Dangling DNS entries occur when DNS records reference resources an organization no longer owns or operates, leaving exploitable gaps that attackers actively hunt. When adversaries exploit these misconfigurations on third-party services like AWS S3, GitHub Pages, or Heroku, they can deploy malicious content under legitimate domain names to facilitate phishing schemes and malware distribution. Censys explores how continuous internet scanning can detect these subdomain takeover risks before attackers do.