Morningstar Underminr Vulnerability Threatens 88 Million Domains with Brand Hijacking
Article Content
- •Underminr affects around 88 million domains, primarily in the US, Canada, and the UK.
- •The vulnerability allows attackers to hijack brand reputations by manipulating web requests.
- •Active exploitation is ongoing, with potential for AI-driven malware campaigns to escalate attacks.
ADAMnetworks has identified a new vulnerability named Underminr that affects approximately 88 million domains globally, with a heightened risk in the US, Canada, and the UK. This exploit allows attackers to manipulate web requests, effectively hijacking the brand reputations of legitimate websites. It circumvents existing defenses that neutralized legacy domain fronting techniques, making attacks largely invisible to security measures. The vulnerability is currently under active exploitation, with potential for AI-driven malware campaigns to scale attacks significantly. ADAMnetworks has initiated responsible disclosure, collaborating with industry partners to develop detection tools and provide real-time vulnerability checks for domain owners. The exploit's ability to evade protective DNS mechanisms poses a critical risk to internet infrastructure.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (13)
Following this threat?
Track ADAMnetworks in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical Cisco FMC Vulnerabilities Under Active Exploitation Cisco's Secure Firewall Management Center (FMC) Software has two critical vulnerabilities, CVE-2026-20079 and CVE-2026-20316, that are currently being exploited by state-sponsored and ransomware actors. CVE-2026-20079, rated 10.0 on the CVSS scale, allows unauthenticated remote attackers to bypass authentication and…
BlueMoon Exploit Kit Targeting Chrome and Windows by Multiple State Actors A new exploit kit named BlueMoon has been rapidly adopted by at least four espionage groups, primarily linked to China, exploiting vulnerabilities in Google Chrome and Microsoft Windows. The first observed use of BlueMoon was on August 28, 2026, by the China-aligned threat actor TA412, with subsequent adoption by…