# DDoS

Published articles for DDoS.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## What part of 'No!' is so hard for the DNS understand?

DevFeed: [What part of 'No!' is so hard for the DNS understand?](<https://devfeed.tech/articles/what-part-of-no-is-so-hard-for-the-dns-understand-10859.md>)

Original publisher: [Read original article](<https://blog.apnic.net/2026/09/04/what-part-of-no-is-so-hard-for-the-dns-understand/>)

Author: Geoff Huston

Published: 2026-09-04T01:06:30Z

Content type: article

Language: en

Sources: [APNIC Blog](<https://devfeed.tech/sources/apnic-blog.md>)

Topics: [servers](<https://devfeed.tech/topics/servers.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Availability](<https://devfeed.tech/topics/availability.md>), [Bot](<https://devfeed.tech/topics/bot.md>), [Script](<https://devfeed.tech/topics/script.md>)

Tags: [apnic-labs](<https://devfeed.tech/tags/apnic-labs.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [availability](<https://devfeed.tech/tags/availability.md>), [bots](<https://devfeed.tech/tags/bots.md>), [caching](<https://devfeed.tech/tags/caching.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [dns](<https://devfeed.tech/tags/dns.md>), [generate](<https://devfeed.tech/tags/generate.md>), [measurement](<https://devfeed.tech/tags/measurement.md>), [random](<https://devfeed.tech/tags/random.md>), [server](<https://devfeed.tech/tags/server.md>), [servers](<https://devfeed.tech/tags/servers.md>), [tech-matters](<https://devfeed.tech/tags/tech-matters.md>)

### AI overview

The article explains how random name attacks overwhelm authoritative DNS servers by generating queries for nonexistent names, bypassing recursive resolver caches and potentially causing domain availability failures. It also describes APNIC Labs' measurement work on nonexistent-domain responses to improve DNS resilience.

### Source excerpt

At APNIC Labs we've been experimenting with understanding how the DNS handles requests to resolve nonexistent names to make the DNS more resilient to random name attacks.

## Security Caveat: Locked out of my server while traveling

DevFeed: [Security Caveat: Locked out of my server while traveling](<https://devfeed.tech/articles/security-caveat-locked-out-of-my-server-while-traveling-32362.md>)

Original publisher: [Read original article](<https://joshtronic.com/2026/08/30/security-caveat-locked-out-server-travel/>)

Author: Josh Sherman

Published: 2026-08-30T00:00:00Z

Content type: opinion

Language: en

Sources: [Josh Sherman](<https://devfeed.tech/sources/josh-sherman.md>)

Topics: [Self-hosted](<https://devfeed.tech/topics/self-hosted.md>), [Security](<https://devfeed.tech/topics/security.md>), [Linode](<https://devfeed.tech/topics/linode.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [hosting](<https://devfeed.tech/topics/hosting.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>)

Tags: [command](<https://devfeed.tech/tags/command.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [linode](<https://devfeed.tech/tags/linode.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosting](<https://devfeed.tech/tags/self-hosting.md>)

### AI overview

A personal account of being unable to access a self-hosted server while traveling because firewall rules restricted services and ports to specific IP addresses. The author describes using Linode's web-hosted shell to add a temporary nomadic IP address to the allow list, then plans to remove it afterward.

### Source excerpt

I'm still on my self-hosting kick as of late, while also questioning my life choices around hosting my own git forge. The last week or so has included what appears to be a DDoS attack rather than some coordinated scraping effort by a sketchy LLM company. Open source will prevail, even if I'm being stubborn about giving in and setting up Anubis. WordPress has been its own other adventure, but this isn't meant to be a post about those security caveats. I'll save those for another week. The current dilemma is that I'm far from home, ~30 hours away up in Rhode Island. I'm sitting at Audrey's Coffee House & Lounge, where it was a bit too early to order a BLT. As I sat down to knock out a quick blog post, I realized very quickly that I didn't think things through as well as I had thought. I keep my servers pretty well hardened, including but not limited to limiting access to certain services / ports to specific IP addresses. This tends to not be much of a problem. I do a lot of work from the house, which in itself is a problem I want to remedy in the near future. I also boss agents around remotely, but they are all homebodies as well. Since I like to stay as close to the server as possible, I try to not introduce managed services except where I feel it's absolutely necessary. In this scenario, I use iptables via the ufw command. I don't run a large enough fleet that I'd feel like leveraging Linode's firewall would be beneficial. Path of least resistance today would be to simply compose a blog post and get it live when I'm back home. Could probably just ask one of my friendly robots to take the markdown file and get it out there for me too. But alas, I would prefer to figure out how to pull this off, then blog about it. All while thinking through alternatives so future Josh can look back at this post and ask, "so why didn't you actually do anything you talked about in this post?" This dance probably looks about the same with most modern VPS hosting providers, but my story

## ICYMI: July 2026 @AWS Security

DevFeed: [ICYMI: July 2026 @AWS Security](<https://devfeed.tech/articles/icymi-july-2026-aws-security-4683.md>)

Original publisher: [Read original article](<https://aws.amazon.com/blogs/security/icymi-july-2026-aws-security/>)

Author: Rodolfo Brenes

Published: 2026-08-26T19:32:55Z

Content type: news

Language: en

Sources: [AWS Security Blog](<https://devfeed.tech/sources/aws-security-blog.md>)

Topics: [Application Security](<https://devfeed.tech/topics/application-security.md>), [AI-assisted coding](<https://devfeed.tech/topics/ai-assisted-coding.md>), [AWS IAM](<https://devfeed.tech/topics/aws-iam.md>)

Tags: [ai-agent](<https://devfeed.tech/tags/ai-agent.md>), [ai-coding](<https://devfeed.tech/tags/ai-coding.md>), [ai-security](<https://devfeed.tech/tags/ai-security.md>), [amazon-bedrock](<https://devfeed.tech/tags/amazon-bedrock.md>), [announcements](<https://devfeed.tech/tags/announcements.md>), [aws](<https://devfeed.tech/tags/aws.md>), [compliance](<https://devfeed.tech/tags/compliance.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [foundational-100](<https://devfeed.tech/tags/foundational-100.md>), [iam](<https://devfeed.tech/tags/iam.md>), [secrets](<https://devfeed.tech/tags/secrets.md>), [security](<https://devfeed.tech/tags/security.md>), [security-blog](<https://devfeed.tech/tags/security-blog.md>), [security-identity-compliance](<https://devfeed.tech/tags/security-identity-compliance.md>)

### AI overview

A July 2026 AWS Security roundup covering AI-agent security, data protection, supply-chain protection, firewall automation, DDoS mitigation, and compliance readiness.

