Infoblox Wants to Find Your Exposed Assets Before Hackers Do
The network security company is entering a crowded market with a twist: using its deep knowledge of the internet's address book to spot weaknesses rivals might miss.

Key points
- Infoblox announced entry into the External Attack Surface Management market on Tuesday, adding a new Supply Chain Intelligence feature alongside it.
- An early access program across roughly 40 organisations found "dangling CNAME records", a type of orphaned web address entry that criminals can hijack, at 31 of them.
- A third of those vulnerable entries were reportedly easy for an outsider to take over with little effort.
- The product needs no software installed on a customer's systems and claims to work without login credentials or active probing.
- Artificial intelligence is making attacker reconnaissance, the process of mapping out a target before striking, dramatically faster, which is the commercial pressure driving this launch.
Security company Infoblox wants to be the thing that finds your open doors before a criminal does. This week the company announced it is entering the External Attack Surface Management (EASM) market, a category of security tools that continuously scan everything a business has exposed to the internet and flag the weaknesses.
EASM has become one of the fastest-growing corners of cybersecurity because the old approach, running a manual check once a quarter, no longer keeps pace with attackers. As first reported by CSO Online, Infoblox framed the launch around one specific pressure: artificial intelligence is now letting criminals map out a target's weaknesses in hours rather than weeks.
What actually makes this different from the dozens of other tools doing the same job?
Infoblox's angle is DNS. DNS, short for Domain Name System, is the internet's address book: it translates a name like "yourbank.com" into the numerical address computers actually use to connect. Infoblox has spent years in that space, and it is applying that expertise here.
The practical upshot: the tool can spot a class of problem called a "dangling CNAME record". A CNAME is a type of DNS entry that points one web address to another. When a company retires an old service but forgets to delete the pointer, that orphaned entry sits in the open. A criminal can register the abandoned destination and suddenly has a web address that looks like it belongs to the real company. Phishing emails sent from there, or login pages hosted there, appear far more convincing.
| Stat | Figure |
|---|---|
| Organisations in early access program | ~40 |
| Found dangling CNAME records | 31 |
| Of those, entries easy to hijack | ~1 in 3 |
| Product launch date | Tuesday (this week) |
Those numbers from Infoblox's own early access program are not flattering for the industry. Dangling records are a known, fixable problem. Finding them at three quarters of tested organisations suggests routine DNS hygiene is still falling through the cracks.
Should customers of businesses using Infoblox's product care?
Indirectly, yes. The second announcement, Supply Chain Intelligence, monitors the internet-facing exposure of a company's own critical vendors and suppliers. The idea is that your data can be stolen through a supplier's weak point just as easily as through your own front door.
If you're a customer of a business that is seriously managing this, you benefit. If a vendor's leaked staff credentials or hijacked subdomain is caught early, the downstream attack that would have hit you never happens.
In practice, the failure mode this product is designed to catch is not some exotic zero-day exploit. It is forgotten infrastructure: old cloud storage buckets left public, expired certificates, abandoned subdomains. The boring stuff that falls off the sprint board.
One thing the post-mortem will say, every time one of these dangling-record hijacks succeeds: somebody knew that entry was outdated and nobody deleted it.



