Critical

Most Parked Domains Now Serving Malicious Content

Krebs on Security
Actively Exploited

Overview

A recent study has revealed that most parked domains—those that are expired, dormant, or commonly misspelled versions of popular sites—are now being used to host malicious content. These domains are redirecting users to scam sites or distributing malware, creating significant risks for individuals who may unknowingly type in these addresses. This trend highlights the dangers of direct navigation, where users enter URLs manually. As attackers exploit these parked domains, both casual internet users and organizations may find themselves vulnerable to online scams and security breaches. Awareness and caution are essential for users to avoid falling victim to these tactics.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: Parked domains, expired domains, common misspellings of popular websites
  • Action Required: Users should double-check URLs before visiting, use security software that warns against malicious sites, and avoid entering sensitive information on unfamiliar domains.
  • Timeline: Newly disclosed

Original Article Summary

Direct navigation -- the act of visiting a website by manually typing a domain name in a web browser -- has never been riskier: A new study finds the vast majority of "parked" domains -- mostly expired or dormant domain names, or common misspellings of popular websites -- are now configured to redirect visitors to sites that foist scams and malware.

Impact

Parked domains, expired domains, common misspellings of popular websites

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Users should double-check URLs before visiting, use security software that warns against malicious sites, and avoid entering sensitive information on unfamiliar domains.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Exploit, Malware.

Related Coverage

Valve notifies Steam hardware customers of a data breach

BleepingComputer

Valve has informed its Steam hardware customers in Europe about a data breach that occurred due to a cyberattack on its shipping partner, CEVA Logistics. Hackers accessed sensitive customer information during the breach, although specific details about the type of data stolen have not been disclosed. This incident raises concerns about the security measures in place at third-party logistics providers, which play a crucial role in the supply chain for tech companies. Affected customers are advised to monitor their accounts for any suspicious activity. This breach also highlights the risks associated with outsourcing logistics and the potential vulnerabilities that can arise from relying on external partners for shipping and handling customer data.

Aug 10, 2026

New Jersey, Alabama Join States Targeted in Water Cyberattacks

SecurityWeek

Hackers believed to be linked to Iran have targeted industrial control systems (ICS) at water facilities across at least a dozen states in the U.S., including New Jersey and Alabama. This cyberattack raises serious concerns about the security of critical infrastructure, as these systems are essential for managing water supplies. While specific details on how the hackers gained access have not been disclosed, the incidents indicate a growing trend of cyber threats against vital public services. The implications of such attacks could be severe, potentially disrupting water services and endangering public safety. Authorities are urging water facilities to bolster their cybersecurity measures in response to these incidents.

Aug 10, 2026

N-able ships second N-central hotfix as attackers keep exploiting CVE-2026-18577

Help Net Security

N-able has released a second hotfix for its N-central remote monitoring and management solution due to ongoing exploitation of the vulnerability identified as CVE-2026-18577. This new hotfix, referred to as Hotfix 2, is critical even for those who have already applied the first hotfix, as it includes additional security measures aimed at protecting users and their customers from active attacks. The company has also shared indicators of compromise that have been observed in these attacks, highlighting the seriousness of the situation. Managed service providers using N-central should prioritize applying this hotfix to enhance their defenses against these threats and protect their clients' systems.

Aug 10, 2026

OpenAI Pauses Astra Model Over Critical Cybersecurity Risk Concerns

Security Affairs

OpenAI has decided to pause work on its Astra model due to significant cybersecurity risks identified during internal evaluations. The company found that Astra's capabilities could potentially reach a Critical risk level according to its Preparedness Framework. This decision indicates that the model's cybersecurity functions raised enough concern that OpenAI could not confidently rule out the possibility of serious vulnerabilities. As a result, the company is reassessing Astra to ensure it does not pose a threat to users or systems. This incident highlights the importance of rigorous testing and evaluation in AI development to prevent potential security issues before deployment.

Aug 10, 2026

Metabase Patches Vulnerability Exploited as Zero-Day

SecurityWeek

Metabase has patched a significant security vulnerability that allowed unauthenticated remote attackers to gain administrative access to its instances. This flaw posed a serious risk, as it enabled attackers to potentially manipulate data and settings without needing any credentials. The issue has been classified as a zero-day exploit, meaning it was actively being exploited in the wild before the patch was released. Users of Metabase should ensure they update to the latest version to protect against this vulnerability. This incident serves as a reminder of the importance of timely software updates and vigilant security practices in safeguarding sensitive data.

Aug 10, 2026

“Ghostjacking” Exploits AI Agents’ Trusted Access to Evade Firewall Controls

Infosecurity Magazine

A recent report by Tenet reveals that around half of the Fortune 500 companies are vulnerable to a new cybersecurity technique called Ghostjacking. This method involves deceiving AI agents with fabricated reports, allowing attackers to bypass traditional firewall controls. The vulnerability is particularly concerning because many organizations rely on AI for security tasks, and if these systems are tricked, it can lead to unauthorized access and potential data breaches. The implications are significant, as it suggests that companies need to reassess their security measures to ensure that AI systems are not easily manipulated. This situation raises important questions about the reliability of AI in cybersecurity and the need for enhanced protocols to safeguard against such tactics.

Aug 10, 2026