New Features in January 2026
Focus
Focus
Advanced DNS Security Powered by Precision AI®

New Features in January 2026

Table of Contents

New Features in January 2026

Review the new features and platform changes for Advanced DNS Security in January 2026.

Dangling Web And App Domain Detection for Advanced DNS Security

January 13, 2025
Websites often link to external resources, but when these third-party domains expire, threat actors can quickly re-register them to host malicious payloads, enabling broken link hijacking attacks. This security vulnerability leaves enterprise users vulnerable to cross-site scripting (XSS) and malware when they access seemingly legitimate business sites.
The Advanced DNS Security and Advanced DNS Security Resolver service now proactively identifies and blocks DNS requests directed at these expired, high-risk domains, ensuring protection before a network connection is ever established. This detection capability is available with the latest cloud update, providing comprehensive security at the DNS resolution layer and filling a critical gap left by existing solutions like static blacklists.
Unlike reactive web proxies, this system analyzes real-time domain registration data alongside DNS query patterns. By mitigating access to potentially harmful external resources at the DNS layer, you eliminate a significant security risk and protect your employees from inadvertently connecting to malicious sites.
Dangling Web and App domains are considered grayware and carry a default action and log severity level of Block and Low, respectively. Additionally, the UTID for this specific domain type is 109,004,101, and can be used to identify such domains in the logs.

File-Converter Domain Support for Advanced DNS Security Resolver

January 13, 2025
The DNS Security Resolver now provides access to a new domain category for content-based DNS signature sources: file-converter. File-converter websites used for tasks like PDF conversion or unlocking documents pose possible data exfiltration risks, especially for enterprises in regulated industries handling sensitive patient or financial data. These sites were previously grouped under Computer and Internet Info. You can now apply a discrete policy action for the file-converter domain category, allowing you to block a specific range of websites.

Malicious Software Host Domain Detection for Advanced DNS Security

January 13, 2025
Threat actors increasingly use domains that mimic legitimate software providers to distribute fake or malicious software. By employing techniques like typo-squatting or character substitution, these deceptive domains trick you into unwittingly downloading trojanized versions of productivity applications or secure shell clients. This vulnerability exposes your network to system infections, data theft, and lateral movement by threat actors who exploit the trust users place in familiar brand names.
The Advanced DNS Security and Advanced DNS Security Resolver services now include a specialized detection capability to proactively identify and block access to these malicious domains. Fake/Malicious software hosting domain detection leverages advanced techniques to analyze DNS queries and responses in real-time for indicators of impersonation. By categorizing these threats under the existing Malware category with a specific threat name (using the format <generic>:Fake_Software:<FQDN>), the service provides you with granular visibility and proactive protection at the DNS layer. This ensures a robust defense against sophisticated impersonation attacks before a network connection is ever established.