An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.
- ID
- 25975
- Status
- summarized
- Published
- 18 Sep 2026, 7:01 PM
- Fetched
- 18 Sep 2026, 11:12 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/an-abandoned-cdn-domain-was-re.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 7.5
- Created
- 18 Sep 2026, 11:15 PM
- Tags
- Audience
- developersvibe_coderssaas_founders
What happened
In July 2025, someone re-registered an expired CDN domain that thousands of websites, code repos, and documentation pages still hard-code references to. The new owner now controls wildcard DNS for the entire domain, meaning any hostname under it resolves to their infrastructure. This mirrors the June 2024 polyfill.io incident where a domain embedded in 110,000+ sites changed ownership and began serving malicious conditional redirects to mobile visitors.
Why it matters
If your site or SaaS product loads any third-party script from a CDN domain you don't control, audit those references now — especially legacy <script> tags from years-old deployments. Static analysis and dependency scanners won't catch this because the script is fetched client-side at runtime, not part of your build. A re-registered domain gives a stranger the ability to serve arbitrary JavaScript with full DOM, cookie, and localStorage access on your pages, and nothing will visibly break to alert you.
Discussion angle
Walk through a quick check: grep your codebases and HTML templates for any CDN hostnames in script/link tags, then verify each domain's registration status and ownership history. Discuss whether Subresource Integrity (SRI) hashes would have mitigated the polyfill.io case and whether they're practical to enforce across a team.