Security experts are scrambling to patch a newly-discovered security flaw in a key component of the Internet infrastructure that could expose consumers and businesses to increased risk of attack by scam artists and virus writers. Yesterday, computer software and hardware industry leaders, including Cisco, Microsoft, and Sun Microsystems, coordinated the release of software updates to plug the security hole, which involves a fundamental design flaw in the domain name system. DNS is the communications standard that acts as a kind of telephone book for the Internet, translating human-friendly Web site names like example.com into numeric addresses that are easier for networking equipment to handle and route. Dan Kaminsky, director of penetration testing for Seattle-based security firm IOActive and the discoverer of the vulnerability, said attackers could use the flaw to “poison” the DNS records of network providers. In such an attack scenario, when customers of a targeted ISP try to