Attackers are buying expired domains to exploit their reputation, traffic and DNS history, using them for malware delivery, scams and C2 infrastructure. Every day, roughly 65,000 domain names that once belonged to someone else get re-registered by a new owner. Infoblox Threat Intel calls these dropcatch domains, and in the first half of 2026 they […]

Cybersecurity researchers have identified a growing trend where threat actors are acquiring expired domain names to leverage their established reputation, existing web traffic, and DNS history for malicious purposes, including malware delivery, scams, and command-and-control (C2) infrastructure. Approximately 65,000 domain names are re-registered daily after expiring, with these "dropcatch" domains accounting for nearly 20% of all new domain registrations in the first half of 2026.
Infoblox Threat Intel, which published a report on this activity, notes that one in five newly registered domains has a prior history. While some of these domains are acquired by legitimate investors or researchers, a significant portion falls into the hands of attackers who recognize the inherent value of a domain with an established past. Such domains may be viewed more favorably by security products and reputation-based algorithms than genuinely new registrations due to their age and historical signals.
The inherited value extends beyond reputation scores. Expired domains often retain residual web traffic from old backlinks, receive email intended for previous owners, appear in cached search results, and may even have lingering DNS records pointing to infrastructure no longer controlled by the original registrant. This pre-existing infrastructure provides a ready-made platform for various illicit activities.
Among generic top-level domains (gTLDs), an average of 50,400 dropcatch domains are registered daily, with 15 TLDs making up about 92% of this activity. The .net and .xyz TLDs show the highest rates, with nearly 30% of new registrations being previously registered, while .com accounts for 24.5%. The identities of those acquiring these domains and their specific uses are often obscured by WHOIS privacy, domain transfers, parking services, and auctions.
Infoblox has been tracking a threat actor dubbed "Sable Squirrel," which has reportedly spent nearly $7 million acquiring expired domains. This actor has built a criminal operation encompassing illegal sports streaming, gambling promotion, and malware infrastructure. Sable Squirrel controls over 10,000 domains, operating streaming platforms under brands like Xoilac, Cakhia, and 90phut, which target Vietnamese, Korean, Japanese, and Australian users and direct them to betting sites. A subset of these streaming domains also functions as C2 servers for malware such as Quasar RAT, AsyncRAT, DCRat, and Remcos RAT.
Notable expired domains acquired by Sable Squirrel include healthymagination.com, which was originally associated with a General Electric health initiative, and rezilion.com, a cybersecurity company whose assets were sold to GitLab in 2024. The acquisition of a defunct infosec firm's domain and its subsequent redirection to malware infrastructure highlights the attackers' understanding of how security tools evaluate domain age. Once Sable Squirrel re-registers a domain, it moves quickly, with 24% going live the same day and 94% within two weeks, aiming to capture traffic before security systems update their assessments.
Beyond Sable Squirrel, Infoblox is also monitoring three "scavenger" actors: Stuffy Squirrel, Shady Squirrel, and Swiping Squirrel. These groups operate differently, acquiring expired domains that were previously compromised by other attackers and inheriting the existing infection traffic. Shady Squirrel, believed to be Russian-speaking and active since at least July 2023, reportedly funnels this traffic to SocGholish and tech support scam networks. It is claimed that SocGholish regained access to thousands of compromised sites by collaborating with Shady Squirrel shortly after its own infrastructure was disrupted by law enforcement.
The research suggests that defenders should question, rather than implicitly trust, domain age and reputation as security indicators, given that an old domain in new hands is only as trustworthy as its current owner. This phenomenon underscores a significant challenge in cybersecurity, as threat actors increasingly exploit the legacy attributes of expired domains to enhance the credibility and effectiveness of their malicious operations.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed