Cyber attacks in 2026 have demonstrated just how quickly vulnerabilities in edge infrastructure, enterprise applications and trusted digital services can become major security incidents. From zero-day exploitation of network management platforms to destructive attacks and data breaches targeting the education sector, threat actors are continuing to exploit weaknesses across the technology stack.
A recent analysis published by CircleID and based on research from WhoisXML API examined five of the biggest cyber attacks of 2026 through a DNS and infrastructure intelligence lens. The incidents included attacks involving Cisco Catalyst SD-WAN Manager, Ivanti Endpoint Manager Mobile (EPMM), Stryker, Instructure's Canvas platform and Oracle PeopleSoft.
Rather than looking only at what happened to the individual victims, the investigation examined the digital infrastructure surrounding these campaigns. Researchers analyzed domains, subdomains and IP addresses associated with the attacks and used DNS, WHOIS and related data to uncover additional infrastructure and potential connections.
The results illustrate why DNS security and threat intelligence remain important components of modern cybersecurity.
What Were the Biggest Cyber Attacks of 2026 So Far?
The five attacks examined in the DNS deep dive were:
Cisco Catalyst SD-WAN attacks involving exploitation of CVE-2026-20245
The Stryker wiper attack, attributed to the Handala threat group
Ivanti EPMM attacks involving critical vulnerabilities
The ShinyHunters Canvas breach
ShinyHunters attacks targeting education organizations using an Oracle PeopleSoft vulnerability
The underlying research came from security organizations including Google Threat Intelligence, Palo Alto Networks Unit 42 and Protos Labs.
The DNS investigation began with indicators of compromise (IoCs) collected from those reports. Researchers identified 54 relevant IoCs after filtering the original data. These consisted of five subdomains, 14 domains and 35 IP addresses. (
That relatively small starting set ultimately produced a much larger picture of potentially related infrastructure.
Why DNS Matters in Cybersecurity
The Domain Name System, or DNS, is fundamental to how the internet works. It translates human-readable domain names into IP addresses so that devices can locate websites and online services.
For security teams, however, DNS represents much more than an internet navigation mechanism.
DNS records can provide clues about how threat actors establish, move and maintain infrastructure. Domains can be registered specifically for malicious campaigns, while existing domains may be repurposed or compromised. IP addresses can also reveal relationships between apparently unrelated domains.
Historical DNS data can be particularly valuable because infrastructure changes over time.
A domain that appears harmless today may previously have resolved to a suspicious IP address. Similarly, an IP address associated with one attack may have hosted multiple domains over its lifetime.
This makes DNS intelligence useful for threat hunting, incident response and identifying infrastructure that conventional security controls may not yet have classified as malicious.
1. Cisco Catalyst SD-WAN Cyber Attack
One of the five incidents involved exploitation of a vulnerability in Cisco Catalyst SD-WAN Manager.
The vulnerability, identified as CVE-2026-20245, was the subject of a Google Threat Intelligence analysis published June 25, 2026. The CircleID investigation identified eight IP indicators associated with the Cisco SD-WAN attacks.
Software-defined wide-area networking has become increasingly important as organizations connect distributed offices, cloud environments, remote users and data centers.
That also makes SD-WAN management infrastructure an attractive target.
An attacker who successfully exploits an edge or management platform can potentially gain a foothold at a strategically important point in an organization's network architecture.
Why the Cisco SD-WAN Attack Matters
The incident highlights the security risks associated with internet-facing network infrastructure.
Organizations frequently prioritize traditional endpoints such as laptops and servers when developing vulnerability management programs. Network management appliances, however, can be equally important because they may provide privileged visibility or control over large portions of an environment.
Security teams should therefore treat edge infrastructure as a high-priority attack surface.
Organizations using SD-WAN should maintain accurate asset inventories, monitor vendor security advisories and prioritize patches for internet-facing management systems.
2. Stryker Wiper Attack
The second incident examined was the Stryker wiper attack, associated with the Handala threat group.
Unlike attacks primarily designed to steal information, wiper attacks are intended to destroy or disrupt systems and data.
The Protos Labs investigation cited by CircleID was published March 20, 2026. The DNS analysis identified three domain IoCs and four IP IoCs associated with the Stryker incident.
One of the domains identified in the research was handala-hack[.]to. DNS history showed 60 domain-to-IP resolutions associated with that domain between October 2024 and July 2026.
Wiper Malware Creates a Different Security Challenge
Ransomware attacks typically provide attackers with a financial incentive: victims are pressured to pay for decryption or to prevent stolen information from being published.
Wipers have a fundamentally different objective.
Their purpose can be disruption, destruction or sabotage. As a result, organizations cannot rely exclusively on backups or ransom-related response plans. They also need robust disaster recovery, network segmentation and the ability to rebuild critical systems.
The Stryker attack demonstrates why organizations should prepare for attacks in which restoring operations is more important than negotiating with an attacker.
3. Ivanti EPMM Cyber Attacks
The Ivanti EPMM attacks represented the largest portion of the subdomain analysis.
