# DDoS

A denial-of-service technique that uses numerous hosts to perform an attack.

This is one page of public article previews, not the complete archive. Follow Next page to continue. Summaries are not the original full articles.

## September 2026 Security Updates #1 for XCP-ng 8.3 LTS

DevFeed: [September 2026 Security Updates #1 for XCP-ng 8.3 LTS](<https://devfeed.tech/articles/september-2026-security-updates-1-for-xcp-ng-8-3-lts-12827.md>)

Original publisher: [Read original article](<https://xcp-ng.org/blog/2026/09/08/september-2026-security-updates-1-for-xcp-ng-8-3-lts/>)

Author: David Morel

Published: 2026-09-08T14:07:29Z

Content type: article

Language: en

Sources: [XCP-ng Blog](<https://devfeed.tech/sources/xcp-ng-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Memory Leaks](<https://devfeed.tech/topics/memory-leaks.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [cve](<https://devfeed.tech/tags/cve.md>), [lts](<https://devfeed.tech/tags/lts.md>), [maintenance-updates](<https://devfeed.tech/tags/maintenance-updates.md>), [memory-leak](<https://devfeed.tech/tags/memory-leak.md>), [release](<https://devfeed.tech/tags/release.md>), [security](<https://devfeed.tech/tags/security.md>), [september-2026](<https://devfeed.tech/tags/september-2026.md>), [updates](<https://devfeed.tech/tags/updates.md>), [vulnerabilities](<https://devfeed.tech/tags/vulnerabilities.md>)

### AI overview

This article announces September 2026 security updates for XCP-ng 8.3 LTS. The fixes address vulnerabilities in Xen, oxenstored, and Tapdisk, including memory leaks, denial-of-service conditions, and out-of-bounds accesses that could allow code execution with administrator privileges in dom0. One Xen issue does not affect supported XCP-ng 8.3 LTS installations and is deferred for defense in depth.

### Source excerpt

New security and maintenance updates are available for XCP-ng 8.3 LTS. This includes update to Xen, oxenstored and blktap.

## What part of 'No!' is so hard for the DNS understand?

DevFeed: [What part of 'No!' is so hard for the DNS understand?](<https://devfeed.tech/articles/what-part-of-no-is-so-hard-for-the-dns-understand-10859.md>)

Original publisher: [Read original article](<https://blog.apnic.net/2026/09/04/what-part-of-no-is-so-hard-for-the-dns-understand/>)

Author: Geoff Huston

Published: 2026-09-04T01:06:30Z

Content type: article

Language: en

Sources: [APNIC Blog](<https://devfeed.tech/sources/apnic-blog.md>)

Topics: [servers](<https://devfeed.tech/topics/servers.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Availability](<https://devfeed.tech/topics/availability.md>), [Bot](<https://devfeed.tech/topics/bot.md>), [Script](<https://devfeed.tech/topics/script.md>)

Tags: [apnic-labs](<https://devfeed.tech/tags/apnic-labs.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [availability](<https://devfeed.tech/tags/availability.md>), [bots](<https://devfeed.tech/tags/bots.md>), [caching](<https://devfeed.tech/tags/caching.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [dns](<https://devfeed.tech/tags/dns.md>), [generate](<https://devfeed.tech/tags/generate.md>), [measurement](<https://devfeed.tech/tags/measurement.md>), [random](<https://devfeed.tech/tags/random.md>), [server](<https://devfeed.tech/tags/server.md>), [servers](<https://devfeed.tech/tags/servers.md>), [tech-matters](<https://devfeed.tech/tags/tech-matters.md>)

### AI overview

The article explains how random name attacks overwhelm authoritative DNS servers by generating queries for nonexistent names, bypassing recursive resolver caches and potentially causing domain availability failures. It also describes APNIC Labs' measurement work on nonexistent-domain responses to improve DNS resilience.

### Source excerpt

At APNIC Labs we've been experimenting with understanding how the DNS handles requests to resolve nonexistent names to make the DNS more resilient to random name attacks.

## Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave

DevFeed: [Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave](<https://devfeed.tech/articles/cloudflare-ddos-threat-report-h1-2026-1-tbps-attacks-soar-as-dns-floods-and-geopolitical-tensions-drive-a-new-wave-113.md>)

Original publisher: [Read original article](<https://blog.cloudflare.com/ddos-threat-report-2026-h1/>)

Author: Cloudforce One

Published: 2026-08-11T13:00:00Z

Content type: article

Language: en

Sources: [Cloudflare Blog](<https://devfeed.tech/sources/cloudflare-blog.md>)

Topics: [DDoS](<https://devfeed.tech/topics/ddos.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [Cloudforce One](<https://devfeed.tech/topics/cloudforce-one.md>), [Network](<https://devfeed.tech/topics/network.md>), [data](<https://devfeed.tech/topics/data.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [High Profile Threats](<https://devfeed.tech/topics/high-profile-threats.md>)

