AI Weekly Malaysia

Back to items Summaries

An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

ID
25975
Status
summarized
Published
18 Sep 2026, 7:01 PM
Fetched
18 Sep 2026, 11:12 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/an-abandoned-cdn-domain-was-re.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
7.5
Created
18 Sep 2026, 11:15 PM
Tags
Audience
developersvibe_coderssaas_founders

What happened

In July 2025, someone re-registered an expired CDN domain that thousands of websites, code repos, and documentation pages still hard-code references to. The new owner now controls wildcard DNS for the entire domain, meaning any hostname under it resolves to their infrastructure. This mirrors the June 2024 polyfill.io incident where a domain embedded in 110,000+ sites changed ownership and began serving malicious conditional redirects to mobile visitors.

Why it matters

If your site or SaaS product loads any third-party script from a CDN domain you don't control, audit those references now — especially legacy <script> tags from years-old deployments. Static analysis and dependency scanners won't catch this because the script is fetched client-side at runtime, not part of your build. A re-registered domain gives a stranger the ability to serve arbitrary JavaScript with full DOM, cookie, and localStorage access on your pages, and nothing will visibly break to alert you.

Discussion angle

Walk through a quick check: grep your codebases and HTML templates for any CDN hostnames in script/link tags, then verify each domain's registration status and ownership history. Discuss whether Subresource Integrity (SRI) hashes would have mitigated the polyfill.io case and whether they're practical to enforce across a team.

Top