Skip to content
Latest
OWAReaper Shows Why Exchange Mailboxes Need Post-Patch Compromise ReviewApache Ant Path Traversal Shows Why Build Pipelines Need SandboxesTeams Helpdesk Impersonation Shows Why Remote Support Needs GuardrailsPaperCut RCE Shows Why Print Servers Need Compromise ReviewEdge AI Moves the Trust Boundary Into Customer-Owned EnvironmentsToy Ghouls Shows Why Custom C2 Needs Protocol-Aware MonitoringTed Backdoor Shows Why Edge Load Balancers Need Compromise ReviewNisos DPRK Investigation Shows Why Remote Hiring Is a Security ControlFake Claude Opus 5 App Shows Why AI Tooling Needs Software ControlNodeRabbit and PollCat Show Why Developer Workstations Need Recruiting-Lure ControlsJSCeal Shows Why Compiled Script Malware Needs Bytecode-Aware DefenseWatershed 250 Shows Water Cybersecurity Needs Practical Field TestsFire Ant Shows Why Trusted Infrastructure Needs First-Class DetectionLLM Safety Fragility Shows Why AI Workflows Need Runtime Guardrails

IOC Passport

dnsrecursive[.]eu

DomainArticle-derived observationCurrent reporting windowReported in 2 articlesWatch this →

A domain extracted from published reporting. It may be infrastructure, a cited service, or a candidate indicator; check current feed admission before blocking. Shown defanged for safe viewing; use Copy live value for the functional form.

This value remains inside its 30-day domain/URL reporting window. Current reporting status is separate from verified-feed admission. Archive-cleared or archived does not mean clean, inactive, benign, remediated, resolved, or safe, and this lifecycle does not change current verified-feed admission.

Current verified-feed status

Checking live guard…

Article reporting and current malicious-feed admission are evaluated separately.

First reported
Last reported
Article count
2
Admission policy
bulwark-exact-malicious-v2
Research lifecycle
Current

Related indicators

Observables that appear alongside this one in the same reporting. Co-occurrence can suggest shared infrastructure, but it does not establish common ownership, campaign identity, or actor attribution.

6897b649f29e54d8910459963bbf94ed5c7a4fe66a56bc5962540b226b8e48c4acocdn[.]comasecdns[.]comCVE-2026-42897i3[.]wp[.]comimages[.]weserv[.]nlslack-imgs[.]comtdndns[.]comCVE-2025-62593CVE-2026-65400folder[.]idhxxp://schemas[.]xmlsoap[.]org/soap/envelope/hxxps://images[.]weserv[.]nl/?url=hxxps://acocdn[.]com/assets/v1_SGVsbG8gV29ybGQschemas[.]xmlsoap[.]orgweserv[.]nl

Newsletter

The House-Of-L Brief.

Two short reads a day on markets, cyber threats, AI, and geopolitics. A "why it matters" line on every story.

Double opt-in. One-click unsubscribe on every issue. We never share your address.