Tags: [analysis](<https://devfeed.tech/tags/analysis.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [cloudforce-one](<https://devfeed.tech/tags/cloudforce-one.md>), [data](<https://devfeed.tech/tags/data.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [dns](<https://devfeed.tech/tags/dns.md>), [drive](<https://devfeed.tech/tags/drive.md>), [global](<https://devfeed.tech/tags/global.md>), [government](<https://devfeed.tech/tags/government.md>), [industry](<https://devfeed.tech/tags/industry.md>), [iran](<https://devfeed.tech/tags/iran.md>), [media](<https://devfeed.tech/tags/media.md>), [network](<https://devfeed.tech/tags/network.md>), [radar](<https://devfeed.tech/tags/radar.md>), [streaming](<https://devfeed.tech/tags/streaming.md>), [threat-report](<https://devfeed.tech/tags/threat-report.md>)

### AI overview

Cloudflare's H1 2026 DDoS Threat Report analyzes attacks from January through June 2026. It highlights a 519% quarter-over-quarter increase in attacks exceeding 1 Tbps, a shift toward DNS and CLDAP reflection and amplification vectors, and the influence of geopolitical events on attack patterns. The report also covers attack volumes, an April peak, and the possible impact of Operation PowerOFF.

### Source excerpt

In the first half of 2026, Cloudflare detected a 519% surge in hyper-volumetric DDos attacks across its network. These attacks were driven heavily by DNS and CLDAP reflection vectors. This report breaks down how major geopolitical conflicts reshaped the global cyber threat landscape.

## Kimwolf v7: An Evolution of the Kimwolf Botnet

DevFeed: [Kimwolf v7: An Evolution of the Kimwolf Botnet](<https://devfeed.tech/articles/kimwolf-v7-an-evolution-of-the-kimwolf-botnet-7752.md>)

Original publisher: [Read original article](<https://unit42.paloaltonetworks.com/kimwolf-v7-botnet-malware/>)

Author: Asher Davila, Chris Navarrete and Doel Santos

Published: 2026-08-11T10:00:16Z

Content type: article

Language: en

Sources: [Unit 42](<https://devfeed.tech/sources/unit-42.md>)

Topics: [Kimwolf v7](<https://devfeed.tech/topics/kimwolf-v7.md>), [Android](<https://devfeed.tech/topics/android.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Internet of things](<https://devfeed.tech/topics/iot.md>), [C2](<https://devfeed.tech/topics/c2.md>), [Ethereum Name Service (ENS)](<https://devfeed.tech/topics/ens.md>), [Malware](<https://devfeed.tech/topics/malware.md>), [Cybercrime](<https://devfeed.tech/topics/cybercrime.md>), [Ethereum](<https://devfeed.tech/topics/ethereum.md>), [Blockchain](<https://devfeed.tech/topics/blockchain.md>), [Routing (disambiguation)](<https://devfeed.tech/topics/routing.md>), [Threat Hunting & Intel](<https://devfeed.tech/topics/threat-hunting-intel.md>)

Tags: [android](<https://devfeed.tech/tags/android.md>), [android-apk](<https://devfeed.tech/tags/android-apk.md>), [blockchain](<https://devfeed.tech/tags/blockchain.md>), [c2](<https://devfeed.tech/tags/c2.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [devices](<https://devfeed.tech/tags/devices.md>), [ethereum](<https://devfeed.tech/tags/ethereum.md>), [http](<https://devfeed.tech/tags/http.md>), [iot-botnets](<https://devfeed.tech/tags/iot-botnets.md>), [kimwolf-v7](<https://devfeed.tech/tags/kimwolf-v7.md>), [linux](<https://devfeed.tech/tags/linux.md>), [malware](<https://devfeed.tech/tags/malware.md>), [network](<https://devfeed.tech/tags/network.md>), [networks](<https://devfeed.tech/tags/networks.md>), [resilience](<https://devfeed.tech/tags/resilience.md>), [routing](<https://devfeed.tech/tags/routing.md>), [rpc](<https://devfeed.tech/tags/rpc.md>), [spoofing](<https://devfeed.tech/tags/spoofing.md>), [threat-research](<https://devfeed.tech/tags/threat-research.md>)

### AI overview

Kimwolf v7 is an Android and IoT botnet variant that adds HTTP/2-based DDoS flooding with browser fingerprinting, Ethereum Name Service resolution for C2 addresses, and Tor-backed routing to improve infrastructure resilience. The article also describes its targeting of Android TV devices and exploitation of unauthenticated ADB instances.

### Source excerpt

Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42.

