Let's talk a moment about DNS Security. With Black Hat coming up next week, DNS Security likely didn't even make it on to your bingo card. And the bad guys thank you for your inattention.
DNS related security is often one of those things that organizations tend to dismiss as housekeeping or (even worse ) SEP (Someone Else's Problem): a loose end, a minor configuration gap, something to clean up at some point not today (other higher priorities intervene). Dangling DNS records fall squarely into that category. A DNS entry pointing to a cloud resource that no longer exists seems harmless. It resolves to nothing. It just sits there.
The team at Silent Push published research that should get everyone to take notice. They call it DangleGeddon, and it demonstrates what happens when AI is turned loose on the problem of dangling DNS records at scale. Using AI tooling — including Claude Opus 5 for context-enriched script generation — researchers scanned 12,500 domains, automatically identified hundreds of exploitable dangling records, and built out the infrastructure required to take them over. The process that previously required days of manual reconnaissance was compressed into minutes. And then, in their words, they were "one button push" from triggering it.
The targets they identified were not obscure. A U.S. federal government domain with a dangling record pointing to an unassigned Azure Blob storage container could be exploited to serve phishing pages that bypass .gov trust filters. France's largest bank, Société Générale, left an Azure resource dangling and exposed. Ford had a developmental application gateway left pointing to nothing, creating a potential platform for credential harvesting or malware hosting. Eli Lilly left a record tied to an Apple device guide — a narrow but focused attack surface against a specific set of targets.
Silent Push ran these tests responsibly, leaving "security notice" pages in place of exploitation and disclosing findings to affected organizations. But the broader implication of the research is difficult to overstate. DangleGeddon is not a theoretical attack. It is not a nation-state capability that requires years of tradecraft to develop. It is a workflow that AI has made accessible — and one that scales globally with very little incremental effort.
The downstream scenarios the researchers projected are stark. A DangleGeddon applied across global banking could paralyze online transactions and trading platforms. In manufacturing, legitimate brand domains could serve malicious content across supply chains touching thousands of partner organizations. In pharmaceuticals, the disruption of R&D infrastructure and clinical trial coordination could ripple far beyond any individual organization.
What makes this particularly urgent is the underlying cause: poor DNS hygiene. Organizations spin up cloud resources, tie subdomains to them, and then decommission those resources without cleaning up the DNS records. The records persist. The attack surface grows. And now, AI can find and exploit that surface faster than human defenders can audit it.
The single takeaway that I want to leave you with: Every (meaning EVERY) organization should be auditing its DNS records — systematically, regularly, and with automation where possible — to identify and remove stale entries before someone else finds them. The bad guys know of this vulnerability. Their AI bots know of this vulnerability. And it is going to be exploited - they are actively mapping it RIGHT NOW.
DNS security will be a significant focus of EMA research in the coming months. As AI continues to transform both the threat landscape and the defensive tooling available to enterprise organizations, EMA will be examining how security and network operations teams are adapting — what architectures are working, where the gaps remain, and what capabilities are most closely correlated with resilient outcomes. Stay tuned for more.

