Silent Push disclosed research dubbed DangleGeddon showing that AI can sharply accelerate dangling DNS takeover attacks, in which a DNS record continues pointing to a deleted cloud resource and an attacker recreates that resource to seize the subdomain. Using Claude Opus 5 and automated workflows, the researchers said they processed roughly 12,500 domains, narrowed them to several hundred viable targets, and reached a stage where exploitation could be launched with minimal additional effort.
The testing was conducted as a safe proof of concept and affected organizations were notified rather than exploited, but the exposed records reportedly included a U.S. federal government domain as well as assets tied to Société Générale, Ford, and Eli Lilly. Silent Push warned that compromised subdomains could be used for phishing, malware delivery, credential harvesting, and other targeted abuse, and said AI-enabled automation could let nation-state or criminal operators weaponize forgotten DNS records at global scale across government, banking, manufacturing, and pharmaceutical sectors.

Track how attackers are adapting to this technology.
2 events from the most recent confirmed update back to the earliest known activity.
Silent Push researchers documented a campaign they call “DangleGeddon,” showing that AI-assisted workflows could automate discovery, filtering, script generation, and infrastructure setup for dangling DNS takeovers at large scale. In their testing, they targeted 12,500 domains, narrowed them to several hundred exploitable candidates, and demonstrated that exploitation could be prepared with minimal effort.
During the DangleGeddon research, Silent Push conducted safe validation tests on exposed dangling DNS records and notified affected organizations instead of abusing the vulnerable subdomains. Examples cited include a U.S. federal government domain, Société Générale, Ford, and Eli Lilly.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcesecurityweek.com
Open sourcesilentpush.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.