< ciso
brief />
Tag Banner

All news with #ddos tag

140 articles

CDN Tsunami: HTTP/3-to-HTTP/1.1 Amplification Risk

🔍 Researchers disclosed two denial-of-service techniques, collectively dubbed CDN Tsunami, that exploit how major CDNs translate client-facing HTTP/3 into backend HTTP/1.1 requests, amplifying small attacker traffic to large origin load. The study tested Alibaba, Baidu, Cloudflare, CloudFront, Fastly, and Tencent, finding widespread susceptibility to a bandwidth amplification variant and partial susceptibility to a connection-amplification variant. Vendor mitigations are applied at CDN edges, and the work will be presented at a September 2026 symposium.
read more →

Cloudflare: Massive rise in >1 Tbps DDoS attacks

🛡️ Cloudflare reported it mitigated over 800 network-layer DDoS attacks exceeding 1 Tbps in Q2, a more than fivefold increase from Q1's 130 such events. The company, which protects roughly 20% of the web, also defended against a record 31.4 Tbps attack by the Aisuru/Kimwolf botnet. In H1 it mitigated 23.2 million network-layer attacks and handled 29.64 trillion malicious HTTP requests, while noting most attacks remained small and short-lived.
read more →

Cloudflare DDoS Threat Report H1 2026 Summary

📊 Cloudflare's H1 2026 DDoS Threat Report from Cloudforce One summarizes DDoS activity across January–June 2026. The report details mitigation of 23.2 million network-layer attacks and 29.64 trillion HTTP requests, highlights April as a peak month, and describes growth in hyper-volumetric and reflection-based vectors like CLDAP. It emphasizes the necessity of automated, always-on protection.
read more →

North Carolina ports confirm disruptive cyberattack

🔒 The North Carolina Ports Authority confirmed a cyberattack disrupted IT systems and slowed operations at the Port of Wilmington, Port of Morehead City, and the Charlotte Inland Port. The incident was detected on August 4, with recovery actions initiated August 5 and gates operating on a normal schedule by August 7. The authority has not attributed the incident to any threat actor or confirmed data theft, and some delays continue as systems are restored.
read more →

Dysphoria botnet compromises 200,000 IoT devices

🔍 Researchers report a new botnet named Dysphoria has infected roughly 200,000 devices globally and is being used for DDoS attacks and traffic relay operations. QiAnXin XLab attributes Dysphoria's evolution to earlier malware families and notes it uses Ethereum ENS and Solana SNS domains for covert C2 resolution. The botnet spreads via weak Telnet/SSH credentials and known router and IoT vulnerabilities, and some variants now solely provide proxy services.
read more →

AWS Shield Advanced adopts Anti‑DDoS WAF rule group

🛡️ In June 2025 AWS introduced the AWS WAF Anti‑DDoS managed rule group to protect application‑layer (L7) traffic. Starting July 27, 2026, Shield Advanced will add this rule group to eligible web ACLs in Count mode and eventually replace Shield’s existing L7 automatic mitigation by January 1, 2027. The rollout includes a free evaluation period, configurable sensitivities, new Challenge actions, reduced WCU usage, and a dedicated dashboard and metrics for observability.
read more →

148 npm Packages Masked as Student Proxies Abused

🔍 JFrog researchers found 148 npm packages posing as student web proxies that converted visitors' browsers into a DDoS botnet for roughly two weeks in May. The packages hosted a proxy UI but loaded a mutable remote script and a WebSocket flood generator, allowing attackers to run volumetric and control-plane attacks from unsuspecting users' tabs. Many packages have since been removed, but remnants and mutable loaders remain active, so network and build mitigations are advised.
read more →

Cloudflare joins UK cyber resilience pledge

🔐 Cloudflare announced it has joined the UK government's Cyber Resilience Pledge as a founding signatory, aligning with the pledge’s pillars of democratized security, leadership accountability, and radical transparency. The post highlights rising cyber threats — including massive DDoS volumes and AI-driven attack vectors — and describes how Cloudflare's global network, zero trust controls, and free protections support resilience across the UK economy. Cloudflare emphasizes supply-chain assurance, board-level governance, and international certifications to meet the pledge's aims.
read more →

Amazon GameLift Servers adds DDoS protection SDKs

🛡️ Amazon GameLift Servers now includes DDoS Protection client SDKs for C# and Unity, enabling developers to protect session-based multiplayer games from denial-of-service and distributed denial-of-service attacks. The service co-locates a relay network with game servers and uses access token-based authentication to allow only authorized client traffic. It enforces per-player UDP traffic limits, offers negligible latency, and is provided at no extra cost to GameLift Servers customers. The new SDKs complement existing C++ and Unreal Engine support and are available in multiple AWS regions.
read more →

Cloudflare Celebrates 12 Years of Project Galileo

🎉 Project Galileo provides free cybersecurity services to over 3,400 websites belonging to journalists, human rights defenders, and nonprofits across 120 countries. Cloudflare published its first comprehensive report on cyberattacks targeting civil society, released 16 participant case studies, and announced new partners. The findings show civil society faces more frequent and intense attacks, including prolonged DDoS, higher exploitation attempts, and elevated phishing rates. Cloudflare calls for broader, affordable protections and will produce this report annually.
read more →

