Archive for Cloudflare

Cloudflare Took A Dirt Nap And Tanks The Internet AGAIN

Posted in Commentary with tags on December 5, 2025 by itnerd

If you wanted proof of how reliant the Internet is on content delivery network Cloudflare, this should provide you proof of that. For the second time in a few weeks, Clouldflare takes down the Internet due to an issue that they have resolved as I type this according to their status page. The incident began around 09:00 UTC, and affected much of the web with X, Substack, Canva, LinkedIn, Deliveroo, Spotify, and ironically Downdetector which reports on outages on the Internet, among others going down.

What this makes clear is that putting all of your eggs in the Cloudflare basket isn’t a good idea. Thus maybe there needs to be a wide ranging discussion on how to make the Internet more resilient without relying on a single provider. Just a thought.

Aisuru, “the apex of botnets”, 29.7 Tbps DDoS attack highlighted by Cloudflare

Posted in Commentary with tags on December 3, 2025 by itnerd

Today, Cloudflare posted its 2025 Q3 DDoS threat report highlighting Aisuru, “the apex of botnets”.

   “The third quarter of 2025 was overshadowed by the Aisuru botnet with a massive army of an estimated 1–4 million infected hosts globally. Aisuru unleashed hyper-volumetric DDoS attacks routinely exceeding 1 terabit per second (Tbps) and 1 billion packets per second (Bpps). 

   “The number of these attacks surged 54% quarter-over-quarter (QoQ), averaging 14 hyper-volumetric attacks daily. The scale was unprecedented, with attacks peaking at 29.7 Tbps and 14.1 Bpps,” the blog reads.

The massive network of compromised IoT devices and routers has conducted more than 1,300 DDoS attacks over the past few months. Its latest major strike reached a staggering peak bandwidth of 29.7 Tbps, setting a new world record for volumetric DDoS attacks. 

The attack lasted only about 69 seconds and during that time it sent junk traffic to tens of thousands of destination ports per second, referred to as a “UDP carpet-bombing” method, overwhelming target infrastructure.

Lydia Zhang, President & Co-Founder, Ridge Security Technology Inc. had this to say:

   “The ironic thing is that organizations often don’t realize their IoT devices or routers have been compromised until a DDoS attack occurs.

   “Routine security hygiene is essential: staying on top of issues, patching vulnerabilities, and quarantining problematic assets daily or weekly.

   “Once a collection of ‘individually compromised devices’ turns into an entire ‘army,’ it becomes too late and nearly impossible to regain control.”

Noelle Murata, Sr. Security Engineer, Xcape, Inc. follows with this comment:

   “The recent record-breaking 29.7 Tbps attack by the Aisuru botnet signals a dangerous evolution in cyber warfare. DDoS attacks and large botnets have been a favorite tool used by cybercriminals; these tactics have grown in sophistication, now employing complex “carpet bombing” techniques to evade detection.

   “The number and size of these botnets have grown, exacerbated by the proliferation of IoT devices like routers and cameras. The sheer number of IoT devices exposed to the Internet and their generally poor security capabilities make the population of potential botnet devices immeasurable; Aisuru alone controls up to 4 million hosts.

   “Think of this scenario like a manufacturer selling millions of cheap, remote-controlled toasters. Individually, they simply toast bread. However, because they lack safety switches or locks, a saboteur can hack them to activate simultaneously, creating a massive power surge that melts the city’s entire electrical grid. The grid fails not because of a defect, but because common appliances were weaponized en masse.

   “This should be a call-to-action for IoT device manufacturers to treat their products as not just purpose-built for a single task, but also as devices worth protecting.

   “We cannot allow consumer convenience to arm global threat actors.”

Michael Bell, Founder & CEO, Suzu Labs had this comment:

   “A 29.7 Tbps attack from 1-4 million compromised IoT devices available as botnet-for-hire for a few thousand dollars means nation-state-level disruption capability is now accessible to anyone with a credit card.

   “The most alarming detail in Cloudflare’s report is that Aisuru’s traffic caused “widespread collateral Internet disruption” in the US when ISPs weren’t even the target, which means attacks aimed at critical infrastructure, healthcare, or emergency services could have cascading effects we haven’t fully modeled.

   “Organizations need to stop treating DDoS protection as optional and recognize that the 69-second attack duration means human response is impossible: you either have autonomous, always-on mitigation or you’re offline before anyone can react.”

This report from Cloudflare should not be ignored as it shows how increasingly dangerous DDoS attacks have become. Which means you need to read it and defend yourself accordingly.

Cloudflare Goes Down And Takes A Lot Of The Internet With It

Posted in Commentary with tags on November 18, 2025 by itnerd

If you were trying to get to Twitter, ChatGPT, Salesforce, or any number of other sites and you were having issues, it wasn’t you. Cloudflare, who are a content delivery network that also provides network and security products to companies took a dive. If you have a look at their status page, they acknowledge that they had an issue, but it is in the process of being resolved. But as I type this, there are still scattered reports of issues. Chances are, these issues will likely go away as the day goes on.

The folks at Cisco ThousandEyes have an outage map. I also got this statement from them regarding what they observed:

On November 18, 2025, at approximately 11:30 UTC, Cisco ThousandEyes began observing a global outage affecting cloud and CDN provider Cloudflare, impacting multiple Internet services including X, OpenAI, and Anthropic. While network paths to Cloudflare’s front-end infrastructure appeared clear of any elevated latency or packet loss, Cisco ThousandEyes observed a number of timeouts and HTTP 5XX server errors, which is indicative of a backend services issue. While Cloudflare has confirmed they are implementing remediation, the outage is still ongoing. Sample service impacted by the outage: https://cs.co/604475xqg

Thus for those who were hoping for a digital snow day, sorry.