## New setup page after domain checkout

DevFeed: [New setup page after domain checkout](<https://devfeed.tech/articles/new-setup-page-after-domain-checkout-1026.md>)

Original publisher: [Read original article](<https://vercel.com/changelog/new-setup-page-after-domain-checkout>)

Author: Can Temizyurek

Published: 2026-08-05T17:00:00Z

Content type: release

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [Vercel](<https://devfeed.tech/topics/vercel.md>), [Routing (disambiguation)](<https://devfeed.tech/topics/routing.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [Amazon Route 53](<https://devfeed.tech/topics/amazon-route-53.md>), [Git](<https://devfeed.tech/topics/git.md>), [Template](<https://devfeed.tech/topics/template.md>)

Tags: [cache](<https://devfeed.tech/tags/cache.md>), [cdn](<https://devfeed.tech/tags/cdn.md>), [checkout](<https://devfeed.tech/tags/checkout.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [dns](<https://devfeed.tech/tags/dns.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [git](<https://devfeed.tech/tags/git.md>), [google](<https://devfeed.tech/tags/google.md>), [routing](<https://devfeed.tech/tags/routing.md>), [vercel](<https://devfeed.tech/tags/vercel.md>)

### AI overview

Vercel has introduced a post-checkout setup page for domain purchases. It tracks registration status and provides guided actions for deploying or connecting projects, proxying or redirecting existing sites, and configuring email DNS records.

### Source excerpt

Buying a domain on Vercel now takes you to a setup page that tracks registration live, with direct paths to deploy a new project, connect an existing one, proxy or redirect a site you already run, or set up email. Registration can take a few minutes. Each setup action unlocks as soon as the domain is ready. If registration fails, the page shows what went wrong and the status of your refund. Deploy a new project or connect an existing one Deploy something opens project creation with the domain preselected. Connect a Git repository, prompt with v0, or start from a template, and the domain is attached when the project deploys. Connect an existing project attaches the domain to a project you pick from your team. Proxy or redirect a site you already run Enter an origin to proxy traffic to, and requests to the domain route through Vercel's CDN. Vercel will cache applicable requests at the edge, and Vercel Firewall's automated DDoS protections will automatically run. Enter a URL to redirect, and visitors are forwarded there. In both cases, Vercel creates a project to handle the routing and configures it for you. Set up email with DNS presets Choose your email provider and Vercel adds the DNS records it needs. Presets are available for Google Workspace, Outlook, iCloud, Proton Mail, Zoho, Mailgun, and ImprovMX. There's also a preset for using the domain as your Bluesky handle. If you'd rather configure records yourself, Manage DNS records opens the domain's DNS records page. Search for a domain at vercel.com/domains to get started. Read more

## What Is Web App and API Protection (WAAP)? | Harness

DevFeed: [What Is Web App and API Protection (WAAP)? | Harness](<https://devfeed.tech/articles/what-is-web-app-and-api-protection-waap-harness-13494.md>)

Original publisher: [Read original article](<https://www.harness.io/blog/what-is-web-app-and-api-protection-waap>)

Author: Michael Isbitski

Published: 2026-07-23T00:00:00Z

Content type: article

Language: en

Sources: [Harness Blog](<https://devfeed.tech/sources/harness-blog.md>)

Topics: [web applications](<https://devfeed.tech/topics/web-applications.md>), [API](<https://devfeed.tech/topics/api.md>), [Security](<https://devfeed.tech/topics/security.md>), [Cybersecurity](<https://devfeed.tech/topics/cybersecurity.md>), [Testing](<https://devfeed.tech/topics/testing.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Bot](<https://devfeed.tech/topics/bot.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [api-security](<https://devfeed.tech/tags/api-security.md>), [bots](<https://devfeed.tech/tags/bots.md>), [ci-cd](<https://devfeed.tech/tags/ci-cd.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [security](<https://devfeed.tech/tags/security.md>), [testing](<https://devfeed.tech/tags/testing.md>), [web-app](<https://devfeed.tech/tags/web-app.md>)

### AI overview

This Harness article explains Web Application and API Protection (WAAP) as a unified approach to securing web applications and APIs. It describes combining API discovery, testing, runtime protection, bot and abuse protection, and cloud-scale WAF capabilities, with integration into software delivery workflows.

### Source excerpt

Discover how Harness Web Application and API Protection (WAAP) unifies web app and API security, testing, and runtime protection. Protect your apps, start today | Blog

## Analysis of Telegram IPv6 BGP announcements by Indian ISPs

DevFeed: [Analysis of Telegram IPv6 BGP announcements by Indian ISPs](<https://devfeed.tech/articles/telegram-bgp-hijack-due-to-weird-blackholing-config-39779.md>)

Original publisher: [Read original article](<https://anuragbhatia.com/post/2026/06/telegram-bgp-hijack-and-blackholing/>)

Published: 2026-06-17T23:52:47Z

Content type: opinion

Language: en

Sources: [Personal blog of Anurag Bhatia](<https://devfeed.tech/sources/personal-blog-of-anurag-bhatia.md>)

Topics: [BGP](<https://devfeed.tech/topics/bgp.md>), [networking](<https://devfeed.tech/topics/networking.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>)

Tags: [as135709](<https://devfeed.tech/tags/as135709.md>), [as152144](<https://devfeed.tech/tags/as152144.md>), [as45820](<https://devfeed.tech/tags/as45820.md>), [bgp](<https://devfeed.tech/tags/bgp.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [lightstorm](<https://devfeed.tech/tags/lightstorm.md>), [rfc7999](<https://devfeed.tech/tags/rfc7999.md>), [rtbh](<https://devfeed.tech/tags/rtbh.md>), [telegram](<https://devfeed.tech/tags/telegram.md>), [ttsl](<https://devfeed.tech/tags/ttsl.md>)

### AI overview

The article examines unusual BGP announcements for Telegram IPv6 prefixes by several Indian ISPs after a reported Telegram prefix hijack. It proposes that existing BGP blackholing configurations may have been used to block Telegram traffic, while noting this is the author's interpretation.

