/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Amazon and Google patch a bug in their DNS-as-a-Service platforms that exposed users' internal networks and traffic; other DNS providers are likely vulnerable

Catalin Cimpanu / The Record :

The Record Catalin Cimpanu

Context & Ripple Effects

Managed DNS has become a repeated leak point inside the big clouds. Google previously shipped a Gmail and G Suite fix for SPF/DMARC spoofing months after a researcher flagged it, and Amazon has since patched two AWS flaws found by Orca Security that could have exposed Glue-managed information and sensitive CloudFormation files. The shared-infrastructure precedent is even broader: researchers documented seven flaws in the open-source Dnsmasq suite earlier in 2021, leaving over a million networking devices exposed.

This latest bug sits in that lineage but raises the stakes: it ran through both companies' DNS-as-a-Service offerings at once, exposing what customers consider private — internal network topology and traffic patterns — rather than a single product surface.

First-order effects

  • Customers using Amazon's and Google's managed DNS platforms had internal network layouts and query traffic exposed to anyone exploiting the flaw until the patch landed, and now need to assess what was observable during the window.
  • Both vendors absorb the immediate remediation burden — patching multi-tenant infrastructure silently at scale, with no customer-side action required but also no per-customer audit trail of what leaked.

Second-order effects

  • Other DNS-as-a-Service providers are likely running the same class of vulnerable configuration, so security teams will push their own DNS vendors for confirmation they are not affected, forcing audits across the managed-DNS market.
  • Enterprise buyers gain fresh ammunition in vendor risk reviews: the same pattern that hit AWS Glue and CloudFormation now extends to DNS, making 'show us your tenant-isolation design' a standard procurement question.

Third-order effects

  • If shared DNS control planes keep producing cross-customer exposure bugs — from Dnsmasq's million-device footprint to these platform flaws — enterprises will segment DNS like any other trust boundary, running internal resolvers separately from provider defaults.
  • Regulators and cyber-insurers increasingly treat multi-tenant infrastructure failures as systemic risk, which could push managed-DNS providers toward mandatory isolation attestations rather than best-effort security postures.

The trend: Cloud DNS is shifting from an assumed-private plumbing layer to an audited attack surface, with each shared-control-plane bug forcing tenants to re-examine what their providers can see.

Discussion

  • @quinnypig Corey Quinn on x
    tl;dr It was possible to see database queries and their results in other people's Route 53 database tables. https://twitter.com/...
  • @campuscodi Catalin Cimpanu on x
    Microsoft said that companies should follow the two guides here and block dynamic DNS updates from leaving the local LAN and reaching the internet or managed DNS servers where it could be intercepted and collected by third-parties https://docs.microsoft.com/... https://social.tec…
  • @campuscodi Catalin Cimpanu on x
    NEW: Amazon and Google patched a major bug in their DNS-as-a-Service platforms that would have allowed threat actors to intercept dynamic DNS updates and map the internet networks of their customers https://therecord.media/... #blackhat https://twitter.com/...