Back to Feed
VulnerabilitiesJul 30, 2026

‘DangleGeddon’: AI Could Weaponize Forgotten DNS Records at Global Scale

Researchers warn AI could weaponize dangling DNS takeovers at nation-state scale against governments, banks, and supply

Summary

Security firm Silent Push published research on 'DangleGeddon,' demonstrating how AI can dramatically scale dangling DNS takeover attacks. Using Claude Opus to automate discovery, script generation, and infrastructure setup, researchers identified hundreds of exploitable targets across US federal government, major banks like Société Générale, Ford, and Eli Lilly. The research highlights how AI acts as a force multiplier for subdomain takeovers, enabling rapid weaponization of a known but widespread vulnerability caused by poor DNS hygiene and orphaned cloud resources.

Full text

A ‘dangling DNS takeover’ is a known attack method that allows a bad actor to take over a subdomain whenever a DNS record points to a cloud resource after the resource has been deleted. The link is left ‘dangling’, pointing to nothing. It is a simple case of poor security hygiene, but not uncommon. If an attacker can find that link – which is not difficult with internet scans – and reconstruct the cloud resource but now under his own control, he can then gain access to the subdomain. Historically, the attack has primarily been used by cybercriminals for financial gain. Security firm Silent Push asked itself, “What if we looked at it the same way a trained nation-state attacker would?” Nation states prioritize the generation of chaos and disruption over monetization; and have a new tool at their disposal – artificial intelligence. The result of its consequent research has now been published. AI proved to be a force multiplier for dangling DNS takeover in the project and research Silent Push calls ‘DangleGeddon’. It massively expanded domain and subdomain discovery. Claude Opus 5 was used for context enriched takeover script generation, targeting 12,500 domains. AI was also used to filter out those resources that lacked allocation or DNS registration, reducing the initial large dataset to a precise list of several hundred exploitable targets. This process found new targets, broadening the attack surface beyond what was known to possible human attackers. The researchers were then able to automate infrastructure build-out for exploitation, “setting us,” write the researchers, “one button push away from Dangle Day.” In short, it continues, “The hypothetical scenario of a DangleGeddon became a very real threat in minutes.”Advertisement. Scroll to continue reading. The researchers ran a range of safe tests to examine what could have become available to attackers had they proceeded. It disclosed its actions to the domain owners by leaving a “Security Notice: This subdomain had a dangling DNS record pointing to a deprovisioned cloud storage endpoint, leaving it vulnerable to subdomain takeover. It is being held by a security researcher solely to prevent abuse (e.g., phishing or malware hosting) while the owner removes the stale record. No data is collected on this page.” In one US federal government domain, where a dangling record pointed to an unassigned Azure blob storage container, takeover allowed the creation of phishing pages bypassing government trust filters. “The domain can now bypass automated safeguards by leveraging the trust associated with .gov domains,” report the researchers. In banking, the largest French bank, Société Générale. left an unassigned Azure Blob storage resource pointing to an application. In manufacturing, Fortune 500 Ford had a dangling DNS record pointing to a developmental application gateway hosted by an Azure VM. Developers’ credentials (API keys and authentication headers) could be harvested for reuse, expanding access into the company, or be used as a platform for malware hosting. In pharmaceuticals, Eli Lilly left a record pointing to an Apple device guide, which could allow an attacker to focus on a specific set of targets and events. From its research, Silent Push projected the downstream impact of this hypothetical DangleGeddon. For the government, it could affect thousands of systems and millions of employees, causing multiple disruptions, “with the potential impact on national security arguably being severe.” In banking, if DangleGeddon is applied globally, multinational firms such as Bank of America, UBS and the Bank of Montreal would suffer downstream effects including paralysis of online banking and real-time payments, as well as blocked trading platforms. In the manufacturing sector, using automotive Ford as an example, domain takeover could host malicious content and serve phishing pages, malware, or other malicious content under the legitimate car maker’s domain. Knock on effects could have catastrophic results on supply chain integration across thousands of other organizations. For Big Pharma, Silent Push warns, “The speed of a takeover cascading into a magnitude involving multiple global pharma organizations would undermine high-performance R&D, disrupt clinical trials, and pose even more serious consequences for the supply chain necessary to deliver drug and therapeutic solutions on a global scale. Estimated losses across organizations could be in the hundreds of billions.” The research from Silent Push suggests that a hypothetical DangleGeddon is eminently achievable with the assistance of AI. The process and effect of such an operation would not attract financially motivated cybercriminals, but is precisely the objective of a geopolitically adversarial nation state – to inflict cost and chaos at a massive scale. But if AI can assist in dangling DNS takeover at nation state level, it could also be used more locally by individual cybercriminals for direct monetization. The moral is simple. Silent Push has demonstrated that it behooves every organization to not leave anything dangling from their sites. Don’t be a Dangler. Related: Dangling DNS Used to Hijack Subdomains of Major Organizations Related: Chinese Hackers Have Been Probing DNS Networks Globally for Years: Report Related: Over 35k Domains Hijacked in ‘Sitting Ducks’ Attacks Related: Inside The UK’s Active Cyber Defense Program Written By Kevin Townsend Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Kevin Townsend Act Security Emerges from Stealth to Fight the Patch ProblemHacker Conversations: Tal Kollander’s Journey From Black Hat to Hack BlockerMedusaHVNC Malware Uses Hidden Windows Desktops to Evade DetectionWhat’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find OutOpenAI Fixes ChatGPT Agent Flaw That Could Let Attackers Forge an AI InsiderVibe-Coded Apps Riddled With Exploitable Security FlawsCisco Launches Low-Cost AI Models for Source Code SecurityCISO Conversations: Andreas Gaetje – From Economics to CISO at Körber AG Latest News Discern Security Raises $13 Million in Series A FundingCantina Emerges From Stealth With $8 Million in FundingOnyx Security Raises $113 Million to Control AI Agents in the EnterpriseSemiconductor Firm Analog Devices Discloses Data BreachCritical Ruflo Flaw Lets Attackers Spawn Rogue AI Swarms 1 in 5 Data Center Assets Are Within Easy Reach of AttackersUS and Allies Update SBOM GuidanceChrome 151 Patches 370 Vulnerabilities Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Closing the Exploitation Gap July 22, 2026 Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the MoveAlex Levinson has been named Executive Director at the National Collegiate Cyber Defense Competition.Hack The Box has appointed Konstantinos Dolkas as CTO and has promoted Christine Bartlett to CMO.The Department of Energy has appointed Andrew McClure as Director of the Office of Cybersecurity, Energ

Entities

Silent Push (vendor)DangleGeddon (campaign)Claude Opus (technology)Microsoft Azure (technology)Azure Blob Storage (product)