### Source excerpt

Since the Telegram's prefix hijack (4 days ago on 17-Jun-2026) by RCom, there is visible noise in the BGP routing table from multiple other Indian ISPs, including Tata Teleservices (AS45820) / Lightstorm (AS135709/AS152144), etc. mostly in IPv6. Let's look at 2a0a:f280::/48 (Live lookup here) Notice all the ASNs here largely seem to be downstreams or peers of AS45820 in India, no major large peer or upstream that would take this announcement outside of India. Similarly, take the case of aggregate - 2a0a:f280::/32. This has TTSL (AS45820) as well as Lightstrom (AS152144/135709) originating these prefixes to smaller peers. Analysis: Possible reason and impact of this behaviour Today I tested some config in lab to see why this could be happening. Here's what I strongly feel is happening (quite sure, unless someone has a better explanation): Indian Govt. has asked ISPs to block Telegram and unlike past blocks mostly at the DNS layer, ISPs have been asked to drop IPs as well. Technically in these cases ISPs could simply add a blackhole route and that would drop traffic going towards these prefixes (from their customers) and that would not be visible at BGP (control plane) but only in traceroutes (data plane). If any of these customers had a full routing feed from those respective ISPs, they would keep on learning Telegram's route with the correct/expected AS_PATH and expected origin AS. Very likely these players had blackhole config setup for the DDoS protection and ended up using the same i.e they are treating Telegram's IPv6 prefixes like they would treat their own when under attack. Also, blackholing is a common practice during DDoS attacks. Imagine a network with a 100G uplink gets hit by a 400G volumetric attack. It will take up all the link bandwidth and thus in these cases ISPs blackhole their own (or downstream) IPs (often small - single /32s or a few) and they signal this to their BGP adjacencies as well. There is a standard BGP blackhole community: 65535:666 as

## 360 billion tokens, 3 million customers, 6 engineers

DevFeed: [360 billion tokens, 3 million customers, 6 engineers](<https://devfeed.tech/articles/360-billion-tokens-3-million-customers-6-engineers-717.md>)

Original publisher: [Read original article](<https://vercel.com/blog/360-billion-tokens-3-million-customers-6-engineers>)

Author: Eric Dodds

Published: 2026-03-18T04:00:00Z

Content type: article

Language: en

Sources: [Vercel News](<https://devfeed.tech/sources/vercel-news.md>)

Topics: [Artificial Intelligence](<https://devfeed.tech/topics/ai.md>), [Software as a service](<https://devfeed.tech/topics/saas.md>), [hosting](<https://devfeed.tech/topics/hosting.md>), [SSL](<https://devfeed.tech/topics/ssl.md>), [Security](<https://devfeed.tech/topics/security.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Architecture & Design](<https://devfeed.tech/topics/architecture-design.md>), [observability](<https://devfeed.tech/topics/observability.md>)

Tags: [ai](<https://devfeed.tech/tags/ai.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [hosting](<https://devfeed.tech/tags/hosting.md>), [observability](<https://devfeed.tech/tags/observability.md>), [saas](<https://devfeed.tech/tags/saas.md>), [security](<https://devfeed.tech/tags/security.md>), [self-hosting](<https://devfeed.tech/tags/self-hosting.md>), [ssl](<https://devfeed.tech/tags/ssl.md>), [vercel](<https://devfeed.tech/tags/vercel.md>)

### AI overview

This developer case study describes Durable, an AI business builder serving about 1.1 billion tokens per day and 3 million customers with a six-engineer team. It explains how Durable consolidated its multi-tenant, multi-product infrastructure on Vercel to ship production agents quickly and reduce infrastructure costs compared with self-hosting.

