Threat Bulletin 0523: HTTP/2 rapid reset against a online payments platform in Latin America
HTTP/2 rapid reset against a online payments platform in Latin America, peaking at 963.2 million requests per second. Mitigated in 0.069 seconds.
HTTP/2 rapid reset against a online payments platform in Latin America, peaking at 963.2 million requests per second. Mitigated in 0.069 seconds.
Rolled out to all points of presence on 20 February 2023. No action is required. Deprecated challenged vs. dropped traffic […]
CLDAP reflection against a fashion retail platform in Iberia, peaking at 291.5 Gbps. Mitigated in 0.009 seconds.
TLS handshake exhaustion against a crypto exchange platform in the Benelux, peaking at 252.2 million requests per second. Mitigated in 0.043 seconds.
Rolled out to all points of presence on 28 January 2023. No action is required. Faster rule propagation: median 10 […]
HTTP/2 rapid reset against a education platform platform in Western Europe, peaking at 821.6 million requests per second. Mitigated in 0.378 seconds.
credential stuffing against a online payments platform in Iberia, peaking at 432.0 million requests per second. Mitigated in 0.934 seconds.
Rolled out to all points of presence on 10 December 2022. No action is required. Log streaming now supports CVE-2026-1127. […]
UDP reflection (DNS) against a B2B SaaS platform in Southeast Asia, peaking at 120.7 Gbps. Mitigated in 0.950 seconds.
cache-busting query flood against a sports betting platform in Latin America, peaking at 165.0 million requests per second. Mitigated in 0.148 seconds.
GRE flood against a tax authority portal platform in Western Europe, peaking at 55.2 Gbps. Mitigated in 0.612 seconds.
Rolled out to all points of presence on 10 November 2022. No action is required. Added GraphQL depth limits support […]