• News/
  • darkreading-20260521130500

Content Delivery Exploit Opens Websites to Brand Hijacking

Dark Reading
·
Nate Nelson
·
Published May 21, 2026
·
Updated

Researchers are sounding the alarm on a class of exploit inherent in Internet infrastructure itself for which there is no simple fix and nearly half of all websites globally are at risk. Conceptually, the issue is a successor to "domain fronting," a trivial Internet routing sleight of hand popular in the mid-2010s. Domain fronting allowed Web surfers to announce to domain name system (DNS) and content delivery network (CDN) providers that they were visiting one website, while in fact being directed to another, simply by switching one field — the HTTP Host header — in their Web requests. It caught enough attention back in 2018 that CDNs have largely mitigated it. The new issue, deemed "Underminr," works around those mitigations and has the very same effect. Although domain fronting is often associated with censorship bypass, the analysts at ADAMnetworks point out its more nefarious use: allowing attackers to conceal their malicious activity online by hijacking the brand reputations of legitimate websites. Hackers are already exploiting Underminr, they report, and your website is very likely available for their pleasure. ADAMnetworks found that 42% of websites are vulnerable, and in the US, that number climbs to 51%. Think back to school, YouTube explainers, or wherever you first learned about how the Internet works. Back then, you learned that when you request to visit a specific website — say, darkreading.com — that request travels to a Domain Name System (DNS) server, which ...

Read full article

Affected Software

4 affected components
Cloudflare content delivery network (CDN)
Fastly content delivery network (CDN)
Multiple CDN providers content delivery network (CDN)
Multiple DNS providers DNS resolver/server
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a new class of exploit in Internet infrastructure that poses risks of brand hijacking for nearly half of all websites globally.

2

What security implications are discussed?

The exploit allows for easy manipulation of website content, resulting in potential brand hijacking with no straightforward fix.

3

What products or software are affected?

The exploit affects several content delivery networks (CDNs) including those from Cloudflare, Fastly, and multiple other CDN and DNS providers.

4

What are the origins of this exploit?

This exploit is conceptually related to earlier methods like 'domain fronting,' highlighting issues in Internet routing.

5

How widespread is the risk posed by this exploit?

The risk is alarmingly high, impacting almost half of all websites worldwide.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203
Content Delivery Exploit Opens Websites to Brand Hijacking - SecAlerts