<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cloud Security on Nalar</title>
    <link>https://nalar.dev/tags/cloud-security/</link>
    <description>Recent content in Cloud Security on Nalar</description>
    <generator>Hugo</generator>
    <language>en-us</language>
    <lastBuildDate>Mon, 14 Sep 2026 00:00:00 +0700</lastBuildDate>
    <atom:link href="https://nalar.dev/tags/cloud-security/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Dangling DNS Records Can Outlive the Services They Point To</title>
      <link>https://nalar.dev/dangling-dns-records-can-outlive-the-services-they-point-to/</link>
      <pubDate>Mon, 14 Sep 2026 00:00:00 +0700</pubDate>
      <guid>https://nalar.dev/dangling-dns-records-can-outlive-the-services-they-point-to/</guid>
      <description>&lt;p&gt;A hostname can remain part of an organisation&amp;rsquo;s public identity long after the application behind it has disappeared. The DNS record still resolves, certificates may have existed for years, links remain in old messages, and browser cookies may still be scoped broadly enough to include the name. Yet the external service named by that record may have been deleted and returned to a provider&amp;rsquo;s pool of available resources.&lt;/p&gt;&#xA;&lt;p&gt;That mismatch creates the conditions for subdomain takeover. The core problem is not DNS compromise. The authoritative zone can be operating exactly as configured. The failure sits between two control planes: DNS still delegates traffic toward an external platform, while the platform no longer associates the referenced resource with the domain owner.&lt;/p&gt;</description>
    </item>
    <item>
      <title>Dangling DNS Records Preserve Authority After Services Disappear</title>
      <link>https://nalar.dev/dangling-dns-records-preserve-authority-after-services-disappear/</link>
      <pubDate>Sun, 13 Sep 2026 00:00:00 +0700</pubDate>
      <guid>https://nalar.dev/dangling-dns-records-preserve-authority-after-services-disappear/</guid>
      <description>&lt;p&gt;A product team deletes an old hosted application, the cloud resource disappears, and the monthly bill stops. The public hostname often survives. Months later, &lt;code&gt;preview.example.com&lt;/code&gt; still resolves through a CNAME to a provider-specific name associated with a resource that no longer exists. From the organisation&amp;rsquo;s perspective the application is gone. From DNS&amp;rsquo;s perspective, authority is still being delegated.&lt;/p&gt;&#xA;&lt;p&gt;That mismatch creates the conditions associated with subdomain takeover. The important detail is not simply that a DNS record points at a dead destination. Exploitation also depends on the external service allowing another party to claim the referenced name, tenant, site, bucket, project, or equivalent routing identifier. A dangling record is therefore evidence of stale control; whether it is directly exploitable depends on the provider&amp;rsquo;s ownership model.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
