mindly.social is one of the many independent Mastodon servers you can use to participate in the fediverse.
Mindly.Social is an English speaking, friendly Mastodon instance created for people who want to use their brains and their hearts to make social networking more social. 🧠💖

Administered by:

Server stats:

1.2K
active users

#fastflux

6 posts6 participants0 posts today

#NSA warns “fast flux” threatens national #security. What is fast flux anyway?

A technique that hostile nation-states & financially motivated #ransomware groups are using to hide their operations poses a threat to critical #infrastructure & national security, the NSA has warned.

The technique is known as #FastFlux. It allows decentralized networks operated by threat actors to hide their infrastructure and survive takedown attempts that would otherwise succeed
#privacy

arstechnica.com/security/2025/

Ars Technica · NSA warns “fast flux” threatens national security. What is fast flux anyway?By Dan Goodin

In case you're not up-to-speed on what #FastFlux #DNS is, it's part of the arms race between attackers and defenders:

THREAT ACTOR: This is my C2 IP
BLUE TEAMER: Blocked at the firewall

TA: Ok, well then, here's my C2 domain. I've rented 50k botnet nodes to use as proxies to my real C2 infrastructure, and I'm going to keep changing the IP the domain points to basically forever. Good luck blocking that. [FAST FLUX]
BT: Blocked the domain's nameserver's IPs at the firewall

🧵

Friendly reminder that you should be blocking all newly registered domains for your end users. Free lists like the NRD (github.com/xRuffKez/NRD) exist. Microsoft Defender for Endpoint also has a built in list you can enable via policy.

IMO everyone should do 365 days but even 30 or 90 will save you so much headache.
#DNS #ThreatIntel #FastFlux

A daily updated list of newly registered domains from the past 14 and 30 days for blocking, monitoring and analysis. - xRuffKez/NRD
GitHubGitHub - xRuffKez/NRD: A daily updated list of newly registered domains from the past 14 and 30 days for blocking, monitoring and analysis.A daily updated list of newly registered domains from the past 14 and 30 days for blocking, monitoring and analysis. - xRuffKez/NRD