New, by me: Local Networks Go Global When Domain Names Collide
The proliferation of new top-level domains (TLDs) has exacerbated a well-known security weakness: Many organizations set up their internal Microsoft authentication systems years ago using domain names in TLDs that didn’t exist at the time. Meaning, they are continuously sending their Windows usernames and passwords to domain names they do not control and which are freely available for anyone to register. Here’s a look at one security researcher’s efforts to map and shrink the size of this insidious problem.
From the story:
"It looks like all of the police cars there have a laptop in the cars, and they're all attached to this memrtcc.ad domain that I now own," Caturegli said, noting wryly that "memrtcc" stands for "Memphis Real-Time Crime Center."
Caturegli said setting up an email server record for memrtcc.ad caused him to begin receiving automated messages from the police department's IT help desk, including trouble tickets regarding the city's Okta authentication system.
https://krebsonsecurity.com/2024/08/local-networks-go-global-when-domain-names-collide/