### Source excerpt

If you found time for a bit of vacation this summer, you might be in catch-up mode. Here's a list to help: all the expert blog posts, new service capabilities, code samples, and workshops, in case you missed it, from July 2026. AWS Security Blog post This month's AWS Security Blog posts covered AI agent [...]

## Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave

DevFeed: [Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave](<https://devfeed.tech/articles/cloudflare-ddos-threat-report-h1-2026-1-tbps-attacks-soar-as-dns-floods-and-geopolitical-tensions-drive-a-new-wave-113.md>)

Original publisher: [Read original article](<https://blog.cloudflare.com/ddos-threat-report-2026-h1/>)

Author: Cloudforce One

Published: 2026-08-11T13:00:00Z

Content type: article

Language: en

Sources: [Cloudflare Blog](<https://devfeed.tech/sources/cloudflare-blog.md>)

Topics: [DDoS](<https://devfeed.tech/topics/ddos.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Cloudforce One](<https://devfeed.tech/topics/cloudforce-one.md>), [Network](<https://devfeed.tech/topics/network.md>), [data](<https://devfeed.tech/topics/data.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [cloudforce-one](<https://devfeed.tech/tags/cloudforce-one.md>), [data](<https://devfeed.tech/tags/data.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [dns](<https://devfeed.tech/tags/dns.md>), [drive](<https://devfeed.tech/tags/drive.md>), [global](<https://devfeed.tech/tags/global.md>), [government](<https://devfeed.tech/tags/government.md>), [industry](<https://devfeed.tech/tags/industry.md>), [iran](<https://devfeed.tech/tags/iran.md>), [media](<https://devfeed.tech/tags/media.md>), [network](<https://devfeed.tech/tags/network.md>), [radar](<https://devfeed.tech/tags/radar.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [threat-report](<https://devfeed.tech/tags/threat-report.md>)

### AI overview

Cloudflare's H1 2026 DDoS Threat Report analyzes attacks from January through June 2026. It highlights a 519% quarter-over-quarter increase in attacks exceeding 1 Tbps, a shift toward DNS and CLDAP reflection and amplification vectors, and the influence of geopolitical events on attack patterns. The report also covers attack volumes, an April peak, and the possible impact of Operation PowerOFF.

### Source excerpt

In the first half of 2026, Cloudflare detected a 519% surge in hyper-volumetric DDos attacks across its network. These attacks were driven heavily by DNS and CLDAP reflection vectors. This report breaks down how major geopolitical conflicts reshaped the global cyber threat landscape.

## Kimwolf v7: An Evolution of the Kimwolf Botnet

DevFeed: [Kimwolf v7: An Evolution of the Kimwolf Botnet](<https://devfeed.tech/articles/kimwolf-v7-an-evolution-of-the-kimwolf-botnet-7752.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/>)

Author: Asher Davila, Chris Navarrete and Doel Santos

Published: 2026-08-11T10:00:16Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Kimwolf v7](<https://devfeed.tech/topics/kimwolf-v7.md>), [Android](<https://devfeed.tech/topics/android.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Internet of things](<https://devfeed.tech/topics/iot.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Ethereum Name Service (ENS)](<https://devfeed.tech/topics/ens.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Routing (disambiguation)](<https://devfeed.tech/topics/routing.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [android-apk](<https://devfeed.tech/tags/android-apk.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [c2](<https://devfeed.tech/tags/c2.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [devices](<https://devfeed.tech/tags/devices.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [http](<https://devfeed.tech/tags/http.md>), [iot-botnets](<https://devfeed.tech/tags/iot-botnets.md>), [kimwolf-v7](<https://devfeed.tech/tags/kimwolf-v7.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network](<https://devfeed.tech/tags/network.md>), [networks](<https://devfeed.tech/tags/networks.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [routing](<https://devfeed.tech/tags/routing.md>), [rpc](<https://devfeed.tech/tags/rpc.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>)

### AI overview

Kimwolf v7 is an Android and IoT botnet variant that adds HTTP/2-based DDoS flooding with browser fingerprinting, Ethereum Name Service resolution for C2 addresses, and Tor-backed routing to improve infrastructure resilience. The article also describes its targeting of Android TV devices and exploitation of unauthenticated ADB instances.

### Source excerpt

Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42.

## New setup page after domain checkout

DevFeed: [New setup page after domain checkout](<https://devfeed.tech/articles/new-setup-page-after-domain-checkout-1026.md>)

Original publisher: [Read original article](<https://vercel.com/changelog/new-setup-page-after-domain-checkout>)

Author: Can Temizyurek

Published: 2026-08-05T17:00:00Z

Content type: release

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [Vercel](<https://devfeed.tech/topics/vercel.md>), [Routing (disambiguation)](<https://devfeed.tech/topics/routing.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [Amazon Route 53](<https://devfeed.tech/topics/amazon-route-53.md>), [Git](<https://devfeed.tech/topics/git.md>), [Template](<https://devfeed.tech/topics/template.md>)

Tags: [cache](<https://devfeed.tech/tags/cache.md>), [cdn](<https://devfeed.tech/tags/cdn.md>), [checkout](<https://devfeed.tech/tags/checkout.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [dns](<https://devfeed.tech/tags/dns.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [git](<https://devfeed.tech/tags/git.md>), [google](<https://devfeed.tech/tags/google.md>), [routing](<https://devfeed.tech/tags/routing.md>), [vercel](<https://devfeed.tech/tags/vercel.md>)

### AI overview

Vercel has introduced a post-checkout setup page for domain purchases. It tracks registration status and provides guided actions for deploying or connecting projects, proxying or redirecting existing sites, and configuring email DNS records.

