{"id":701,"date":"2026-06-10T16:57:37","date_gmt":"2026-06-10T15:57:37","guid":{"rendered":"https:\/\/blogs.it.ox.ac.uk\/nexus\/?p=701"},"modified":"2026-06-10T17:01:36","modified_gmt":"2026-06-10T16:01:36","slug":"typos-and-data-loss","status":"publish","type":"post","link":"https:\/\/blogs.it.ox.ac.uk\/nexus\/2026\/06\/10\/typos-and-data-loss\/","title":{"rendered":"Typos and data-loss"},"content":{"rendered":"\n<p>Shared by <a href=\"https:\/\/www.linkedin.com\/feed\/update\/urn:li:activity:7470080810260291586\/\" data-type=\"link\" data-id=\"https:\/\/www.linkedin.com\/feed\/update\/urn:li:activity:7470080810260291586\/\">Alex Shakhov<\/a>:<br><br>&#8220;A European cybersecurity company left a typo in their DNS for over a year, so we registered it.<\/p>\n\n\n\n<p>We only did that to keep an attacker from getting there first, after they ignored our disclosures across multiple channels. The next day, their own security telemetry started flowing to us.<\/p>\n\n\n\n<p>The typo was in their DMARC RUA endpoint, so within days we had mapped their sending infrastructure, the vendors sending on their behalf, and even their internal R&amp;D systems, right down to the specific tooling they run and where it&#8217;s hosted.<\/p>\n\n\n\n<p>If an attacker had registered that domain, this would be a GDPR incident with fines and a reputational hit, built from a single typo.<\/p>\n\n\n\n<p>It doesn&#8217;t matter if you have #DMARC p=reject and enterprise-level security controls in place, when the employees touching your DNS are typing the values instead of copying\/pasting them.<\/p>\n\n\n\n<p>Audit your DNS and confirm you control every domain it points to. There&#8217;s no point in strict security controls if one dangling record is leaking your internal data.<\/p>\n\n\n\n<p><img loading=\"lazy\" decoding=\"async\" width=\"800\" height=\"292\" class=\"wp-image-704\" src=\"http:\/\/blogs.it.ox.ac.uk\/nexus\/files\/2026\/06\/image_2026-06-10_165610925.png\" alt=\"Typo in DMARC record\" srcset=\"https:\/\/blogs.it.ox.ac.uk\/nexus\/files\/2026\/06\/image_2026-06-10_165610925.png 800w, https:\/\/blogs.it.ox.ac.uk\/nexus\/files\/2026\/06\/image_2026-06-10_165610925-300x110.png 300w, https:\/\/blogs.it.ox.ac.uk\/nexus\/files\/2026\/06\/image_2026-06-10_165610925-768x280.png 768w\" sizes=\"auto, (max-width: 800px) 100vw, 800px\" \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Shared by Alex Shakhov: &#8220;A European cybersecurity company left a typo in their DNS for over a year, so we registered it. We only did that to keep an attacker from getting there first, after they ignored our disclosures across &hellip; <a href=\"https:\/\/blogs.it.ox.ac.uk\/nexus\/2026\/06\/10\/typos-and-data-loss\/\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":107,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-701","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/posts\/701","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/users\/107"}],"replies":[{"embeddable":true,"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/comments?post=701"}],"version-history":[{"count":4,"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/posts\/701\/revisions"}],"predecessor-version":[{"id":725,"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/posts\/701\/revisions\/725"}],"wp:attachment":[{"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/media?parent=701"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/categories?post=701"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blogs.it.ox.ac.uk\/nexus\/wp-json\/wp\/v2\/tags?post=701"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}