Cloudflare CDN Flaw Leaks User Location Data

Posted in Commentary with tags on January 23, 2025 by itnerd

A security researcher named Daniel has discovered a flaw in Cloudflare’s CDN potentially exposing someone’s location by sending them an image on platforms like Signal and Discord. Daniel says he is publishing his research as a warning, especially for journalists, activists, and hackers, as hundreds of apps are vulnerable to this undetectable attack, including Signal, Discord and Twitter/X https://gist.github.com/hackermondev/45a3cdfa52246f1d1201c1e8cdef6117

Roger Grimes, data-driven defense evangelist at KnowBe4, commented:

“At first glance, the flaw seems really innocuous and barely relevant, but there are scenarios, like those involving tracked dissents, where it could be a problem. For example, if the agency that’s tracking you knows you’ve got safe houses in one of two countries but isn’t sure which you’re in, this sort of flaw might be interesting to them. Or I’m a woman trying to escape an ex-boyfriend and he’s not sure which relative or friend’s house I’m hiding out at. And the attack is just generic enough that I think it can be applied to more CDNs…I doubt Cloudflare is the only CDN with this sort of vulnerability. Also, kudos to the 15-year old kid that found and released this attack.”

The report by Daniel should be read in detail because it not only shows how bad this flaw is, but the fact that it is still out there waiting to be exploited. Hopefully those who are mentioned in this report such as Cloudflare along with any other products that might be vulnerable to this attack do something to fix this. And for everyone else, I would take the steps that Daniel outlines to protect yourselves.

Cloudflare Tanks For Several Hours Taking A Whole Lot Of Websites And Apps With It

Posted in Commentary with tags on June 21, 2022 by itnerd

Web domains and apps failed to connect this morning due to an outage at content delivery network provider Clouldflare. This impacted tens of thousands of users of said websites and apps. But to the company’s credit, they identified a problem and fixed in a few hours it based on this. But the outage still caused chaos because when Cloudflare goes down, the entire Internet feels it.

Having said that, things should be back to normal. Unless perhaps you’re an Office365 user.

UPDATE: The issue was caused by a network configuration error according to Cloudflare.

You Can Check To See If Your ISP Properly Implements BGP To Protect You

Posted in Commentary with tags on April 20, 2020 by itnerd

Is BGP Safe Yet” is a new site that names and shames internet service providers that don’t tend to their routing in a secure manner. This is important because of this reason laid out by Wired:

For more than an hour at the beginning of April, major sites like Google and Facebook sputtered for large swaths of people. The culprit wasn’t a hack or a bug. It was problems with the internet data routing standard known as the Border Gateway Protocol, which had allowed significant amounts of web traffic to take an unexpected detour through a Russian telecom. For Cloudflare CEO Matthew Prince, it was the last straw. BGP disruptions happen frequently, generally by accident. But BGP can also be hijacked for large-scale spying, data interception, or as a sort of denial of service attack.

That’s where “Is BGP Safe Yet” comes in:

On Friday, the company launched Is BGP Safe Yet​, a site that makes it easier for anyone to check whether their internet service provider has added the security protections and filters that can make BGP more stable. Those improvements are most effective with wide adoption from ISPs, content delivery networks like Cloudflare, and other cloud providers. Cloudflare estimates that so far about half of the internet is more protected thanks to heavy hitters like AT&T, the Swedish telecom Telia, and the Japanese telecom NTT adopting BGP improvements. And while Cloudflare says it doesn’t seem like the Rostelecom incident was intentional or malicious, Russian telecoms do have a history of suspicious BGP meddling, and similar problems will keep cropping up until the whole industry is on board.

Now out of interest, I tested this with Rogers who is my telco. Unsurprisingly they failed:

The reason why I said “unsurprisingly” is that there are a bunch of reasons why an ISP like Rogers might fail a test like this. The biggest one is that infrastructure equipment companies may not properly implement BGP protections. And it is said that 50% of ISPs worldwide may fail this test. But by highlighting the ISPs that do fail, it may motivate them to do something about it and make the Internet a better place for all. Thus I encourage you to use this test with your ISP and place the result on Twitter, which is made easier by the button that they have on the site allowing you to do that with the following result:

There’s nothing like bad press on Twitter to get the attention of those who run ISPs.

Cloudflare Security Breach Exposes Data From 3400 Websites Including, Fitbit & Uber

Posted in Commentary with tags on February 24, 2017 by itnerd

User data from 3,400 websites has been leaked and cached by search engines as a result of a bug in the Cloudflare content delivery network. The goal of a content delivery network is to serve content to end-users with high availability and high performance.But instead, this one leaked data and the leaks were spotted by Google security researcher Tavis Ormandy who has a habit of spotting this sort of thing. A Cloudflare blog post acknowledges that the issue was serious, but says there is no evidence of it having been exploited:

The bug was serious because the leaked memory could contain private information and because it had been cached by search engines. We have also not discovered any evidence of malicious exploits of the bug or other reports of its existence.

But Cloudflare’s response was quickly smacked down by Ormandy:

[The company’s blog post] contains an excellent postmortem, but severely downplays the risk to customers.

An unofficial list of sites that may be affected has been posted to Github and it includes sites like Fitbit and Uber, but note that this includes all domains that use Cloudflare DNS. That means that this is a much larger number than use the affected services. In the meantime Google, Bing, Yahoo and other search engines have been working on clearing cached data from the breach before anyone went public. But that doesn’t mean that nothing leaked out as this issue likely existed for months before being patched.