< ciso
brief />
Tag Banner

All news with #ddos tag

146 articles

Managing AI token costs and denial-of-wallet risk

🧭 Companies rapidly adopted AI agents, but unpredictable and spiking token consumption has created financial, reliability, and security challenges. Automated processes exposed to external inputs can be weaponized as a new form of DDoS that drives up usage fees. As pay-as-you-go billing replaces flat subscriptions, organizations face surprise overspend and need FinOps-like practices tailored to probabilistic generative AI. Practical measures include restricting agent permissions, setting token limits and alerts, validating external inputs, and calculating per-unit costs to detect billing anomalies.
read more →

x47.c Botnet Offers AI API Draining and More

🔍 Researchers have uncovered a previously undocumented Windows botnet named x47.c that advertises 18 attack methods, including an "AI API drain" designed to exhaust paid AI credits. Qrator Research Labs analyzed seller materials from WraithTools and found modules for credential theft, SOCKS5 proxying and an AI-assisted persistence feature. The botnet also supports multiple DDoS techniques, fast-flux routing and a stealer targeting browser credentials and tokens.
read more →

NoName057(16) Relaunches DDoS Campaigns Against Japan

🛡️ On August 24, 2026, pro-Russian hacktivist collective NoName057(16) announced the relaunch of #OpJapan, a DDoS campaign targeting Japanese organizations in response to Japan's support for Ukraine and NATO. The group claimed 66 attacks against 26 entities across maritime, logistics and government sectors between August 24 and 30, using both volumetric floods and targeted requests against costly site functions. Activity has mostly been DDoS, with opportunistic intrusions against small- to medium-sized businesses and no observed data theft or backend compromises. By August 31, activity slowed as attention shifted to #OpEstonia, while coalition partners like Dark Storm Team joined the wave.
read more →

Cloudflare launches Adaptive Intelligence for bots

🛡️ Cloudflare today unveiled Adaptive Intelligence, a new non-deterministic bot detection engine designed to make attacks slow and costly rather than trying to keep every attacker out. It continuously retrains on live traffic, generates short-lived disposable rules, and learns from labeled corrections across the network to reduce attacker feedback. The approach complements behavioral validation and aims to balance protection with low false positives for real users.
read more →

Massive DDoS Disrupts Norway’s Government Services

🔒 A large DDoS attack began at 03:38 CEST, disrupting the Norwegian Digitalization Agency (Digdir) and its provider Vivicta, affecting public-service logins, electronic IDs and signatures, secure digital mail, and inter-agency data exchange. Several services were briefly unavailable and some, including ID-porten and eSignering, remain partially inaccessible, causing login errors and slow responses. Digdir reports stabilization of many systems, no evidence of a security breach or personal data compromise, and has notified NSM and Datatilsynet. This is the third recent DDoS against Digdir; there is no official attribution but media have speculated about Russian involvement.
read more →

Amazon GameLift Servers Adds Enhanced DDoS Protection

🛡️ Amazon GameLift Servers now includes Enhanced DDoS Protection, automatically active when you run game servers with no configuration required. The feature provides gaming-optimized traffic shaping to mitigate common network and transport layer attacks such as UDP reflection and SYN floods. It complements AWS Shield Standard and integrates with the Player Gateway relay option for higher-risk games.
read more →

CDN Tsunami: HTTP/3-to-HTTP/1.1 Amplification Risk

🔍 Researchers disclosed two denial-of-service techniques, collectively dubbed CDN Tsunami, that exploit how major CDNs translate client-facing HTTP/3 into backend HTTP/1.1 requests, amplifying small attacker traffic to large origin load. The study tested Alibaba, Baidu, Cloudflare, CloudFront, Fastly, and Tencent, finding widespread susceptibility to a bandwidth amplification variant and partial susceptibility to a connection-amplification variant. Vendor mitigations are applied at CDN edges, and the work will be presented at a September 2026 symposium.
read more →

Cloudflare: Massive rise in >1 Tbps DDoS attacks

🛡️ Cloudflare reported it mitigated over 800 network-layer DDoS attacks exceeding 1 Tbps in Q2, a more than fivefold increase from Q1's 130 such events. The company, which protects roughly 20% of the web, also defended against a record 31.4 Tbps attack by the Aisuru/Kimwolf botnet. In H1 it mitigated 23.2 million network-layer attacks and handled 29.64 trillion malicious HTTP requests, while noting most attacks remained small and short-lived.
read more →

Cloudflare DDoS Threat Report H1 2026 Summary

📊 Cloudflare's H1 2026 DDoS Threat Report from Cloudforce One summarizes DDoS activity across January–June 2026. The report details mitigation of 23.2 million network-layer attacks and 29.64 trillion HTTP requests, highlights April as a peak month, and describes growth in hyper-volumetric and reflection-based vectors like CLDAP. It emphasizes the necessity of automated, always-on protection.
read more →

North Carolina ports confirm disruptive cyberattack

🔒 The North Carolina Ports Authority confirmed a cyberattack disrupted IT systems and slowed operations at the Port of Wilmington, Port of Morehead City, and the Charlotte Inland Port. The incident was detected on August 4, with recovery actions initiated August 5 and gates operating on a normal schedule by August 7. The authority has not attributed the incident to any threat actor or confirmed data theft, and some delays continue as systems are restored.
read more →

