Security experts have hijacked over 2,000 subdomains from legitimate websites while researching possible security flaws in Amazon’s CloudFront CDN service. Experts found that CloudFront’s CDN routing mechanism that linked a site’s domain to a specific server contained a flaw that allowed attackers to point misconfigured subdomain to their own endpoint instead. Some of the most high-profile subDOMains belonged to companies such as the Red Cross, Bloomberg, Reuters, Dow Jones, Harvard, Harvard and University of Maryland.
Source: https://www.bleepingcomputer.com/news/security/researchers-hijack-over-2-000-subdomains-from-legitimate-sites-in-cloudfront-experiment/