Ivanti Endpoint Manager Mobile is used to manage mobile devices and related enterprise resources. Vulnerabilities in management platforms can be particularly significant because these systems often occupy privileged positions within corporate environments.
Palo Alto Networks Unit 42 published an analysis of critical Ivanti EPMM vulnerabilities on February 17, 2026. The DNS investigation found five subdomain IoCs, 14 domain IoCs and 17 IP IoCs associated with the attacks.
DNS Infrastructure Revealed Additional Clues
The investigation found several suspicious subdomains associated with the Ivanti campaign.
One example, ddns[.]1433[.]eu[.]org, had no WHOIS data and was associated with four other subdomains. While the apex domain did not have threat intelligence hits, sibling hosts under the same domain were flagged by public sandboxes as malicious. Another suspicious infrastructure pattern involved domains under the oast namespace.
Researchers found that oast[.]fun, oast[.]site and oast[.]me continued to record network activity. They were associated with the Ivanti EPMM attacks, with some communications appearing months after the attacks were initially reported.
This illustrates an important threat intelligence lesson: an attack may be publicly disclosed long before every piece of associated infrastructure disappears.
Attack Infrastructure Can Have a Long Life
The analysis found that the 14 domain IoCs included both relatively new and much older domains. Creation dates ranged from 2016 to 2026.
This is significant because defenders cannot necessarily identify malicious infrastructure simply by looking for newly registered domains.
Threat actors may maintain infrastructure for years, reuse old domains or acquire domains with existing histories.
Historical DNS and WHOIS analysis can therefore provide context that a simple domain reputation check may miss.
4. ShinyHunters Canvas Breach
The fourth incident was the ShinyHunters Canvas breach, involving the education sector.
Canvas is an online learning management platform widely used by educational organizations. The Protos Labs intelligence report referenced by CircleID was published May 13, 2026. The DNS analysis identified two domain IoCs and one IP IoC associated with the Canvas breach.
The involvement of ShinyHunters is particularly significant because the group has been associated with data theft and extortion campaigns.
Education organizations are attractive targets because they can hold large quantities of sensitive information, including student records, employee information and institutional data.
Education Remains an Attractive Target
Educational institutions also frequently operate complex technology environments with large numbers of users and devices.
Universities and school systems may have:
Large user populations
Distributed networks
Legacy applications
Third-party SaaS platforms
Valuable personal information
Numerous external integrations
This combination creates opportunities for attackers.
The Canvas incident demonstrates why cybersecurity programs in education must account not only for endpoint security but also for cloud applications, identity systems, DNS activity and third-party infrastructure.
5. ShinyHunters and Oracle PeopleSoft
The fifth attack involved ShinyHunters activity targeting the education sector through an Oracle PeopleSoft vulnerability.
Google Threat Intelligence published its analysis of the activity on June 12, 2026. CircleID's DNS investigation used one sample from the broader campaign and identified one domain IoC and five IP IoCs. (CircleID)
Oracle PeopleSoft is used by organizations for important enterprise functions, including human resources and financial management.
That makes vulnerabilities affecting enterprise applications particularly concerning.
A successful compromise can potentially expose systems containing highly sensitive business and personal information.
Enterprise Applications Are High-Value Targets
Organizations often focus their security resources on externally facing websites and infrastructure. Enterprise applications can be just as important.
Applications responsible for human resources, finance, customer management and other business functions frequently contain sensitive information and may integrate with numerous internal systems.
Vulnerability management programs should therefore prioritize these applications according to business impact, not simply their visibility to the public internet.
What the DNS Investigation Discovered
The most interesting aspect of the CircleID analysis is what happened after researchers examined the initial IoCs.
The 54 indicators produced a much larger collection of potentially relevant infrastructure.
Researchers identified:
Four unique client IP addresses communicating with three domain IoCs
Three domain IoCs associated with a typosquatting group
161 potentially victim-owned IP addresses communicating with 20 IP IoCs
Six email-connected domains
13 additional IP addresses, nine of which were confirmed malicious
132 IP-connected domains
753 string-connected domains, two of which were confirmed malicious (CircleID)
These findings demonstrate the value of looking beyond the original indicators contained in an incident report.
An IoC should not necessarily be treated as an isolated artifact. It can be a starting point for discovering related infrastructure.
How Threat Actors Use Domains and IP Addresses
Cybercriminal infrastructure can contain numerous interconnected components.
An attacker may register several domains for different purposes, use multiple IP addresses, establish subdomains and create lookalike domains for phishing or impersonation.
These relationships can provide valuable clues.
For example, researchers found that three domains associated with the Ivanti attacks—oast[.]site, oast[.]live and oast[.]fun—were connected through bulk registration with another domain, oast[.]online, dating back to January 2022.
That kind of relationship would be difficult to identify by looking at a single domain in isolation.
The Importance of DNS History
Historical DNS data can help security teams answer questions such as:
What IP addresses has this domain previously resolved to?
What domains have previously shared this IP address?
When did a domain begin pointing to suspicious infrastructure?
Has an apparently legitimate domain previously been associated with malicious activity?
Are multiple domains connected through common infrastructure?
The CircleID investigation found 2,201 historical domain-to-IP resolutions across 13 of the domain IoCs.
