Sploitus New TypoFinder Exploit Targets Domain Security
Article Content
- •TypoFinder exploits domain name vulnerabilities using keyboard proximity and glyph similarity.
- •The tool supports checks against Google Safe Browsing API for enhanced threat detection.
- •Users must obtain an API key to utilize the full capabilities of TypoFinder.
A new exploit named TypoFinder has been released, designed to manipulate domain names by replacing characters with adjacent keyboard symbols and similar-looking glyphs. This tool can also flip bits in legitimate domains, aiding in bitsquatting attacks, and checks websites against the Google Safe Browsing API for phishing and malware detection. Users must register for a Google Safe Browsing API key to utilize the tool effectively. The exploit's release comes with a script for updating data sources to ensure accurate threat detection. The impact of this tool could be significant as it enables attackers to create deceptive domains that closely resemble legitimate ones, potentially affecting various organizations and users online.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical GitLab CVE-2026-85706 Exploited; Microsoft Issues Record 974 Patches A critical CVE-2026-85706 path-traversal vulnerability in GitLab (CVSS 10.0) was exploited in the wild just hours after its disclosure on September 12, 2026. Microsoft released its largest-ever patch batch, addressing 974 vulnerabilities, including several actively exploited Windows flaws. The GitLab flaw allows…