Abandoned CDN Domains Expose Sites to Remote Risk
🔒 In July 2025 an expired CDN domain was re-registered and began serving content to thousands of sites that still referenced its hostnames. The new owner controls wildcard DNS and can choose what those pages load, creating a supply-chain risk that server-side tooling often misses. Content Security Policy (CSP) in report-only mode provides a low-risk way to discover and monitor what third-party scripts actually execute. Compliance mandates such as PCI DSS v4.0.1 now require inventorying and alerting on scripts that run on payment pages, and services like Report URI can collect, archive, and alert on client-side script activity without adding site-side code.
