with its most important decisions made for them.

Read more
The US government just blacklisted foreign-made robots and power inverters
Uncle Sam just said no thanks to foreign robots and power inverters, at least the new ones.
robots with black background

Months after banning all foreign routers and subsequently approving some of them in weeks, the FCC is back at it again, and this time robots and power inverters are in its crosshairs. 

The Federal Communications Commission has added two new entries to its Covered List, and this time the targets are advanced robots and power inverters made outside the US. The move follows a White House-led security review that flagged both categories as genuine risks to national security.

Read more