### Source excerpt

Impact at a glance Durable ships new production agents to customers in a single day AI features and agents serve ~1.1B tokens per day (360B per year) 10x leverage for every engineer, product manager, and designer 3-4x lower infra cost compared to self hosting Durable began with a simple goal: make owning a business easier than having a job. 60% of U.S. adults say they want to be their own boss, but only about 4% actually do it. Durable's bet is that the blocker isn't ambition. It's friction. "Small businesses are death by a thousand tools, logins, workflows, and designs," explained James Clift, founder of Durable. "If you remove those barriers, business owners can focus on their customers." Today, Durable is an AI business builder that helps entrepreneurs launch in minutes, then optimize with agents that handle things like SEO, content, and operations. The gap between idea and ownership has never been smaller. It feels like one seamless experience to their customers, but under the hood it's a multi-tenant, multi-product platform that has to run millions of individual businesses safely, reliably, and cost-effectively. As they scaled, manually operating multiple services just to self-host was enough work to be a second product. With a small team, Durable chose rapid consolidation over incremental improvement: one codebase, one infrastructure platform. Infra is hard; multi-tenant infra is harder Durable isn't serving one app. They are managing millions of customer sites, CRMs, and agents, each with different traffic patterns and different operational needs. One customer site might get 100x the traffic of another, and power laws show up quickly. When spikes happen, a small portion of Durable customers can consume a disproportionate share of compute, which made cost isolation, attribution, and pricing strategy significant engineering problems. Khan called out a few of the most acute pain-points from self-hosting: Custom domains and SSL at SaaS scale, including paying tho

## Cyber fallout from the Iran war: What to have on your radar

DevFeed: [Cyber fallout from the Iran war: What to have on your radar](<https://devfeed.tech/articles/cyber-fallout-from-the-iran-war-what-to-have-on-your-radar-8329.md>)

Original publisher: [Read original article](<https://www.welivesecurity.com/en/business-security/cyber-fallout-iran-war-what-have-radar/>)

Author: Tomáš Foltýn

Published: 2026-03-12T14:17:33Z

Content type: article

Language: en

Sources: [WeLiveSecurity](<https://devfeed.tech/sources/welivesecurity.md>)

Topics: [Security & Privacy](<https://devfeed.tech/topics/security-privacy.md>), [Threat Research](<https://devfeed.tech/topics/threat-research.md>), [cloud-infrastructure](<https://devfeed.tech/topics/cloud-infrastructure.md>), [Amazon Web Services (AWS)](<https://devfeed.tech/topics/amazon-web-services-aws.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Reconnaissance](<https://devfeed.tech/topics/recon.md>)

Tags: [amazon-web-services-aws](<https://devfeed.tech/tags/amazon-web-services-aws.md>), [business-security](<https://devfeed.tech/tags/business-security.md>), [canada](<https://devfeed.tech/tags/canada.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cybersecurity](<https://devfeed.tech/tags/cybersecurity.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [iran](<https://devfeed.tech/tags/iran.md>), [united-kingdom](<https://devfeed.tech/tags/united-kingdom.md>), [us](<https://devfeed.tech/tags/us.md>)

### AI overview

The article examines the cybersecurity fallout from the Iran war, including attacks on AWS data centers and the rapid mobilization of pro-Iranian cyber groups. It describes hacktivism, APT reconnaissance and initial access, espionage, disruption, sabotage, and the heightened risks to organizations with Middle East supply-chain or cloud dependencies.

### Source excerpt

The cybersecurity implications of the war in the Middle East extend far beyond the region. Here's where to focus your defenses.

## Technology Short Take 190

DevFeed: [Technology Short Take 190](<https://devfeed.tech/articles/technology-short-take-190-10921.md>)

Original publisher: [Read original article](<https://blog.scottlowe.org/2026/02/06/technology-short-take-190/>)

Author: Scott Lowe

Published: 2026-02-06T13:00:00Z

Content type: article

Language: en

Sources: [Scott's Weblog](<https://devfeed.tech/sources/scott-s-weblog.md>)

Topics: [networking](<https://devfeed.tech/topics/networking.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Azure](<https://devfeed.tech/topics/azure.md>), [Security](<https://devfeed.tech/topics/security.md>), [Windows](<https://devfeed.tech/topics/windows.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [Encryption](<https://devfeed.tech/topics/encryption.md>), [Git](<https://devfeed.tech/topics/git.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Terraform](<https://devfeed.tech/topics/terraform.md>), [Linux](<https://devfeed.tech/topics/linux.md>), [macOS](<https://devfeed.tech/topics/macos.md>)

Tags: [2026](<https://devfeed.tech/tags/2026.md>), [article](<https://devfeed.tech/tags/article.md>), [aws](<https://devfeed.tech/tags/aws.md>), [azure](<https://devfeed.tech/tags/azure.md>), [cilium](<https://devfeed.tech/tags/cilium.md>), [cli](<https://devfeed.tech/tags/cli.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cni](<https://devfeed.tech/tags/cni.md>), [containers](<https://devfeed.tech/tags/containers.md>), [cri-o](<https://devfeed.tech/tags/cri-o.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [devops](<https://devfeed.tech/tags/devops.md>), [docker](<https://devfeed.tech/tags/docker.md>), [git](<https://devfeed.tech/tags/git.md>), [go](<https://devfeed.tech/tags/go.md>), [iac](<https://devfeed.tech/tags/iac.md>), [k8s](<https://devfeed.tech/tags/k8s.md>), [kubernetes](<https://devfeed.tech/tags/kubernetes.md>), [linux](<https://devfeed.tech/tags/linux.md>), [macos](<https://devfeed.tech/tags/macos.md>), [markdown](<https://devfeed.tech/tags/markdown.md>), [networking](<https://devfeed.tech/tags/networking.md>), [oci](<https://devfeed.tech/tags/oci.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [technology](<https://devfeed.tech/tags/technology.md>), [terraform](<https://devfeed.tech/tags/terraform.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

Technology Short Take 190 is a curated roundup of technical reading on networking, solar-storm effects on satellites, hardware, DDoS attacks against Microsoft Azure, Windows encryption, cloud management, Git tools, Terraform and OpenTofu, hosted email, Linux, macOS, and Markdown.

