importantSYS.SOURCE: The Hacker News• 2026-09-18T16:31:16+05:30
Security Risks from Abandoned CDN Domains and Third-Party Script Vulnerabilities
An abandoned CDN domain was re-registered, allowing the new owner to control resources loaded by thousands of websites that still reference it. The article highlights risks from third-party scripts and emphasizes Content Security Policy (CSP) as a critical defense mechanism for detecting unauthorized code execution.
In July 2025, someone registered a domain that used to belong to a content delivery network. The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of websites, code repositories, and documentation pages still carry hard-coded references to hostnames beneath it.
The new owner holds
*** END OF TRANSMISSION ***