Skip to content
Back

Security at the Speed of the Newsroom: How ynet Caught a Live Subdomain Takeover

Inbal Lev

Customer Success Engineer

September 7, 2026
Share

A fabricated article appears on a real news domain. The address looks right. The branding looks familiar. Readers share it before anyone has time to question it.

For a major publisher, that scenario causes reputational damage long before the security team confirms what happened. And an attacker may not need to breach the newsroom's systems to pull it off - a single forgotten DNS record can be enough.

That was the risk facing ynet, the digital home of Yedioth Ahronoth and one of Israel's most-read news brands. Its 24/7 operation spans Hebrew, English, Russian, and Spanish editions, along with video, lifestyle verticals, local properties, and e-commerce. Behind those familiar pages is a sprawling external footprint built over 25 years: hundreds of domains and subdomains, election and sports microsites, campaign pages, commerce platforms, and staging environments.

Some are launched in hours. Others outlive the projects that created them.

What is a subdomain takeover?

A subdomain takeover happens when a DNS record points to an external resource - a hosting provider, CDN, or SaaS platform - that has since been released or deleted. The subdomain still resolves. It still carries the organization's domain name. But the content it serves can now be controlled by whoever claims that released resource.

For news organizations, the attack surface is particularly acute. Subdomains are created constantly for election coverage, sports tournaments, advertising campaigns, and seasonal verticals. When a project ends, the content disappears. The dangling DNS record often doesn't.

A forgotten record with a very real owner

Shortly after ynet deployed ULTRA RED across its external attack surface, the platform identified a subdomain created years earlier for a campaign that had since ended. The page was gone, but its DNS record remained - a dangling DNS entry still pointing to a third-party resource that had been released.

This was more than untidy infrastructure. ULTRA RED validated that the resource could be claimed, giving a stranger control over the content served from a genuine ynet.co.il address.

The possible outcomes went far beyond a defaced page: a fake article during an election, a phishing campaign hosted on an address readers already trusted, or malware distributed under the country's most-read news brand. Because the attack required no intrusion into ynet's own systems, conventional perimeter alarms might never have fired.

Crucially, ULTRA RED did not stop at flagging a suspicious configuration. It supplied proof-of-concept evidence confirming the subdomain takeover was viable. ynet removed the dangling DNS record that same day.

"No one broke into anything. Someone had simply left a DNS record in place, and that was enough to publish content under our name. A typical scan wouldn't have caught it," said Ilan Norman, CISO at Ynet Group.

Why another vulnerability report wasn't the answer

ynet did not lack vulnerability data. The problem was deciding which findings justified touching live systems where availability is non-negotiable - especially during peak news events.

Traditional scanners produced thousands of theoretical CVEs based largely on version data. The security team then had to reproduce findings, assess exploitability, persuade system owners to act, and work through a backlog filled with uncertainty. Meanwhile, the attack surface kept changing.

"We had plenty of vulnerability reports. The challenge was knowing which findings were real," Norman said. "If you're asking system owners to make changes in production, you need to prove why."

ULTRA RED gave the team an attacker's-eye view of the entire brand family, continuously assessing assets as they appeared. Rather than forwarding everything that might be vulnerable, the platform executed real attack logic and surfaced confirmed exposures with the exact request, response, and exploit path.

That changed the remediation conversation. Severity scores gave way to demonstrated facts. The reproduce-and-argue stage disappeared, and critical findings began moving from detection to remediation in under 24 hours, compared with a previous cycle measured in weeks.

From finding vulnerabilities to shrinking the perimeter

Continuous discovery also exposed a broader opportunity. Once ynet could see campaign sites, staging environments, forgotten subdomains, and dangling DNS records in one place, exposure management became an asset-lifecycle discipline.

Legacy properties could be retired. Obsolete records could be removed. New election hubs, tournament sites, and event microsites could be validated as they went live - not months later during the next scheduled test.

For a newsroom, speed is part of the job. Security cannot ask publishing to stand still while it takes a snapshot. It has to keep pace, distinguish exploitable risk from background noise, and provide evidence strong enough to drive action without delay.

That is what validation-first exposure management gave ynet: fewer arguments over what could happen, faster action on what demonstrably could, and a smaller attack surface left behind.

Read the full case study to see how ynet protects a fast-changing digital estate with continuous exposure validation - or explore how ULTRA RED platform proves what’s actually exploitable.

Inbal Lev

Customer Success Engineer