https://ift.tt/prcPCqG How To Prepare For Your Virtual Doctor Visit To Get The Most From Your Consultation
https://ift.tt/prcPCqG How To Prepare For Your Virtual Doctor Visit To Get The Most From Your Consultation
- Get link
- X
- Other Apps
Unknown threat actors have compromised multiple domain names registered with Squarespace. The incident, which began around July 10, 2024, has affected numerous domains that were transferred to Squarespace following its acquisition of Google Domains in September 2023.
On September 7, 2023, Squarespace acquired all domain registration data and customers from Google Domains. This migration process, which has been ongoing for several months, involved automatically creating Squarespace accounts for each domain based on the email addresses associated with the Google Domains accounts, including admin, tech, and billing contacts.
The attackers have exploited vulnerabilities in the migration process, gaining unauthorized access to Squarespace accounts. The exact method of access remains unclear, but potential vectors include:
Are you from SOC/DFIR Teams? - Sign up for a free ANY.RUN account! to Analyse Advanced Malware Files
Once inside the Squarespace accounts, the threat actors escalated their privileges by taking over DNS records. This involved changing nameservers or directly editing DNS records to redirect domain traffic and intercept emails by altering MX records. This allowed the attackers to perform password resets and gain further control over associated accounts.
The breach has had a widespread impact, particularly on decentralized finance (DeFi) platforms. Notable affected entities include Compound Finance, Celer Network, and Pendle Finance, among others. These platforms experienced DNS hijacking, redirecting users to malicious sites designed to steal funds and sensitive information.
Squarespace has issued several recommendations to mitigate the impact and prevent further unauthorized access:
Security researchers have identified specific indicators of compromise associated with the attack:
The investigation into the breach is ongoing, with security experts working to understand the full extent of the compromise and the exact methods used by the attackers. Squarespace has been urged to enhance its security measures and provide more robust support to affected customers.
As the situation develops, users are advised to exercise extreme caution when interacting with any potentially compromised domains and to stay updated with the latest security advisories from Squarespace and other relevant authorities.
“Is Your System Under Attack? Try Cynet XDR: Automated Detection & Response for Endpoints, Networks, & Users!”- Free Demo
The post Hackers Compromised Multiple Squarespace Customers’ Domain Names appeared first on Cyber Security News.
Comments
Post a Comment
Commenter vous !