### Source excerpt

Buying a domain on Vercel now takes you to a setup page that tracks registration live, with direct paths to deploy a new project, connect an existing one, proxy or redirect a site you already run, or set up email. Registration can take a few minutes. Each setup action unlocks as soon as the domain is ready. If registration fails, the page shows what went wrong and the status of your refund. Deploy a new project or connect an existing one Deploy something opens project creation with the domain preselected. Connect a Git repository, prompt with v0, or start from a template, and the domain is attached when the project deploys. Connect an existing project attaches the domain to a project you pick from your team. Proxy or redirect a site you already run Enter an origin to proxy traffic to, and requests to the domain route through Vercel's CDN. Vercel will cache applicable requests at the edge, and Vercel Firewall's automated DDoS protections will automatically run. Enter a URL to redirect, and visitors are forwarded there. In both cases, Vercel creates a project to handle the routing and configures it for you. Set up email with DNS presets Choose your email provider and Vercel adds the DNS records it needs. Presets are available for Google Workspace, Outlook, iCloud, Proton Mail, Zoho, Mailgun, and ImprovMX. There's also a preset for using the domain as your Bluesky handle. If you'd rather configure records yourself, Manage DNS records opens the domain's DNS records page. Search for a domain at vercel.com/domains to get started. Read more

## Temporal CTO: A 20-year shortcut to build reliable agents

DevFeed: [Temporal CTO: A 20-year shortcut to build reliable agents](<https://devfeed.tech/articles/temporal-cto-a-20-year-shortcut-to-build-reliable-agents-1907.md>)

Original publisher: [Read original article](<https://1password.com/blog/build-reliable-agents>)

Author: info@1password.com (Chris Fowler)

Published: 2026-08-04T00:00:00Z

Content type: article

Language: en

Sources: [Blog on 1Password Blog](<https://devfeed.tech/sources/blog-on-1password-blog.md>)

Topics: [distributed-systems](<https://devfeed.tech/topics/distributed-systems.md>), [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Large Language Model](<https://devfeed.tech/topics/llm.md>), [Processes](<https://devfeed.tech/topics/processes.md>), [Orchestration](<https://devfeed.tech/topics/orchestration.md>)

Tags: [agentic](<https://devfeed.tech/tags/agentic.md>), [agents](<https://devfeed.tech/tags/agents.md>), [ai](<https://devfeed.tech/tags/ai.md>), [architecture](<https://devfeed.tech/tags/architecture.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [developers](<https://devfeed.tech/tags/developers.md>), [distributed-systems](<https://devfeed.tech/tags/distributed-systems.md>), [infrastructure](<https://devfeed.tech/tags/infrastructure.md>), [llm](<https://devfeed.tech/tags/llm.md>), [podcasts](<https://devfeed.tech/tags/podcasts.md>)

### AI overview

The article explains why long-running agentic systems encounter familiar distributed-systems failures, especially state loss and retry storms. It presents durable execution, flow control, queues, and rate limiting as mechanisms for making agents recoverable and resilient in production.

### Source excerpt

Zero-Shot Learning is a podcast about how AI gets built, secured, and deployed. Hosted by Nancy Wang, 1Password CTO, and Dev Tagare, Senior Director of Engineering at Google, it's a builder's view of the architecture and the complex decisions it takes to ship with AI. In this episode, 1Password VP, GM of Developer and AI, Jeff Malnick sits in for Dev. When Maxim Fateev, CTO and co-founder of Temporal, joined Zero-Shot Learning, he brought a historical perspective to the challenges developers face when building agentic systems today. From vanishing state to retry storms, Fateev saw that the failures of deploying long-running agents have parallels to the problems he's been working on for decades. Maxim joined Amazon in 2002, where he co-created Simple Workflow Service, the internal orchestration platform that became one of the most widely used services at Amazon. At Uber, he built Cadence, the open-source predecessor to Temporal, the durable execution platform, which he co-founded in 2019. Temporal now runs production workloads for OpenAI, GitLab, Lovable, Docker, and Cloudflare, and has more than 2,500 customers globally. As the industry builds agentic systems, Fateev is watching it rediscover exactly what his infrastructure was built to solve. A brief history of failures Agents become distributed systems the moment they cross a network. Every call to an LLM, every tool invocation, every write to a downstream service crosses a process boundary, and a process boundary is where distributed systems failures begin. Two common ways agents fail in production are state loss and retry storms. While working, an agent builds state, e.g. a record of which tools it called, the results it received, and how far it progressed in a task. When the process crashes, that record is gone. There is no checkpoint to resume from, no record of what was completed, no way to distinguish completed work from incomplete work. The next run starts from scratch, leaving the operator unsure which act

## What Is Web App and API Protection (WAAP)? | Harness

DevFeed: [What Is Web App and API Protection (WAAP)? | Harness](<https://devfeed.tech/articles/what-is-web-app-and-api-protection-waap-harness-13494.md>)

Original publisher: [Read original article](<https://www.harness.io/blog/what-is-web-app-and-api-protection-waap>)

Author: Michael Isbitski

Published: 2026-07-23T00:00:00Z

Content type: article

Language: en

Sources: [Harness Blog](<https://devfeed.tech/sources/harness-blog.md>)

Topics: [web applications](<https://devfeed.tech/topics/web-applications.md>), [API](<https://devfeed.tech/topics/api.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Bot](<https://devfeed.tech/topics/bot.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [api-security](<https://devfeed.tech/tags/api-security.md>), [bots](<https://devfeed.tech/tags/bots.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [web-app](<https://devfeed.tech/tags/web-app.md>)

### AI overview

This Harness article explains Web Application and API Protection (WAAP) as a unified approach to securing web applications and APIs. It describes combining API discovery, testing, runtime protection, bot and abuse protection, and cloud-scale WAF capabilities, with integration into software delivery workflows.

### Source excerpt

Discover how Harness Web Application and API Protection (WAAP) unifies web app and API security, testing, and runtime protection. Protect your apps, start today | Blog

## Laravel Cloud security defaults behind every deploy

DevFeed: [Laravel Cloud security defaults behind every deploy](<https://devfeed.tech/articles/laravel-cloud-security-defaults-behind-every-deploy-3762.md>)

Original publisher: [Read original article](<https://laravel.com/blog/laravel-cloud-security-defaults-behind-every-deploy>)

Author: Laravel Team

Published: 2026-07-08T10:56:00Z

Content type: article

Language: en

Sources: [Laravel Blog](<https://devfeed.tech/sources/laravel-blog.md>)

Topics: [Laravel](<https://devfeed.tech/topics/laravel.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Security & compliance, Cloud security](<https://devfeed.tech/topics/security-compliance-cloud-security.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [Amazon Web Services](<https://devfeed.tech/topics/aws.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>)

Tags: [aws](<https://devfeed.tech/tags/aws.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-security](<https://devfeed.tech/tags/cloud-security.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

This article explains how Laravel Cloud provides security defaults around every deployment. It describes Laravel's built-in protections, including CSRF validation, escaped output, safe Eloquent bindings, password hashing, mass-assignment protection, and signed URLs, then covers Cloudflare edge filtering, AWS-hosted compute, DDoS mitigation, runtime patching, audit logs, network isolation, and package vulnerability scanning.

