Securitybrief.Au Netcraft Launches AI Tool to Disrupt Malicious Domains Preemptively
Article Content
- •Netcraft's Preemptive Domain Disruption targets domains before phishing campaigns launch.
- •90% of malicious domains are taken down within 24 hours of detection.
- •The service uses AI to identify and disrupt malicious infrastructure proactively.
On March 17, 2026, Netcraft announced the launch of its AI-powered Preemptive Domain Disruption service, designed to identify and take down attacker-controlled domains before they are utilized in phishing and Business Email Compromise (BEC) campaigns. This service targets the critical window between domain registration and activation, where attackers often prepare their infrastructure. Early results indicate that approximately 90% of malicious domains can be removed within 24 hours, with one enterprise customer reporting over 21,000 takedowns in three months. The tool employs infrastructure clustering and campaign fingerprinting to detect domains showing signs of preparation for abuse, even before they host malicious content. This proactive approach aims to redefine cyber threat prevention as attackers increasingly leverage AI to enhance their operations. The service is part of a broader shift towards earlier intervention in cybercrime, reflecting the growing urgency in combating brand impersonation and credential theft. Netcraft will also share data from this service with the Anti-Phishing Working Group to enhance collective defense efforts.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…