Cybersecurity Dive October 10, 2023
Google, AWS and Cloudflare warned the HTTP/2 Rapid Reset attacks are beyond anything ever recorded.
AWS, Cloudflare and Google observed mass exploits of a novel zero-day vulnerability used to launch distributed denial of service attacks reaching a record-breaking scale, the companies said Tuesday.
Security researchers warned threat actors are exploiting the zero-day vulnerability, HTTP/2 Rapid Reset, to launch a series of attacks. Observations of peak requests per second during the attacks varied widely between AWS, Cloudflare and Google.
Google said the attacks peaked at 398 million requests per second, surpassing the peak DDoS attack observed during 2022, which topped off at 46 million requests per second.
The vulnerability is being tracked as CVE-2023-44487 and has a high severity CVSS...