### Source excerpt

Laravel Cloud handles WAF, runtime patching, audit logs, network isolation, and package vulnerability scans by default. See what runs in the background.

## Analysis of Telegram IPv6 BGP announcements by Indian ISPs

DevFeed: [Analysis of Telegram IPv6 BGP announcements by Indian ISPs](<https://devfeed.tech/articles/telegram-bgp-hijack-due-to-weird-blackholing-config-39779.md>)

Original publisher: [Read original article](<https://anuragbhatia.com/post/2026/06/telegram-bgp-hijack-and-blackholing/>)

Published: 2026-06-17T23:52:47Z

Content type: opinion

Language: en

Sources: [Personal blog of Anurag Bhatia](<https://devfeed.tech/sources/personal-blog-of-anurag-bhatia.md>)

Topics: [BGP](<https://devfeed.tech/topics/bgp.md>), [networking](<https://devfeed.tech/topics/networking.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>)

Tags: [as135709](<https://devfeed.tech/tags/as135709.md>), [as152144](<https://devfeed.tech/tags/as152144.md>), [as45820](<https://devfeed.tech/tags/as45820.md>), [bgp](<https://devfeed.tech/tags/bgp.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [lightstorm](<https://devfeed.tech/tags/lightstorm.md>), [rfc7999](<https://devfeed.tech/tags/rfc7999.md>), [rtbh](<https://devfeed.tech/tags/rtbh.md>), [telegram](<https://devfeed.tech/tags/telegram.md>), [ttsl](<https://devfeed.tech/tags/ttsl.md>)

### AI overview

The article examines unusual BGP announcements for Telegram IPv6 prefixes by several Indian ISPs after a reported Telegram prefix hijack. It proposes that existing BGP blackholing configurations may have been used to block Telegram traffic, while noting this is the author's interpretation.

### Source excerpt

Since the Telegram's prefix hijack (4 days ago on 17-Jun-2026) by RCom, there is visible noise in the BGP routing table from multiple other Indian ISPs, including Tata Teleservices (AS45820) / Lightstorm (AS135709/AS152144), etc. mostly in IPv6. Let's look at 2a0a:f280::/48 (Live lookup here) Notice all the ASNs here largely seem to be downstreams or peers of AS45820 in India, no major large peer or upstream that would take this announcement outside of India. Similarly, take the case of aggregate - 2a0a:f280::/32. This has TTSL (AS45820) as well as Lightstrom (AS152144/135709) originating these prefixes to smaller peers. Analysis: Possible reason and impact of this behaviour Today I tested some config in lab to see why this could be happening. Here's what I strongly feel is happening (quite sure, unless someone has a better explanation): Indian Govt. has asked ISPs to block Telegram and unlike past blocks mostly at the DNS layer, ISPs have been asked to drop IPs as well. Technically in these cases ISPs could simply add a blackhole route and that would drop traffic going towards these prefixes (from their customers) and that would not be visible at BGP (control plane) but only in traceroutes (data plane). If any of these customers had a full routing feed from those respective ISPs, they would keep on learning Telegram's route with the correct/expected AS_PATH and expected origin AS. Very likely these players had blackhole config setup for the DDoS protection and ended up using the same i.e they are treating Telegram's IPv6 prefixes like they would treat their own when under attack. Also, blackholing is a common practice during DDoS attacks. Imagine a network with a 100G uplink gets hit by a 400G volumetric attack. It will take up all the link bandwidth and thus in these cases ISPs blackhole their own (or downstream) IPs (often small - single /32s or a few) and they signal this to their BGP adjacencies as well. There is a standard BGP blackhole community: 65535:666 as

## Key Components of a Production Web Application

DevFeed: [Key Components of a Production Web Application](<https://devfeed.tech/articles/key-components-of-a-prod-web-application-34686.md>)

Original publisher: [Read original article](<https://newsletter.systemdesigncodex.com/p/key-components-of-a-prod-web-application>)

Author: Saurabh Dashora

Published: 2026-06-09T07:56:22Z

Content type: article

Language: en

Sources: [System Design Codex](<https://devfeed.tech/sources/system-design-codex.md>)

Topics: [web applications](<https://devfeed.tech/topics/web-applications.md>), [CI/CD](<https://devfeed.tech/topics/cicd.md>), [Load Balancing](<https://devfeed.tech/topics/load-balancing.md>), [proxy](<https://devfeed.tech/topics/proxy.md>), [Caching](<https://devfeed.tech/topics/caching.md>)

Tags: [cache](<https://devfeed.tech/tags/cache.md>), [caching](<https://devfeed.tech/tags/caching.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [haproxy](<https://devfeed.tech/tags/haproxy.md>), [web](<https://devfeed.tech/tags/web.md>)

### AI overview

This article provides a high-level overview of components used in production web applications, including CI/CD pipelines, DNS resolution, load balancers, reverse proxies, and content delivery networks. It explains their roles in deployment, availability, scalability, performance, and security.

### Source excerpt

A big picture view...

## Firewall-mitigated traffic is free on Vercel

DevFeed: [Firewall-mitigated traffic is free on Vercel](<https://devfeed.tech/articles/firewall-mitigated-traffic-is-free-on-vercel-1196.md>)

Original publisher: [Read original article](<https://vercel.com/changelog/web-application-firewall-mitigated-traffic-is-free-on-vercel>)

Author: Pranav Kanchi

Published: 2026-05-18T20:00:00Z

Content type: release

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [Firewall](<https://devfeed.tech/topics/firewall.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>)

Tags: [cdn](<https://devfeed.tech/tags/cdn.md>), [cost](<https://devfeed.tech/tags/cost.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [vercel](<https://devfeed.tech/tags/vercel.md>)

### AI overview

Vercel Firewall now waives CDN request and Fast Data Transfer charges for traffic that its WAF denies, challenges, or rate-limits. The change applies automatically to all projects using Vercel Firewall.