Cybercrime Escalates Across Asia-Pacific Amid Digitization

🛡️Interpol warns that cybercrime now accounts for 30% of crime in over half of Asia and South Pacific nations, driven by rapid digital adoption. The 2025/2026 Asia and South Pacific Cyberthreat Assessment, covering 18 countries, highlights online scams, infostealers, ransomware, deepfakes and BEC as primary threats. The report notes sharp rises in ransomware, DDoS and deepfake activity, and calls for improved cross-border collaboration and capacity building.
read more →

Gain visibility into DDoS attacks with flow logs

🛡️ This post explains how AWS Shield Advanced attack flow logs capture metadata during DDoS events and publish records to Amazon S3, CloudWatch Logs, or Data Firehose. It outlines the fields included in each flow log entry, describes delivery configuration and required IAM permissions, and shows how to create the CloudWatch Logs delivery objects that connect a Shield protection to a destination. The article also covers output formats, file size and timing, cost considerations, and cross-account/Region aggregation options.
read more →

Pre-positioned Cyber Threats Targeting FIFA 2026

🛡️ Check Point Research and Exposure Management tracked a year-long rise in coordinated cyber threats aimed at FIFA World Cup 2026. Attackers have pre-positioned infrastructure across finance, travel and hospitality, and gambling, with active domains, fake apps, and social schemes ready to scale. The report highlights escalating fraud, domain impersonation, mobile-app impersonation, B2B spoofing risks, and potential operational impacts like ransomware and DDoS.
read more →

Inside C0XMO: Cross-Platform Gafgyt Propagation

🛡️ FortiGuard Labs details a new Gafgyt variant, C0XMO, which exploits CVE-2021-27137 in vulnerable DD-WRT firmware to gain remote control of devices. The malware separates scanning into a standalone Python scanner and distributes architecture-specific ELF payloads to multiple Linux platforms. C0XMO implements multi-stage persistence, kills competing botnets, supports extensive DDoS commands, and communicates with a C2 using a custom handshake. Organizations should update firmware, disable unnecessary remote services, and enforce strong credentials to mitigate risk.
read more →

AWS Direct Connect adds VIF Rate Limiters

🛡️ AWS Direct Connect now supports Virtual Interface (VIF) Rate Limiters on dedicated connections to prevent a single VIF from consuming all bandwidth and causing congestion. You can cap bandwidth for up to 10 VIFs per dedicated connection with increments from 50 Mbps to 1.6 Tbps when using a link aggregation group. Rate limiting applies to both ingress and egress, and excess packets are dropped. New CloudWatch metrics include utilization as a percentage of configured capacity and dropped packet counts, and the feature is available in all supported commercial and China Regions via console, API, or SDK.
read more →

AWS Shield Advanced adds DDoS attack flow logs

📡 AWS Shield Advanced now provides DDoS attack flow logs that deliver packet-level visibility into traffic targeting Shield-protected resources. The logs capture source and destination IPs, ports, protocols, packet and byte counts, and source country details, and are published every five minutes during active attacks. Log data can be delivered to Amazon S3, Amazon CloudWatch Logs, or Amazon Data Firehose for forensic analysis, threat intelligence, and compliance. To use the feature, resources must be protected by Shield Advanced and log delivery must be configured; the feature is available in all regions where Shield Advanced operates.
read more →

DDoS-as-a-Service: Evolution of a Paid Market

🔍 DDoS attacks are increasingly packaged and sold as polished online services, lowering barriers for would-be attackers and reshaping the underground market. Flare researchers compared DDoS-related underground activity from early 2023 and early 2026, finding a marked rise in service ads, actors, and professionalized offerings. Ads now emphasize panels, APIs, botnet backing, pricing tiers, and reseller programs, while public mitigations report multi-terabit attacks. The market’s shift toward productized services means defenders must assume easier access to disruptive capabilities.
read more →

Attack Surface and Cyber Risks for FIFA 2026

📘 The 2026 FIFA World Cup spans 39 days across 16 host cities in three nations, creating a vast temporary tournament network layered on existing stadium and municipal infrastructure. This assessment warns of high likelihoods for disruptive intrusions, large-scale fraud and politically motivated DDoS and hack-and-leak operations. Key drivers include Iran-nexus disruptive campaigns, pro-Russian hacktivist DDoS activity and financially motivated cybercrime targeting fans and the hospitality ecosystem.
read more →

Dutch raid seizes servers, arrests hosting co-owners

🛡️ Dutch authorities arrested two co-owners of related hosting companies and seized over 800 servers on May 18, alleging they operated infrastructure used by Russia for cyberattacks and influence operations targeting the EU. The arrests follow investigative reporting that linked MIRhosting and WorkTitans to Stark Industries, an ISP sanctioned by the EU for facilitating DDoS, proxy, and anonymity services tied to Russia-backed actors. Officials searched businesses and data centers and charged the suspects with violating sanctions law by making economic resources available to sanctioned entities. Both suspects deny wrongdoing and one company says it has paused services to the implicated client pending internal review.
read more →

Global takedown of criminal VPN service First VPN

🔎 Authorities across Europe and North America announced a coordinated operation that dismantled First VPN, a criminal virtual private network service used to obscure ransomware, data theft, scanning, and DDoS activity. Led by France and the Netherlands with support from many countries and agencies since December 2021, investigators executed concurrent actions in May 2026, seizing servers, domains, and infrastructure while interviewing the service administrator. Europol and the FBI say First VPN marketed anonymity to cybercriminals on Russian-language forums, offered multiple protocols and payment methods, and provided exit nodes across 27 countries used by at least 25 ransomware groups.
read more →