That historical perspective can help investigators reconstruct how infrastructure changed during an attack.
What Organizations Can Learn From the Biggest Cyber Attacks of 2026
The five incidents reveal several common cybersecurity lessons.
Patch Internet-Facing Systems Quickly
The Cisco and Ivanti incidents demonstrate the importance of rapidly addressing vulnerabilities in network and management infrastructure.
Critical vulnerabilities affecting systems accessible from the internet should receive immediate attention.
Monitor DNS Activity
DNS monitoring can reveal communications with suspicious domains and help identify compromised systems.
Organizations should establish baselines for normal DNS behavior and investigate unusual connections.
Look Beyond Known IoCs
Known indicators are only the beginning.
Security teams should investigate relationships between domains, IP addresses, certificates, WHOIS records, DNS history and other infrastructure characteristics.
Protect Enterprise Applications
The PeopleSoft incident illustrates the importance of securing business-critical applications.
Organizations should maintain inventories of enterprise applications and understand what sensitive information each system stores or can access.
Prepare for Destructive Attacks
The Stryker wiper attack shows that organizations must prepare for attacks that seek disruption rather than financial gain.
Offline or otherwise protected backups, tested disaster recovery plans and network segmentation can reduce the impact of destructive attacks.
Monitor Third-Party and Cloud Services
The Canvas incident highlights the risks associated with widely used online platforms.
Security teams should understand what data third-party platforms hold, what integrations they have and how access is authenticated.
Why Threat Intelligence Is Becoming More Important
Modern cyber attacks rarely occur within a single isolated system.
Attackers can move across domains, cloud platforms, IP addresses, third-party services and enterprise applications.
Threat intelligence helps defenders connect these individual pieces.
The DNS investigation demonstrates how a relatively small group of known indicators can lead to hundreds of additional artifacts. Researchers used WHOIS history, reverse WHOIS, DNS lookups, DNS history and IP intelligence to expand their understanding of the infrastructure.
This approach can help organizations move from reactive detection to proactive threat hunting.
Conclusion
The biggest cyber attacks of 2026 so far show that organizations face threats across virtually every layer of the technology environment.
Cisco SD-WAN and Ivanti EPMM demonstrate the risks associated with vulnerable edge and management infrastructure. The Stryker wiper attack highlights the destructive potential of modern cyber operations. The Canvas breach illustrates the risks facing education technology, while the Oracle PeopleSoft campaign demonstrates why enterprise applications remain attractive targets.
But one of the most important lessons comes from looking beyond the individual incidents.
DNS records, IP addresses, domain registrations and historical infrastructure can reveal relationships that are not immediately obvious from an incident report. In the CircleID analysis, 54 initial IoCs ultimately led researchers to identify hundreds of connected domains and IP addresses.
For security teams, that means threat intelligence should not stop at the first known malicious domain or IP address.
The organizations best positioned to defend against emerging cyber attacks will be those that combine vulnerability management, DNS monitoring, threat hunting, network visibility and proactive intelligence to understand not just what an attacker has done, but what infrastructure may be connected to the attack.
Frequently Asked Questions
What are the biggest cyber attacks of 2026 so far?
Among the major incidents examined in the CircleID DNS analysis are the Cisco Catalyst SD-WAN attacks, Stryker wiper attack, Ivanti EPMM attacks, ShinyHunters' Canvas breach and ShinyHunters activity involving an Oracle PeopleSoft vulnerability. (CircleID)
What is a DNS attack?
A DNS attack is a cyberattack that exploits or abuses the Domain Name System. Examples include DNS hijacking, DNS spoofing, DNS tunneling and attacks that use malicious domains as part of a broader campaign. DNS data can also be used by defenders to investigate cyber attacks and identify suspicious infrastructure.
How does DNS help cybersecurity teams?
DNS provides visibility into connections between domains and IP addresses. Historical DNS information can help security teams identify infrastructure associated with malware, phishing campaigns and other attacks.
What is an IoC in cybersecurity?
An indicator of compromise, or IoC, is a piece of information that may indicate malicious activity. Examples include suspicious IP addresses, domains, URLs, file hashes and email addresses.
Why is threat intelligence important in 2026?
Cyber attacks increasingly involve interconnected infrastructure rather than a single malicious file or server. Threat intelligence helps security teams identify relationships between IoCs and discover additional infrastructure that may be associated with an attack.
What can organizations do to prevent cyber attacks?
Organizations should prioritize vulnerability management, patch internet-facing systems, implement strong identity controls, monitor DNS and network traffic, segment critical systems, secure third-party applications, maintain tested backups and conduct proactive threat hunting.
Can DNS monitoring detect a cyberattack?
DNS monitoring can identify suspicious communications and unusual domain activity, but it is not sufficient by itself to detect every attack. It works best as one component of a broader security monitoring and threat intelligence strategy.
What is a wiper attack?
A wiper attack is a cyberattack designed to destroy or disrupt data, systems or infrastructure. Unlike ransomware, which typically aims to extort victims for financial gain, a wiper may have destruction or disruption as its primary objective.