### Source excerpt

Vercel Firewall now waives CDN Requests and Fast Data Transfer for any traffic denied, challenged, or rate-limited by Web Application Firewall (WAF). Vercel has always provided unlimited DDoS mitigation at no cost. Vercel WAF, included in CDN cost, gives you custom rules, managed rules, and rate limiting for bad traffic that isn't DDoS. With this change, you don't pay for requests or bandwidth that WAF denies, challenges, or rate-limits. That means no surprise bill when a scraper hammers your product pages, a credential-stuffing botnet hits your login route, or a bot abuses an expensive endpoint. The waiver applies automatically to every project using Vercel Firewall and no configuration is required. Learn how to implement WAF rules in the Firewall documentation. Read more

## 360 billion tokens, 3 million customers, 6 engineers

DevFeed: [360 billion tokens, 3 million customers, 6 engineers](<https://devfeed.tech/articles/360-billion-tokens-3-million-customers-6-engineers-717.md>)

Original publisher: [Read original article](<https://vercel.com/blog/360-billion-tokens-3-million-customers-6-engineers>)

Author: Eric Dodds

Published: 2026-03-18T04:00:00Z

Content type: article

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [hosting](<https://devfeed.tech/topics/hosting.md>), [SSL](<https://devfeed.tech/topics/ssl.md>), [Security](<https://devfeed.tech/topics/security.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [observability](<https://devfeed.tech/topics/observability.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [observability](<https://devfeed.tech/tags/observability.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosting](<https://devfeed.tech/tags/self-hosting.md>), [ssl](<https://devfeed.tech/tags/ssl.md>), [vercel](<https://devfeed.tech/tags/vercel.md>)

### AI overview

This developer case study describes Durable, an AI business builder serving about 1.1 billion tokens per day and 3 million customers with a six-engineer team. It explains how Durable consolidated its multi-tenant, multi-product infrastructure on Vercel to ship production agents quickly and reduce infrastructure costs compared with self-hosting.

### Source excerpt

Impact at a glance Durable ships new production agents to customers in a single day AI features and agents serve ~1.1B tokens per day (360B per year) 10x leverage for every engineer, product manager, and designer 3-4x lower infra cost compared to self hosting Durable began with a simple goal: make owning a business easier than having a job. 60% of U.S. adults say they want to be their own boss, but only about 4% actually do it. Durable's bet is that the blocker isn't ambition. It's friction. "Small businesses are death by a thousand tools, logins, workflows, and designs," explained James Clift, founder of Durable. "If you remove those barriers, business owners can focus on their customers." Today, Durable is an AI business builder that helps entrepreneurs launch in minutes, then optimize with agents that handle things like SEO, content, and operations. The gap between idea and ownership has never been smaller. It feels like one seamless experience to their customers, but under the hood it's a multi-tenant, multi-product platform that has to run millions of individual businesses safely, reliably, and cost-effectively. As they scaled, manually operating multiple services just to self-host was enough work to be a second product. With a small team, Durable chose rapid consolidation over incremental improvement: one codebase, one infrastructure platform. Infra is hard; multi-tenant infra is harder Durable isn't serving one app. They are managing millions of customer sites, CRMs, and agents, each with different traffic patterns and different operational needs. One customer site might get 100x the traffic of another, and power laws show up quickly. When spikes happen, a small portion of Durable customers can consume a disproportionate share of compute, which made cost isolation, attribution, and pricing strategy significant engineering problems. Khan called out a few of the most acute pain-points from self-hosting: Custom domains and SSL at SaaS scale, including paying tho

## Cyber fallout from the Iran war: What to have on your radar

DevFeed: [Cyber fallout from the Iran war: What to have on your radar](<https://devfeed.tech/articles/cyber-fallout-from-the-iran-war-what-to-have-on-your-radar-8329.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/cyber-fallout-iran-war-what-have-radar/>)

Author: Tomáš Foltýn

Published: 2026-03-12T14:17:33Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Amazon Web Services (AWS)](<https://devfeed.tech/topics/amazon-web-services-aws.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>)

Tags: [amazon-web-services-aws](<https://devfeed.tech/tags/amazon-web-services-aws.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [canada](<https://devfeed.tech/tags/canada.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [iran](<https://devfeed.tech/tags/iran.md>), [united-kingdom](<https://devfeed.tech/tags/united-kingdom.md>), [us](<https://devfeed.tech/tags/us.md>)

### AI overview

The article examines the cybersecurity fallout from the Iran war, including attacks on AWS data centers and the rapid mobilization of pro-Iranian cyber groups. It describes hacktivism, APT reconnaissance and initial access, espionage, disruption, sabotage, and the heightened risks to organizations with Middle East supply-chain or cloud dependencies.

### Source excerpt

The cybersecurity implications of the war in the Middle East extend far beyond the region. Here's where to focus your defenses.

## Security Week 2611: атаки на мобильные устройства в 2025 году

DevFeed: [Security Week 2611: атаки на мобильные устройства в 2025 году](<https://devfeed.tech/articles/security-week-2611-2025-23060.md>)

Original publisher: [Read original article](<https://habr.com/ru/companies/kaspersky/articles/1008574/>)

Author: Kaspersky\_Lab ("Лаборатория Касперского")

Published: 2026-03-10T15:13:26Z

Content type: news

Language: ru

Sources: ["Лаборатория Касперского" RU](<https://devfeed.tech/sources/ru-2.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Android](<https://devfeed.tech/topics/android.md>), [Internet of things](<https://devfeed.tech/topics/iot.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [android](<https://devfeed.tech/tags/android.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [iot](<https://devfeed.tech/tags/iot.md>), [kaspersky](<https://devfeed.tech/tags/kaspersky.md>), [malware](<https://devfeed.tech/tags/malware.md>), [security](<https://devfeed.tech/tags/security.md>), [tag-9fe8963de219](<https://devfeed.tech/tags/tag-9fe8963de219.md>), [tag-c30961c9c16f](<https://devfeed.tech/tags/tag-c30961c9c16f.md>)

### AI overview

Kaspersky experts published a final report on mobile-device threats in 2025. The report says more than 14 million attacks involving malware or adware were prevented, with about 815,000 malware variants identified. It highlights threats including the Keenadu backdoor in counterfeit Android firmware, the Kimwolf IoT botnet targeting Android TV devices for DDoS attacks, and the LunaSpy spyware Trojan.