### Source excerpt

Welcome to Technology Short Take #190! This is the first Tech Short Take of 2026, and it has been nearly three months (wow!) since the last one. I can't argue that I fell off the blogging bandwagon over the end of 2025 and early 2026. I won't get into all the reasons why (if you're interested then feel free to reach out and I'll fill you in). Enough about me--let's get to the technical content! Here's hoping you find something useful. Networking Here's a little something on the lighter side about what causes network outages. As the lead-in to this article on Starlink's performance during a solar superstorm says, "It's not science fiction." Solar storms can have a real impact on Earth, and satellites in low-Earth orbit (LEO) are not exempt from that impact. Servers/Hardware William Lam reviews the Mini PC and SFF (small form factor) hardware announcements from CES 2026. Security The scale of DDoS attacks continues to grow, as evidenced by this report of a 15 Tbps attack on Microsoft Azure. Microsoft having the ability to give away your Windows PC's data encryption key is horrifying. Cloud Computing/Cloud Management While doing some reading on Terragrunt, I also came across this open source tool for performing operations against multiple Git repositories. I don't have a use case for it, but it is cool! While on the topic of Terragrunt: let me say that I appreciate the work that went into their online docs! From what I've read so far, they are well-written, clear, concise, and informative. Well done! And while still on the topic of Terragrunt: it was this article from Axel Mendoza on why they use Terragrunt over Terraform/OpenTofu that sent me down the Terragrunt rabbit hole. The most recent installation of Ricardo Sueiras' AWS open source newsletter pointed me to a couple of tools that look really handy: s3sh (available from GitHub) and taws (also available from GitHub). Nick Buraglio has a great comparison of hosted email options. Operating Systems/Applications Howard

## Mitigating Denial-of-Service Vulnerability from Unrecoverable Stack Space Exhaustion for React, Next.js, and APM Users

DevFeed: [Mitigating Denial-of-Service Vulnerability from Unrecoverable Stack Space Exhaustion for React, Next.js, and APM Users](<https://devfeed.tech/articles/mitigating-denial-of-service-vulnerability-from-unrecoverable-stack-space-exhaustion-for-react-next-js-and-apm-users-2883.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/vulnerability/january-2026-dos-mitigation-async-hooks>)

Published: 2026-01-13T17:00:00Z

Content type: article

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Next.js](<https://devfeed.tech/topics/next-js.md>), [React](<https://devfeed.tech/topics/react.md>), [Application Performance Management (APM)](<https://devfeed.tech/topics/apm.md>), [Availability](<https://devfeed.tech/topics/availability.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>)

Tags: [apm](<https://devfeed.tech/tags/apm.md>), [availability](<https://devfeed.tech/tags/availability.md>), [javascript](<https://devfeed.tech/tags/javascript.md>), [next-js](<https://devfeed.tech/tags/next-js.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [react](<https://devfeed.tech/tags/react.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Node.js describes a denial-of-service vulnerability in which stack space exhaustion can cause an immediate, uncatchable process exit when async hooks are enabled. The issue affects applications using React Server Components, Next.js request-context tracking, and APM instrumentation. A January 2026 Node.js security release adds a mitigation, while applications and frameworks should adopt stronger defenses such as limiting attacker-controlled recursion.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## Oracle zero-day vulnerability for sale

DevFeed: [Oracle zero-day vulnerability for sale](<https://devfeed.tech/articles/oracle-zero-day-vulnerability-for-sale-20573.md>)

Original publisher: [Read original article](<https://yurichev.com/blog/oracle/>)

Published: 2025-09-17T22:00:00Z

Content type: opinion

Language: en

Sources: [Dennis Yurichev](<https://devfeed.tech/sources/dennis-yurichev.md>)

Topics: [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Exploit](<https://devfeed.tech/topics/exploit.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>)

Tags: [exploit](<https://devfeed.tech/tags/exploit.md>), [rdbms](<https://devfeed.tech/tags/rdbms.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

The author describes a zero-day vulnerability in Oracle RDBMS that can make a remote database hang or freeze, characterizing it as a denial-of-service issue without access to remote data. The author says they are considering selling a proof of concept or exploit.

