BIND warns of bugs that could bring DNS cache attack back from the dead

BIND warns of bugs that could bring DNS cache attack back from the dead

Developers behind BIND, the leading software for domain name resolution, have issued a serious alert regarding two critical vulnerabilities that could enable attackers to corrupt DNS caches. This could lead users to malicious sites that mimic legitimate ones. The vulnerabilities, identified as CVE-2025-40778 and CVE-2025-40780, arise from a logic flaw and a deficiency in pseudo-random number generation, with both issues rated at a severity of 8.6. In a related discovery, the creators of the Unbound DNS resolver software have also reported similar vulnerabilities affecting their system, which has a lower severity score of 5.6. These flaws could allow malicious actors to manipulate DNS resolvers within countless organizations, substituting valid domain lookup results with harmful ones. For instance, a user attempting to access a legitimate website could be redirected to a site controlled by an attacker. Patches addressing all three vulnerabilities were released on Wednesday. This situation echoes the notable DNS cache poisoning issue revealed by researcher Dan Kaminsky in 2008, which exposed users to potential threats from counterfeit websites of major organizations like Google and Bank of America. At that time, a coordinated global effort among DNS providers and browser developers led to the implementation of crucial fixes that mitigated the risk of widespread attacks. The root of the problem lies in the use of UDP packets by DNS, which are sent unidirectionally, making it impossible for DNS resolvers to authenticate their communications. This design flaw renders UDP traffic easily spoofable, allowing attackers to send packets that appear to originate from legitimate sources, increasing the risk of DNS cache poisoning.

Sources : Ars Technica

Published On : Oct 22, 2025, 22:40

AI
Ford Unveils Innovative AI Assistant to Enhance Fleet Safety and Efficiency

This week, Ford introduced a groundbreaking AI assistant designed to help fleet owners track vital metrics like seatbelt...

TechCrunch | Mar 11, 2026, 23:00
Ford Unveils Innovative AI Assistant to Enhance Fleet Safety and Efficiency
AI
Netflix's Bold Move: $600 Million Investment in Ben Affleck's AI Venture

In a significant development last week, Netflix revealed its acquisition of InterPositive, an innovative AI company co-f...

TechCrunch | Mar 11, 2026, 22:30
Netflix's Bold Move: $600 Million Investment in Ben Affleck's AI Venture
Gadgets
Google Transitions to Minority Stake in New Fiber Internet Venture

In a strategic move, Google has announced that its fiber internet division, GFiber, is merging with Astound Broadband to...

CNBC | Mar 11, 2026, 23:35
Google Transitions to Minority Stake in New Fiber Internet Venture
Gaming
Google Strengthens Play Games for PC with New Titles and Cross-Platform Features

Google has been exploring the integration of its Play Games platform into Windows for several years, but only recently h...

Ars Technica | Mar 11, 2026, 23:10
Google Strengthens Play Games for PC with New Titles and Cross-Platform Features
Startups
Atlassian's Bold Move: CEO Reveals Layoffs Amid AI Transition

In a recent four-minute video message, Atlassian's CEO, Mike Cannon-Brookes, reached out to employees to discuss the com...

Business Insider | Mar 12, 2026, 02:45
Atlassian's Bold Move: CEO Reveals Layoffs Amid AI Transition
View All News