1 article with this tag
Delete a cloud resource without deleting the DNS record and you have a dangling entry: anyone can claim that subdomain by provisioning a resource with the same FQDN. Your servers stay untouched while a legitimate subdomain serves an attacker's content. The damage is not cosmetic — apps commonly expose session cookies to wildcard subdomains, so the hijacked one can read them. And the documentation explicitly rejects the belief that a certificate protects you. The fix is making deletion order a mechanism, not a memory.