### Source excerpt

Oracle zero-day vulnerability for sale

## Wednesday, May 14, 2025 Security Releases

DevFeed: [Wednesday, May 14, 2025 Security Releases](<https://devfeed.tech/articles/wednesday-may-14-2025-security-releases-2897.md>)

Original publisher: [Read original article](<https://nodejs.org/en/blog/vulnerability/may-2025-security-releases>)

Published: 2025-05-14T03:00:00Z

Content type: release

Language: en

Sources: [Node.js Blog](<https://devfeed.tech/sources/node-js-blog.md>)

Topics: [Node.js](<https://devfeed.tech/topics/node-js.md>), [releases](<https://devfeed.tech/topics/releases.md>), [Security](<https://devfeed.tech/topics/security.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [Memory Leaks](<https://devfeed.tech/topics/memory-leaks.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Parser](<https://devfeed.tech/topics/parser.md>), [Windows](<https://devfeed.tech/topics/windows.md>)

Tags: [2025](<https://devfeed.tech/tags/2025.md>), [http](<https://devfeed.tech/tags/http.md>), [memory](<https://devfeed.tech/tags/memory.md>), [node](<https://devfeed.tech/tags/node.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source](<https://devfeed.tech/tags/open-source.md>), [release](<https://devfeed.tech/tags/release.md>), [releases](<https://devfeed.tech/tags/releases.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [windows](<https://devfeed.tech/tags/windows.md>)

### AI overview

The Node.js Project announced security releases for the 24.x, 23.x, 22.x, and 20.x release lines on May 14, 2025. The updates address vulnerabilities involving cryptographic operations in background threads, HTTP request smuggling in Node.js 20, and an unrecoverable memory leak affecting specific Windows configurations.

### Source excerpt

Node.js® is a free, open-source, cross-platform JavaScript runtime environment that lets developers create servers, web apps, command line tools and scripts.

## Laravel Cloud is live! Can you ship in 1 minute?

DevFeed: [Laravel Cloud is live! Can you ship in 1 minute?](<https://devfeed.tech/articles/laravel-cloud-is-live-can-you-ship-in-1-minute-3760.md>)

Original publisher: [Read original article](<https://laravel.com/blog/laravel-cloud-is-live-can-you-ship-in-1-minute>)

Author: Sam

Published: 2025-02-21T21:26:00Z

Content type: article

Language: en

Sources: [Laravel Blog](<https://devfeed.tech/sources/laravel-blog.md>)

Topics: [Cloud](<https://devfeed.tech/topics/cloud.md>), [Laravel](<https://devfeed.tech/topics/laravel.md>), [Livewire](<https://devfeed.tech/topics/livewire.md>), [autoscaling](<https://devfeed.tech/topics/autoscaling.md>), [React](<https://devfeed.tech/topics/react.md>), [VS Code Extension](<https://devfeed.tech/topics/vscode-extension.md>), [Vue.js](<https://devfeed.tech/topics/vue.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [Databases](<https://devfeed.tech/topics/databases.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Authentication](<https://devfeed.tech/topics/authentication.md>), [SSL](<https://devfeed.tech/topics/ssl.md>)

Tags: [authentication](<https://devfeed.tech/tags/authentication.md>), [autoscaling](<https://devfeed.tech/tags/autoscaling.md>), [caching](<https://devfeed.tech/tags/caching.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [databases](<https://devfeed.tech/tags/databases.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [extension](<https://devfeed.tech/tags/extension.md>), [laravel](<https://devfeed.tech/tags/laravel.md>), [react](<https://devfeed.tech/tags/react.md>), [ssl](<https://devfeed.tech/tags/ssl.md>), [sso](<https://devfeed.tech/tags/sso.md>), [tailwind](<https://devfeed.tech/tags/tailwind.md>), [vs-code](<https://devfeed.tech/tags/vs-code.md>), [vue](<https://devfeed.tech/tags/vue.md>)

### AI overview

Laravel announces Laravel Cloud, new Starter Kits for React, Vue, and Livewire, a stable VS Code Extension, and Laravel 12. Laravel Cloud supports rapid deployment with autoscaling, hibernation, managed databases, caching, storage, DDoS protection, SSL, CDN, and edge caching.

### Source excerpt

Today we shipped Laravel Cloud, Starter Kits (React, Vue, & Livewire), VS Code Extension, and Laravel 12.

## Securing APIs: Express rate limit and slow down

DevFeed: [Securing APIs: Express rate limit and slow down](<https://devfeed.tech/articles/securing-apis-express-rate-limit-and-slow-down-4115.md>)

Original publisher: [Read original article](<https://developer.mozilla.org/en-US/blog/securing-apis-express-rate-limit-and-slow-down/>)

Author: vultr

Published: 2024-05-28T00:00:00Z

Content type: tutorial

Language: en

Sources: [MDN Blog](<https://devfeed.tech/sources/mdn-blog.md>)

Topics: [Express](<https://devfeed.tech/topics/express.md>), [Security](<https://devfeed.tech/topics/security.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Firewall](<https://devfeed.tech/topics/firewall.md>), [Bash](<https://devfeed.tech/topics/bash.md>), [ssh](<https://devfeed.tech/topics/ssh.md>), [HTML](<https://devfeed.tech/topics/html.md>), [JavaScript](<https://devfeed.tech/topics/javascript.md>)

