Danglegeddon: Find your vulnerable subdomains before AI agents take them over

Danglegeddon is a Silent Push research simulation that measured how quickly dangling DNS records could be found and taken over at scale. A dangling DNS record is a record that still points to a service that has been deleted, such as a forgotten CNAME to a decommissioned cloud resource. Anyone who claims that service can take control of the subdomain.

In this webinar, Silent Push Solutions Engineer Jathan Anandham and Threat Reseacher Jaimin Nayi from the Preemptive Cyber Defense team walk through the research. The team scanned 12,500 apex domains across government, banking, pharmaceutical, and automotive organizations and surfaced roughly 85,000 dangling DNS records. With AI helping to validate and map the findings, they narrowed that list to around 16,000 worth reviewing. Every finding was disclosed to the affected organizations.

What you’ll learn

  • How AI changes the speed and scale at which attackers can find and prioritize abandoned DNS records.
  • Why dangling CNAME, MX, and NS records carry different levels of risk, from hosting a phishing page on a trusted subdomain to taking over an entire DNS zone.
  • How mergers, acquisitions, layoffs, and team changes leave records behind long after the service is switched off.
  • A live demo of a real dangling subdomain, from takeover proof of concept to finding it in the Silent Push platform.
  • Practical steps defenders can take, including removing DNS records before deprovisioning services, assigning record owners, publishing CAA records, and monitoring continuously.

Access now: