LIVE · cybersecurity feed
Live wire
cloud

Secure all your internal vibe-coded applications — in one click

Introducing Cloudflare Access for Workers. Attach an Access policy directly to a Worker and it applies everywhere that Worker runs — routes, custom domains, workers.dev, and previews — automatically.

zeroday.news ·

Cloudflare has confirmed that it was affected by a critical vulnerability, CVE-2023-50387, dubbed "KeyTrap," which could allow an attacker to exhaust CPU resources on a DNS resolver, effectively creating a denial-of-service condition. The vulnerability, which affects DNSSEC, was publicly disclosed by researchers at the University of Stuttgart and the German National Research Center for Applied Cybersecurity ATHENE.

The KeyTrap vulnerability exploits a flaw in how DNSSEC-validating resolvers process DNSKEY records. An attacker can craft a malicious DNSSEC zone that, when queried, forces the resolver to perform an excessive number of cryptographic signature verifications. This intensive computational load can consume all available CPU resources, leading to a denial of service for legitimate DNS queries. The researchers demonstrated that a single DNS query to a vulnerable resolver could trigger this resource exhaustion.

Cloudflare, a major provider of DNS services, confirmed that its 1.1.1.1 public DNS resolver was susceptible to KeyTrap. The company stated that it had implemented a fix for the vulnerability on December 15, 2023, following responsible disclosure by the researchers. Cloudflare's mitigation involved changes to its DNS resolver software to limit the number of cryptographic operations performed for a single DNS query, preventing the resource exhaustion attack.

The vulnerability's impact extends beyond Cloudflare, as it affects any DNSSEC-validating resolver that does not properly handle the malicious DNSKEY record structure. This includes a wide range of DNS software implementations. The researchers indicated that the attack could be executed with a single DNS query, making it a potent tool for disrupting internet services reliant on DNSSEC.

DNSSEC, or Domain Name System Security Extensions, is a suite of specifications designed to add a layer of security to the DNS by authenticating DNS data. While DNSSEC aims to prevent spoofing and other attacks, the KeyTrap vulnerability highlights a critical weakness in its implementation across various resolvers. The vulnerability underscores the complexity of securing fundamental internet protocols and the potential for subtle flaws to have widespread impact.

The disclosure of KeyTrap has prompted a broader call for DNS operators and software vendors to update their systems and ensure they are protected against this specific attack vector. Organizations that operate their own DNSSEC-validating resolvers are advised to consult their software vendors for patches and mitigation strategies. The fix implemented by Cloudflare and other affected parties typically involves rate-limiting or otherwise restricting the processing of overly complex DNSSEC responses.

cloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-58231critical

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek.

breach

Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology

Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa. Across Egypt, Nigeria, South Africa, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and connected operations. But more technology does not automatically create stronger security operations; many security teams are not short on data, but rather on time, conte

ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.

vulnerability

Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Threat actors gained root access to the vulnerable systems and deployed a Monero miner. The post Recent macOS Screen Sharing Vulnerability Exploited in Attacks appeared first on SecurityWeek.