Skip to content
New TypoFinder Exploit Targets Domain Security

New TypoFinder Exploit Targets Domain Security

First seen 18 Sep 2026, 18:24 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 18, 2026 at 18:54 UTC
  • TypoFinder exploits domain name vulnerabilities using keyboard proximity and glyph similarity.
  • The tool supports checks against Google Safe Browsing API for enhanced threat detection.
  • Users must obtain an API key to utilize the full capabilities of TypoFinder.

A new exploit named TypoFinder has been released, designed to manipulate domain names by replacing characters with adjacent keyboard symbols and similar-looking glyphs. This tool can also flip bits in legitimate domains, aiding in bitsquatting attacks, and checks websites against the Google Safe Browsing API for phishing and malware detection. Users must register for a Google Safe Browsing API key to utilize the tool effectively. The exploit's release comes with a script for updating data sources to ensure accurate threat detection. The impact of this tool could be significant as it enables attackers to create deceptive domains that closely resemble legitimate ones, potentially affecting various organizations and users online.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-18
TypoFinder exploit released
The TypoFinder tool was published, allowing manipulation of domain names for phishing attacks.
Sploitus

More articles in this cluster (2)