Dutch NCSC predicts abuse of DNS server software BIND 9
techzine.eu·1d
Flag this post

It’s always DNS.” That was a popular online response to last week’s global AWS outage. The Dutch cybersecurity agency NCSC expects more trouble when it comes to DNS issues, but this time due to DNS server software BIND 9.

Two serious vulnerabilities in BIND 9 enable so-called cache poisoning. This causes the DNS server to provide incorrect responses to users’ DNS requests. Because the wrong IP address can be communicated to the endpoint, attackers are able to redirect victims to a malicious website.

The vulnerabilities, CVE-2025-40778 and CVE-2025-40780, score an 8.6. The NCSC is calling on organizations to install the available updates. The threat of abuse is real, now that proof-of-concept code is available. The updates were released last week, so organizations have th…

Similar Posts

Loading similar posts...