Squarespace Domain Hijacks Enabled by Email Address Exploit ...
Blog post from Socket
In July 2023, after Google sold its Google Domains accounts to Squarespace for an estimated $180 million, over a dozen domains were hijacked due to security vulnerabilities associated with the migration process. The transfer resulted in weak security defaults, as Squarespace did not migrate Multi-Factor Authentication (MFA) details, allowing threat actors to gain access through email addresses tied to existing domains without email verification for new accounts. This issue affected not only the domains but also compromised associated Google Workspace accounts, leading to unauthorized actions such as domain transfers, DNS changes, and email spoofing. Despite Squarespace implementing patches to address these vulnerabilities, security researchers criticized the acquisition's oversight, urging users to consider alternative registrars and reinforcing the importance of robust security measures like enabling 2FA and using unique passwords to safeguard against unauthorized access.
No tracked trend matches for this post yet.
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.