### Source excerpt

Эксперты "Лаборатории Касперского" опубликовали итоговый отчет по угрозам для мобильных устройств за 2025 год. Всего за прошлый год было предотвращено более 14 миллионов атак с использованием вредоносного или рекламного ПО. Было обнаружено около 815 тысяч вариантов вредоносных программ, из которых 255 тысяч относились к банковским троянам. Большая часть вредоносного ПО относится к классу Adware (62%) и RiskTool (19%), троянские программы составили чуть больше 17% от общего количества зловредов, банковские трояны -- 9%. При этом, по сравнению с 2024 годом, количество вредоносных программ, наносящих реальный урон, выросло, а доля нежелательного рекламного ПО снизилась. Отдельный интерес представляют приведенные в отчете примеры неординарного вредоносного ПО, обнаруженного в 2025 году. Это, например, выявленный в конце 2025 года бэкдор Keenadu, который встраивался прямо в прошивки ряда поддельных Android-смартфонов. В отчете также отмечен IoT-ботнет Kimwolf (обзор на китайском языке), нацеленный на приставки Android TV. Зараженные устройства в дальнейшем использовались для проведения DDoS-атак. Читать далее

## Technology Short Take 190

DevFeed: [Technology Short Take 190](<https://devfeed.tech/articles/technology-short-take-190-10921.md>)

Original publisher: [Read original article](<https://blog.scottlowe.org/2026/02/06/technology-short-take-190/>)

Author: Scott Lowe

Published: 2026-02-06T13:00:00Z

Content type: article

Language: en

Sources: [Scott's Weblog](<https://devfeed.tech/sources/scott-s-weblog.md>)

Topics: [networking](<https://devfeed.tech/topics/networking.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Azure](<https://devfeed.tech/topics/azure.md>), [Security](<https://devfeed.tech/topics/security.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Git](<https://devfeed.tech/topics/git.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [macOS](<https://devfeed.tech/topics/macos.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [article](<https://devfeed.tech/tags/article.md>), [aws](<https://devfeed.tech/tags/aws.md>), [azure](<https://devfeed.tech/tags/azure.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [cli](<https://devfeed.tech/tags/cli.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cni](<https://devfeed.tech/tags/cni.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cri-o](<https://devfeed.tech/tags/cri-o.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [devops](<https://devfeed.tech/tags/devops.md>), [docker](<https://devfeed.tech/tags/docker.md>), [git](<https://devfeed.tech/tags/git.md>), [go](<https://devfeed.tech/tags/go.md>), [iac](<https://devfeed.tech/tags/iac.md>), [k8s](<https://devfeed.tech/tags/k8s.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [markdown](<https://devfeed.tech/tags/markdown.md>), [networking](<https://devfeed.tech/tags/networking.md>), [oci](<https://devfeed.tech/tags/oci.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [technology](<https://devfeed.tech/tags/technology.md>), [terraform](<https://devfeed.tech/tags/terraform.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Technology Short Take 190 is a curated roundup of technical reading on networking, solar-storm effects on satellites, hardware, DDoS attacks against Microsoft Azure, Windows encryption, cloud management, Git tools, Terraform and OpenTofu, hosted email, Linux, macOS, and Markdown.

### Source excerpt

Welcome to Technology Short Take #190! This is the first Tech Short Take of 2026, and it has been nearly three months (wow!) since the last one. I can't argue that I fell off the blogging bandwagon over the end of 2025 and early 2026. I won't get into all the reasons why (if you're interested then feel free to reach out and I'll fill you in). Enough about me--let's get to the technical content! Here's hoping you find something useful. Networking Here's a little something on the lighter side about what causes network outages. As the lead-in to this article on Starlink's performance during a solar superstorm says, "It's not science fiction." Solar storms can have a real impact on Earth, and satellites in low-Earth orbit (LEO) are not exempt from that impact. Servers/Hardware William Lam reviews the Mini PC and SFF (small form factor) hardware announcements from CES 2026. Security The scale of DDoS attacks continues to grow, as evidenced by this report of a 15 Tbps attack on Microsoft Azure. Microsoft having the ability to give away your Windows PC's data encryption key is horrifying. Cloud Computing/Cloud Management While doing some reading on Terragrunt, I also came across this open source tool for performing operations against multiple Git repositories. I don't have a use case for it, but it is cool! While on the topic of Terragrunt: let me say that I appreciate the work that went into their online docs! From what I've read so far, they are well-written, clear, concise, and informative. Well done! And while still on the topic of Terragrunt: it was this article from Axel Mendoza on why they use Terragrunt over Terraform/OpenTofu that sent me down the Terragrunt rabbit hole. The most recent installation of Ricardo Sueiras' AWS open source newsletter pointed me to a couple of tools that look really handy: s3sh (available from GitHub) and taws (also available from GitHub). Nick Buraglio has a great comparison of hosted email options. Operating Systems/Applications Howard

## Laravel Cloud is live! Can you ship in 1 minute?

DevFeed: [Laravel Cloud is live! Can you ship in 1 minute?](<https://devfeed.tech/articles/laravel-cloud-is-live-can-you-ship-in-1-minute-3760.md>)

Original publisher: [Read original article](<https://laravel.com/blog/laravel-cloud-is-live-can-you-ship-in-1-minute>)

Author: Sam

Published: 2025-02-21T21:26:00Z

Content type: article

Language: en

Sources: [Laravel Blog](<https://devfeed.tech/sources/laravel-blog.md>)

Topics: [Cloud](<https://devfeed.tech/topics/cloud.md>), [Laravel](<https://devfeed.tech/topics/laravel.md>), [Livewire](<https://devfeed.tech/topics/livewire.md>), [autoscaling](<https://devfeed.tech/topics/autoscaling.md>), [React](<https://devfeed.tech/topics/react.md>), [VS Code Extension](<https://devfeed.tech/topics/vscode-extension.md>), [Vue.js](<https://devfeed.tech/topics/vue.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [SSL](<https://devfeed.tech/topics/ssl.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [autoscaling](<https://devfeed.tech/tags/autoscaling.md>), [caching](<https://devfeed.tech/tags/caching.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [databases](<https://devfeed.tech/tags/databases.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [extension](<https://devfeed.tech/tags/extension.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [react](<https://devfeed.tech/tags/react.md>), [ssl](<https://devfeed.tech/tags/ssl.md>), [sso](<https://devfeed.tech/tags/sso.md>), [tailwind](<https://devfeed.tech/tags/tailwind.md>), [vs-code](<https://devfeed.tech/tags/vs-code.md>), [vue](<https://devfeed.tech/tags/vue.md>)

### AI overview

Laravel announces Laravel Cloud, new Starter Kits for React, Vue, and Livewire, a stable VS Code Extension, and Laravel 12. Laravel Cloud supports rapid deployment with autoscaling, hibernation, managed databases, caching, storage, DDoS protection, SSL, CDN, and edge caching.

