View Ridge Security
Back to Cyber HoseVulnerabilities & CVEs

Underminr DNS flaw lets attackers hide C2 behind trusted domains

🕵️ THREAT RESEARCH & DEEP DIVES

  • Laravel-Lang PHP Packages Compromised to Deliver Cross-Platform Credential Stealer — The Hacker News A new software supply chain attack has compromised multiple Laravel-Lang PHP packages (laravel-lang/lang, http-statuses, attributes, actions) to distribute a sophisticated credential-stealing framework. The campaign uses newly published malicious tags to push trojanized versions, targeting developers and CI pipelines relying on these popular localization packages. Immediate audit of Laravel-Lang dependencies and package integrity verification is critical to prevent credential exfiltration.

🔓 VULNERABILITIES & CVEs

  • ‘Underminr’ Vulnerability Lets Attackers Hide Malicious Connections Behind Trusted Domains — SecurityWeek A stealthy DNS vulnerability dubbed “Underminr” affects approximately 88 million domains, enabling attackers to bypass DNS filtering and cloak command-and-control (C2) traffic behind trusted domain names. This flaw undermines conventional network defenses by hiding malicious connections in legitimate DNS responses, complicating detection and blocking efforts. Network defenders should review DNS filtering policies and monitor for anomalous DNS behaviors indicative of C2 evasion. No CVE assigned yet; tracking ongoing.

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check