Dysphoria botnet compromises 200,000 IoT devices

🔍 Researchers report a new botnet named Dysphoria has infected roughly 200,000 devices globally and is being used for DDoS attacks and traffic relay operations. QiAnXin XLab attributes Dysphoria's evolution to earlier malware families and notes it uses Ethereum ENS and Solana SNS domains for covert C2 resolution. The botnet spreads via weak Telnet/SSH credentials and known router and IoT vulnerabilities, and some variants now solely provide proxy services.
read more →

AWS Shield Advanced adopts Anti‑DDoS WAF rule group

🛡️ In June 2025 AWS introduced the AWS WAF Anti‑DDoS managed rule group to protect application‑layer (L7) traffic. Starting July 27, 2026, Shield Advanced will add this rule group to eligible web ACLs in Count mode and eventually replace Shield’s existing L7 automatic mitigation by January 1, 2027. The rollout includes a free evaluation period, configurable sensitivities, new Challenge actions, reduced WCU usage, and a dedicated dashboard and metrics for observability.
read more →

148 npm Packages Masked as Student Proxies Abused

🔍 JFrog researchers found 148 npm packages posing as student web proxies that converted visitors' browsers into a DDoS botnet for roughly two weeks in May. The packages hosted a proxy UI but loaded a mutable remote script and a WebSocket flood generator, allowing attackers to run volumetric and control-plane attacks from unsuspecting users' tabs. Many packages have since been removed, but remnants and mutable loaders remain active, so network and build mitigations are advised.
read more →

Cloudflare joins UK cyber resilience pledge

🔐 Cloudflare announced it has joined the UK government's Cyber Resilience Pledge as a founding signatory, aligning with the pledge’s pillars of democratized security, leadership accountability, and radical transparency. The post highlights rising cyber threats — including massive DDoS volumes and AI-driven attack vectors — and describes how Cloudflare's global network, zero trust controls, and free protections support resilience across the UK economy. Cloudflare emphasizes supply-chain assurance, board-level governance, and international certifications to meet the pledge's aims.
read more →

Amazon GameLift Servers adds DDoS protection SDKs

🛡️ Amazon GameLift Servers now includes DDoS Protection client SDKs for C# and Unity, enabling developers to protect session-based multiplayer games from denial-of-service and distributed denial-of-service attacks. The service co-locates a relay network with game servers and uses access token-based authentication to allow only authorized client traffic. It enforces per-player UDP traffic limits, offers negligible latency, and is provided at no extra cost to GameLift Servers customers. The new SDKs complement existing C++ and Unreal Engine support and are available in multiple AWS regions.
read more →

Cloudflare Celebrates 12 Years of Project Galileo

🎉 Project Galileo provides free cybersecurity services to over 3,400 websites belonging to journalists, human rights defenders, and nonprofits across 120 countries. Cloudflare published its first comprehensive report on cyberattacks targeting civil society, released 16 participant case studies, and announced new partners. The findings show civil society faces more frequent and intense attacks, including prolonged DDoS, higher exploitation attempts, and elevated phishing rates. Cloudflare calls for broader, affordable protections and will produce this report annually.
read more →

Cybercrime Escalates Across Asia-Pacific Amid Digitization

🛡️Interpol warns that cybercrime now accounts for 30% of crime in over half of Asia and South Pacific nations, driven by rapid digital adoption. The 2025/2026 Asia and South Pacific Cyberthreat Assessment, covering 18 countries, highlights online scams, infostealers, ransomware, deepfakes and BEC as primary threats. The report notes sharp rises in ransomware, DDoS and deepfake activity, and calls for improved cross-border collaboration and capacity building.
read more →

Gain visibility into DDoS attacks with flow logs

🛡️ This post explains how AWS Shield Advanced attack flow logs capture metadata during DDoS events and publish records to Amazon S3, CloudWatch Logs, or Data Firehose. It outlines the fields included in each flow log entry, describes delivery configuration and required IAM permissions, and shows how to create the CloudWatch Logs delivery objects that connect a Shield protection to a destination. The article also covers output formats, file size and timing, cost considerations, and cross-account/Region aggregation options.
read more →

Pre-positioned Cyber Threats Targeting FIFA 2026

🛡️ Check Point Research and Exposure Management tracked a year-long rise in coordinated cyber threats aimed at FIFA World Cup 2026. Attackers have pre-positioned infrastructure across finance, travel and hospitality, and gambling, with active domains, fake apps, and social schemes ready to scale. The report highlights escalating fraud, domain impersonation, mobile-app impersonation, B2B spoofing risks, and potential operational impacts like ransomware and DDoS.
read more →

Inside C0XMO: Cross-Platform Gafgyt Propagation

🛡️ FortiGuard Labs details a new Gafgyt variant, C0XMO, which exploits CVE-2021-27137 in vulnerable DD-WRT firmware to gain remote control of devices. The malware separates scanning into a standalone Python scanner and distributes architecture-specific ELF payloads to multiple Linux platforms. C0XMO implements multi-stage persistence, kills competing botnets, supports extensive DDoS commands, and communicates with a C2 using a custom handshake. Organizations should update firmware, disable unnecessary remote services, and enforce strong credentials to mitigate risk.
read more →