### Source excerpt

Today we shipped Laravel Cloud, Starter Kits (React, Vue, & Livewire), VS Code Extension, and Laravel 12.

## Every developer deserves a Vegas Blackout

DevFeed: [Every developer deserves a Vegas Blackout](<https://devfeed.tech/articles/every-developer-deserves-a-vegas-blackout-6093.md>)

Original publisher: [Read original article](<https://turso.tech/blog/vegas-blackout>)

Author: Glauber Costa

Published: 2024-10-24T00:00:00Z

Content type: article

Language: en

Sources: [Turso Blog](<https://devfeed.tech/sources/turso-blog.md>)

Topics: [Turso](<https://devfeed.tech/topics/turso.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [Serverless](<https://devfeed.tech/topics/serverless.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>)

Tags: [database](<https://devfeed.tech/tags/database.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [developer](<https://devfeed.tech/tags/developer.md>), [serverless](<https://devfeed.tech/tags/serverless.md>), [turso](<https://devfeed.tech/tags/turso.md>)

### AI overview

Turso announces Vegas Blackout, a feature that lets users select one day per month before the invoice closes and remove that day's usage charges from their bill. Usage data remains available for records, while the selected day's billable usage is excluded.

### Source excerpt

Some things are better forgotten. Now, you can do that with Turso.

## Securing APIs: Express rate limit and slow down

DevFeed: [Securing APIs: Express rate limit and slow down](<https://devfeed.tech/articles/securing-apis-express-rate-limit-and-slow-down-4115.md>)

Original publisher: [Read original article](<https://developer.mozilla.org/en-US/blog/securing-apis-express-rate-limit-and-slow-down/>)

Author: vultr

Published: 2024-05-28T00:00:00Z

Content type: tutorial

Language: en

Sources: [MDN Blog](<https://devfeed.tech/sources/mdn-blog.md>)

Topics: [Express](<https://devfeed.tech/topics/express.md>), [Security](<https://devfeed.tech/topics/security.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [Bash](<https://devfeed.tech/topics/bash.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [HTML](<https://devfeed.tech/topics/html.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>)

Tags: [bash](<https://devfeed.tech/tags/bash.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [guide](<https://devfeed.tech/tags/guide.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [security](<https://devfeed.tech/tags/security.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>)

### AI overview

This tutorial explains how to secure Express applications by implementing rate limiting and slow-down mechanisms. It covers deploying an application on a server, configuring firewall access, and using these controls to improve resilience, scalability, security, and service reliability.

### Source excerpt

This guide introduces you to rate limits and slow down mechanisms. Learn how to apply slow down and rate limit mechanisms in Express applications.

## Chainguard patches 3 "silent" Golang CVEs in under 24 hours

DevFeed: [Chainguard patches 3 "silent" Golang CVEs in under 24 hours](<https://devfeed.tech/articles/chainguard-patches-3-silent-golang-cves-in-under-24-hours-12975.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-patches-3-silent-golang-cves-in-under-24-hours>)

Published: 2024-03-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Go](<https://devfeed.tech/topics/go.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [toolchain](<https://devfeed.tech/topics/toolchain.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [github](<https://devfeed.tech/tags/github.md>), [go](<https://devfeed.tech/tags/go.md>), [golang](<https://devfeed.tech/tags/golang.md>), [golang-patch](<https://devfeed.tech/tags/golang-patch.md>), [linux](<https://devfeed.tech/tags/linux.md>), [melange](<https://devfeed.tech/tags/melange.md>), [merge](<https://devfeed.tech/tags/merge.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [safe-source-for-open-source](<https://devfeed.tech/tags/safe-source-for-open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [silent-cve](<https://devfeed.tech/tags/silent-cve.md>), [tooling](<https://devfeed.tech/tags/tooling.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard describes how it patched three Golang CVEs in under 24 hours. Its automation monitored new Go releases, opened a pull request, rebuilt the Wolfi package, and updated Chainguard Images containing Go.

### Source excerpt

See how Chainguard swiftly patched three Golang CVEs in under 24 hours, showcasing rapid response and dedication to secure software.

## Find and fix HTTP/2 rapid reset zero-day vulnerability CVE-2023-44487

DevFeed: [Find and fix HTTP/2 rapid reset zero-day vulnerability CVE-2023-44487](<https://devfeed.tech/articles/find-and-fix-http-2-rapid-reset-zero-day-vulnerability-cve-2023-44487-7922.md>)

Original publisher: [Read original article](<https://snyk.io/blog/find-fix-http-2-rapid-reset-zero-day-vulnerability-cve-2023-44487/>)

Author: Jamie Smith; Kriti Dogra; Anthony Larkin

Published: 2023-10-11T23:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [HTTP](<https://devfeed.tech/topics/http.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [nginx](<https://devfeed.tech/topics/nginx.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [aws](<https://devfeed.tech/tags/aws.md>), [azure](<https://devfeed.tech/tags/azure.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [developer](<https://devfeed.tech/tags/developer.md>), [http](<https://devfeed.tech/tags/http.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

This article explains the HTTP/2 Rapid Reset vulnerability, tracked as CVE-2023-44487, which can enable large volumetric DDoS attacks against web servers implementing HTTP/2. It recommends mitigating exposure through infrastructure providers and CDNs, then upgrading affected packages and checking container images and open source ecosystems for remediated versions.

### Source excerpt

Learn how to find and fix the HTTP/2 rapid reset vulnerability (CVE-2023-44487) that has been designated a High severity vulnerability with a CVSS score of 7.5 (out of 10).

