image credit: Adobe Stock

Internet-Wide Zero-Day Bug Fuels Largest-Ever DDoS Event

October 12, 2023


An Internet-wide security vulnerability is at the root of a zero-day attack dubbed “HTTP/2 Rapid Reset,” which resulted in a distributed denial-of-service (DDoS) flood that was orders of magnitude larger than any previous attack ever recorded. It marks a new chapter in the evolution of DDoS threats, researchers noted.

Amazon Web Services, Cloudflare, and Google Cloud each independently observed the attack in question, which featured multiple waves of traffic that lasted for just minutes each. They targeted cloud and Internet infrastructure providers, and the attack took place over Aug. 28–29. Unknown perpetrators are behind the event, but it’s clear that they exploited a bug in the HTTP/2 protocol, which is used in about 60% of all Web applications.

Read More on Network Computing