Cisco Umbrella: "This site is blocked due to a security threat."

Hi folks,

I’m new to Ghost. I just registered a website with the address “tilt-blocks.ghost.io“, and just changed theme to “Edition”, when a few minutes later it stopped working, and when I reloaded it, I got a Cisco Umbrella message with the messages below:

“This site is blocked due to a security threat.”

“This site is blocked due to a security threat that was discovered by the Cisco Umbrella security researchers.”

This site was blocked due to the following categories: Newly Seen Domains”

I tried it with 3 different VPNs and without any, on 3 browsers (Chrome, Brave and Vivaldi) with no ad blockers, and both on my phone and laptop, and consistently received the same page, sometimes showing instead the insecure SSL cert page instead.

Now I’m even not able to log into my account to fix anything, as the admin dashboard in Ghost is also reachable via the same address.

I sent an e-mail to support, but it says they will respond in office hours. I can’t find any entry on this forum either, so, I assume it’s not a common issue.

Does anyone have a hint on how to solve that matter?

Thank you in advance!

Hey and welcome to Ghost!

This is not an issue that Ghost(Pro) could solve, unfortunately.

Something in the network you’re on (a router, switch, etc.) is using a protection layer that’s quite unreliable. “Newly seen domains” is not a spam/thread filter I would personally trust.

You have two options:

You can either disable this security tool if you know where in your network it is set up − or use a different network (e.g. your phone’s mobile connection) and contact your network administrator.

2 Likes

This is the problem **Cisco Umbrella
**
Typical corporate control of everythng

yep, got it. but I’m mostly curious why it only happens specifically with my-site.ghost.io and no other else. I don’t know other sites .ghost.io to try out, so I assume it’s gonna be the same, but I mostly use many web tools of all types, but this is the single case when I see it. That’s my curiosity.

I tried using my phone connection as well. Same result. I assume that’s because the laptop got the protection software installed on it.

but anyways, I realized another computer doesn’t have that issue, so, it’s probably specific to this device. I was afraid that could be a larger issue affecting many others

The reason is on the screen you shared:

Newly seen domains

That is, quite frankly, a pretty uhh…crude reason to activate a network firewall.

So, your network administrator is overly cautious. That’s good. But blocking “new domains”….ehh. Yes, there is probably a correlation between new domains and spam/scam sites. But then there’s also a big correlation with existing domains :upside_down_face:

So, to answer this question: because the domain has a new SSL certificate (I assume), your firewall sees that, and has an over-eager rule in place that makes little sense :smiley:

The problem is definitely with the firewall − not Ghost.