blog.talosintelligence.com Cisco Talos Reports Ongoing Sea Turtle DNS Hijacking Campaign
Article Content
- •Sea Turtle campaign targets DNS systems of national security organizations.
- •At least 40 organizations across 13 countries have been compromised since 2017.
- •New DNS hijacking techniques have emerged, increasing the threat level.
Cisco Talos has identified a persistent cyber threat campaign named 'Sea Turtle' that manipulates DNS systems, primarily targeting national security organizations in the Middle East and North Africa. The campaign, which began as early as January 2017, has compromised at least 40 organizations across 13 countries. Recent findings indicate that the actors behind Sea Turtle have regrouped and are employing a new DNS hijacking technique, compromising name server records to respond to DNS requests with falsified A records. This new technique has only been observed in a few targeted operations, including a country code top-level domain (ccTLD) registry. The ongoing threat underscores the potential for broader attacks on the global DNS system, which could undermine internet trust and stability. Cisco Talos emphasizes the need for responsible nations to establish norms protecting the DNS system from such attacks.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Sea Turtle and CVE-2009-1151 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What organizations are targeted?
What is the new technique used by Sea Turtle?
What should organizations do to protect against this threat?
Continue Reading
Critical Authentication Bypass in Rejetto HFS Exploited Within 24 Hours Anthropic's Mythos model identified a critical authentication bypass in Rejetto HTTP File Server (HFS), tracked as CVE-2026-61500, allowing remote code execution. Discovered by Horizon3 researcher Zach Hanley, the flaw was revealed on September 27, 2026, and exploitation began within 24 hours, with attacks traced to…
Critical Citrix NetScaler Zero-Day Vulnerabilities Exploited In late September 2026, two critical zero-day vulnerabilities (CVE-2026-88771 and CVE-2026-88772) in Citrix NetScaler ADC and Gateway were actively exploited, allowing remote code execution. The Cybersecurity and Infrastructure Security Agency (CISA) added these CVEs to its Known Exploited Vulnerabilities catalog on…