## Introducing Shortcut, Figma's new blog

DevFeed: [Introducing Shortcut, Figma's new blog](<https://devfeed.tech/articles/introducing-shortcut-figma-s-new-blog-9910.md>)

Original publisher: [Read original article](<https://www.figma.com/blog/introducing-shortcut-letter-from-the-editor/>)

Author: Amber Bravo

Published: 2023-06-20T00:00:00Z

Content type: article

Language: en

Sources: [Figma Blog](<https://devfeed.tech/sources/figma-blog.md>)

Topics: [Figma](<https://devfeed.tech/topics/figma.md>), [Web](<https://devfeed.tech/topics/web.md>)

Tags: [blog](<https://devfeed.tech/tags/blog.md>), [company](<https://devfeed.tech/tags/company.md>), [content](<https://devfeed.tech/tags/content.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [design](<https://devfeed.tech/tags/design.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [figma](<https://devfeed.tech/tags/figma.md>), [product](<https://devfeed.tech/tags/product.md>)

### AI overview

Figma introduces Shortcut, a new blog focused on stories about people, ideas, priorities, and the process of bringing products to life. The article describes Figma's multiplayer origins, the redesign of its blog experience, new topic navigation, special collections, and contributions from illustrators and writers.

### Source excerpt

Every product has a story. Often, that story unfolds in Figma. Shortcut's mission is to tell stories about people, and the priorities, plans, and pivots they discover along the path of bringing new ideas to life.

## Use these seven incident response metrics to better understand the efficiency of your response processes

DevFeed: [Use these seven incident response metrics to better understand the efficiency of your response processes](<https://devfeed.tech/articles/use-these-seven-incident-response-metrics-to-better-understand-the-efficiency-of-your-response-processes-11834.md>)

Original publisher: [Read original article](<https://incident.io/blog/incident-reporting-metrics>)

Author: incident.io

Published: 2023-03-20T00:00:00Z

Content type: article

Language: en

Sources: [The incident.io Blog](<https://devfeed.tech/sources/the-incident-io-blog.md>)

Topics: [Incident response](<https://devfeed.tech/topics/incident-response.md>), [incident management](<https://devfeed.tech/topics/incident-management.md>), [Availability](<https://devfeed.tech/topics/availability.md>), [Resilience](<https://devfeed.tech/topics/resilience.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [dashboards](<https://devfeed.tech/topics/dashboards.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [servers](<https://devfeed.tech/topics/servers.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [availability](<https://devfeed.tech/tags/availability.md>), [best-practices](<https://devfeed.tech/tags/best-practices.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [efficiency](<https://devfeed.tech/tags/efficiency.md>), [incident](<https://devfeed.tech/tags/incident.md>), [incident-channel](<https://devfeed.tech/tags/incident-channel.md>), [incident-management](<https://devfeed.tech/tags/incident-management.md>), [incident-response](<https://devfeed.tech/tags/incident-response.md>), [metrics](<https://devfeed.tech/tags/metrics.md>), [outage](<https://devfeed.tech/tags/outage.md>), [post-mortem](<https://devfeed.tech/tags/post-mortem.md>), [slack-incident](<https://devfeed.tech/tags/slack-incident.md>), [systems](<https://devfeed.tech/tags/systems.md>), [uptime](<https://devfeed.tech/tags/uptime.md>)

### AI overview

This article presents seven incident response metrics that help organizations understand response processes, identify improvement opportunities, optimize strategies, and strengthen system resilience. It also describes how incident.io's Insights dashboard provides pre-built views for analyzing these metrics.

### Source excerpt

By using these metrics, your organization can get a full picture of the effectiveness of your incident response.

## Own Your Online Presence with a Personal Domain and Social-Media Redirects

DevFeed: [Own Your Online Presence with a Personal Domain and Social-Media Redirects](<https://devfeed.tech/articles/own-your-online-presence-step-1-25306.md>)

Original publisher: [Read original article](<https://kau.sh/blog/own-your-online-presence/>)

Author: Kaushik Gopal

Published: 2023-02-03T03:13:13Z

Content type: tutorial

Language: en

Sources: [Kaushik Gopal's Site](<https://devfeed.tech/sources/kaushik-gopal-s-site.md>)

Topics: [Internet](<https://devfeed.tech/topics/internet.md>), [Website](<https://devfeed.tech/topics/website.md>), [Mastodon](<https://devfeed.tech/topics/mastodon.md>), [Amazon Route 53](<https://devfeed.tech/topics/amazon-route-53.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>)

Tags: [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [dns](<https://devfeed.tech/tags/dns.md>), [internet](<https://devfeed.tech/tags/internet.md>), [io](<https://devfeed.tech/tags/io.md>), [social-media](<https://devfeed.tech/tags/social-media.md>)

### AI overview

The article recommends buying a personal domain, configuring DNS, and creating subdomain redirects for social-media accounts. These redirects let the author preserve familiar URLs when changing platforms or handles, illustrated by a move from mastodon.social to hachyderm.io.

### Source excerpt

Owning your content and where you put it is crucial in the online world. The first step to establishing your corner on the internet is to choose a domain name.1 After obtaining a domain name, many people only set up a website. However, I recommend taking the next step of creating subdomain redirects for your social media handles. By Cloudinary, CC BY-SA 4.0 For example, when mastodon.social suffered a DDoS attack, I moved to hachyderm.io,2 but the mastodon link I hand out to folks remained unchanged. How you ask? It's mastodon.kau.sh and I control the redirect. I just switched it intenally from mastodon.social/@kaushikgopal -> hachyderm.io/@kaush.3 This is also why I am not terribly worried about changing my handles on Github, Twitter, LinkedIn, or YouTube, as I have redirects for all of these: github.kau.sh twitter.kau.sh linkedin.kau.sh youtube.kau.sh To take control of your online presence, buy your own domain, adjust your DNS settings,4 and start using your own URLs. It's a simple first step with a big impact. After many many attempts, I landed on one that I liked. I use namecheap (referral code) ↩︎ It was already on my mind to be honest and I guess this was the push I needed. ↩︎ The added benefit is that I don't have to remember or type Mastodon's unattractive URLs. ↩︎ Cloudflare makes these trivially easy. ↩︎

[Next page](<https://devfeed.tech/tags/ddos.md?cursor=WyIyMDIzLTAyLTAzVDAzOjEzOjEzKzAwOjAwIiwgImI5MTZiZGM4LTM5ODgtNDI4Ny1iZmE5LTk4ZDJhYTY5MWNmMyJd>)