Cybersecurity Alert: Cloudflare Faces Largest DDoS Attack in History

Image by Pixabay

This post is also available in: עברית (Hebrew)

Cloudflare has unveiled the largest distributed denial of service (DDoS) attack to date, peaking at an astonishing 3.8 terabits per second. This unprecedented wave of DDoS attacks occurred throughout September, testing the defenses of numerous internet properties.

In its latest report, Cloudflare asserts that its systems successfully mitigated this barrage of attacks, with over 100 incidents reported in September alone. Many of these assaults exceeded two billion packets and three terabits per second. “Detection and mitigation was fully autonomous,” the report noted, emphasizing the company’s advanced capabilities in countering such threats.

However, Cloudflare cautions that not all internet properties are safe from these massive assaults. Previously, the Australian security firm Global Secure Layer reported mitigating a high packet-rate attack, although it had a comparatively lower bit rate. Cloudflare warns that the sheer scale of these attacks can overwhelm unprotected internet properties as well as those shielded by on-premise equipment or cloud providers lacking sufficient network capacity.

The recent wave of attacks predominantly targets sectors such as financial services, telecommunications, and internet services. Alarmingly, nearly a quarter of all malicious traffic emanates from just two countries: Russia (12.1%) and Vietnam (11.6%), with significant contributions also from Brazil, Spain, and the U.S.

Cybercriminals are exploiting UDP (User Datagram Protocol) packets to launch these attacks, using compromised devices like MikroTik routers, DVRs, and web servers. A particular concern is the discovery of compromised Asus home routers, which were likely exploited due to a critical vulnerability found earlier this year.

DDoS attacks aim to disrupt legitimate users’ access by saturating bandwidth or exhausting system resources. While often viewed as a nuisance, these attacks can severely impact service availability, underscoring the importance of robust defense strategies in today’s digital world.