How a wildcard DNS record on GitHub Pages allowed strangers to create scam subdomains on my domain
By
rmeertens
Front-window bakery material. Catches the eye, delivers the goods.
Summary
A developer traveling in Africa discovers that a wildcard DNS record pointing to GitHub Pages allowed strangers to create scam subdomains (like kafka.immersivepoints.com) under his personal domain without his knowledge. The article details how GitHub Pages' subdomain handling combined with wildcard DNS configurations creates a security loophole where anyone can claim subdomains on someone else's domain, leading to potential abuse for phishing and scams.
Key quotes
· 3 pulledMy immersivepoints.com domain is only used for one website hosted as a GitHub page.
There definitely is no Kafka involved here, let alone that I knew the new owner of this subdomain.
How a wildcard DNS record pointing at GitHub Pages let strangers spin up scam subdomains on my own domain — and what should change.
You might also wanna read
GitHub Bans Security Researcher Over Windows Zero-Day Exploit Code in YellowKey Dispute
Security researcher Nightmare-Eclipse reportedly lost his GitHub account after posting Windows zero-day exploit code related to the YellowKe
Suspicious hidden message discovered in jqwik testing library 1.10.0
A developer reports discovering a suspicious string in the jqwik testing library (version 1.10.0) that appears during Maven test runs. The s
Attackers exploit FortiClient EMS vulnerability (CVE-2026-35616) to deliver infostealer to enterprise devices
Attackers are exploiting a known vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver a broad-spectru
Critical Gogs RCE bug (CVSS 9.4) remains unpatched; exploit module now public
A critical remote code execution (RCE) vulnerability rated 9.4/10 has been discovered in Gogs, a popular open-source self-hosted Git service
GrapheneOS: A privacy-focused, open-source mobile OS with Android app compatibility
GrapheneOS is a non-profit, open-source mobile operating system focused on privacy and security, with full Android app compatibility. Founde
Anthropic Releases Free Security Plugin for Claude Code Terminal to Detect Vulnerabilities
Anthropic has released a free security-guidance plugin for its Claude Code terminal tool that autonomously reviews code edits, model outputs
cybersecuritynews.com·11h ago