Abandoned CDN Domain Re-Registered, Thousands of Sites Still Reference It
Security researchers warn of potential supply chain risks as expired CDN hostname is reclaimed

Key Takeaways
- An abandoned CDN domain was re-registered in July 2025, though the report was published in September 2026.
- Thousands of websites, code repositories, and documentation pages still contain hard-coded references to hostnames beneath the former CDN domain.
- The new owner of the domain has the potential to serve malicious content, tracking scripts, or malware to visitors of sites that still reference it.
Related Security News

WordPress Core Cross-Site Request Forgery Vulnerability Dubbed 'Click2Shell' Enables PHP Execution
A cross-site request forgery (CSRF) vulnerability in WordPress Core, tracked as 'Click2Shell', has been reported to allow attackers to execute arbitrary PHP code on the server. Technical details and a proof-of-concept exploit have been published. The full extent of affected WordPress versions, exploitation activity, and severity rating remain unconfirmed and require verification through official WordPress security channels.


