Infoblox, a prominent player in DDI (DNS, DHCP, and IPAM) and DNS-layer security, has announced its intent to acquire Axur, a global provider of AI-powered external threat intelligence and mitigation. The acquisition, expected to close in spring 2026, represents a strategic expansion for Infoblox, moving its security focus beyond the network perimeter to proactively address threats on the public internet. Axur's platform specializes in automatically discovering and taking down malicious infrastructure, including phishing sites, fake social media profiles, and fraudulent mobile apps. By combining this capability with Infoblox's core DNS security, the merged entity will offer a comprehensive solution that can both block access to malicious sites and actively work to remove them from the internet, drastically shortening attack lifecycles.
The acquisition directly addresses the modern threat landscape where attacks often begin outside the organization's control. These external threats include:
Axur's technology is designed to continuously scan the public internet (including websites, social media, app stores, and dark web forums) to identify these threats. Its AI-driven platform can reportedly detect new phishing activity in under four minutes and achieves a takedown success rate of nearly 99%.
The combination of Infoblox and Axur creates a powerful security synergy:
This two-pronged approach—Block and Takedown—significantly reduces the median uptime of an attack from days to mere hours, minimizing the window for potential victims to be compromised.
The integrated solution provides multiple layers of mitigation against external threats:
The core function of the combined Infoblox/Axur solution is to identify and block access to malicious web content like phishing sites.
Axur's capability to discover and take down malicious infrastructure before it can be widely used in campaigns is a form of pre-compromise mitigation, disrupting attacker resource development.
The integration of Axur's external threat intelligence directly into the Infoblox platform supercharges the effectiveness of DNS Denylisting. This countermeasure works by using a DNS firewall to intercept DNS queries from endpoints and block any requests for domains known to be malicious. With Axur, the list of malicious domains is updated in near real-time as new phishing and brand abuse sites are discovered on the internet. This allows organizations to proactively prevent users from ever connecting to these harmful sites, effectively neutralizing the threat at the earliest possible point in the attack chain. This is a highly efficient, low-impact method of protecting an entire organization.
While DNS filtering is the primary control, Outbound Traffic Filtering at the firewall or proxy level provides a critical layer of defense-in-depth. By leveraging the same threat intelligence feed from Axur/Infoblox, organizations can create rules to block any direct-to-IP or non-DNS outbound connections to the IP addresses associated with the malicious infrastructure. This is crucial for stopping malware that may have already infected a device and is attempting to communicate with a command-and-control server using a hardcoded IP address, bypassing DNS altogether. This ensures that even if one layer of defense is evaded, another is in place to stop the threat.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
Help others stay informed about cybersecurity threats