Tags: [bash](<https://devfeed.tech/tags/bash.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [firewall](<https://devfeed.tech/tags/firewall.md>), [guide](<https://devfeed.tech/tags/guide.md>), [how-to](<https://devfeed.tech/tags/how-to.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [security](<https://devfeed.tech/tags/security.md>), [ssh](<https://devfeed.tech/tags/ssh.md>), [web-applications](<https://devfeed.tech/tags/web-applications.md>)

### AI overview

This tutorial explains how to secure Express applications by implementing rate limiting and slow-down mechanisms. It covers deploying an application on a server, configuring firewall access, and using these controls to improve resilience, scalability, security, and service reliability.

### Source excerpt

This guide introduces you to rate limits and slow down mechanisms. Learn how to apply slow down and rate limit mechanisms in Express applications.

## Exploiting HTTP/2 CONTINUATION frames for DoS attacks

DevFeed: [Exploiting HTTP/2 CONTINUATION frames for DoS attacks](<https://devfeed.tech/articles/exploiting-http-2-continuation-frames-for-dos-attacks-7912.md>)

Original publisher: [Read original article](<https://snyk.io/blog/exploiting-http-2-continuation-frames-dos-attacks/>)

Author: Vandana Verma Sehgal

Published: 2024-04-08T05:00:00Z

Content type: article

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [HTTP](<https://devfeed.tech/topics/http.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [servers](<https://devfeed.tech/topics/servers.md>), [web applications](<https://devfeed.tech/topics/web-applications.md>), [Go Language](<https://devfeed.tech/topics/go-language.md>), [Node.js](<https://devfeed.tech/topics/node-js.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [awareness](<https://devfeed.tech/tags/awareness.md>), [blog](<https://devfeed.tech/tags/blog.md>), [code-security](<https://devfeed.tech/tags/code-security.md>), [developer](<https://devfeed.tech/tags/developer.md>), [devops](<https://devfeed.tech/tags/devops.md>), [devrel](<https://devfeed.tech/tags/devrel.md>), [enablement](<https://devfeed.tech/tags/enablement.md>), [engineering](<https://devfeed.tech/tags/engineering.md>), [go](<https://devfeed.tech/tags/go.md>), [http](<https://devfeed.tech/tags/http.md>), [http-server](<https://devfeed.tech/tags/http-server.md>), [internet-traffic](<https://devfeed.tech/tags/internet-traffic.md>), [js](<https://devfeed.tech/tags/js.md>), [monitor](<https://devfeed.tech/tags/monitor.md>), [node-js](<https://devfeed.tech/tags/node-js.md>), [open-source-security](<https://devfeed.tech/tags/open-source-security.md>), [performance](<https://devfeed.tech/tags/performance.md>), [security](<https://devfeed.tech/tags/security.md>), [server](<https://devfeed.tech/tags/server.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [snyk-platform](<https://devfeed.tech/tags/snyk-platform.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

This article explains a vulnerability in HTTP/2 implementations that lets attackers flood a single stream with excessive CONTINUATION frames, potentially overwhelming or crashing web servers. It describes the affected ecosystem, including Node.js and Go, and recommends patching, rate limiting, traffic monitoring, and temporarily disabling HTTP/2 when no patch is available.

### Source excerpt

This post covers all the info you need on the new HTTP/2 CONTINUATION frames vulnerability, including the affected versions, its impact, mitigation steps, and how to protect your applications.

## Chainguard patches 3 "silent" Golang CVEs in under 24 hours

DevFeed: [Chainguard patches 3 "silent" Golang CVEs in under 24 hours](<https://devfeed.tech/articles/chainguard-patches-3-silent-golang-cves-in-under-24-hours-12975.md>)

Original publisher: [Read original article](<https://www.chainguard.dev/unchained/chainguard-patches-3-silent-golang-cves-in-under-24-hours>)

Published: 2024-03-21T00:00:00Z

Content type: article

Language: en

Sources: [Chainguard: Unchained](<https://devfeed.tech/sources/chainguard-unchained.md>)

Topics: [chainguard](<https://devfeed.tech/topics/chainguard.md>), [Vulnerabilities](<https://devfeed.tech/topics/vulnerabilities.md>), [Go](<https://devfeed.tech/topics/go.md>), [chainguard images](<https://devfeed.tech/topics/chainguard-images.md>), [Security](<https://devfeed.tech/topics/security.md>), [Automation](<https://devfeed.tech/topics/automation.md>), [toolchain](<https://devfeed.tech/topics/toolchain.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Monitoring](<https://devfeed.tech/topics/monitoring.md>), [Open Source](<https://devfeed.tech/topics/open-source.md>), [Pull Request](<https://devfeed.tech/topics/pull-request.md>), [Linux](<https://devfeed.tech/topics/linux.md>)

Tags: [automation](<https://devfeed.tech/tags/automation.md>), [chainguard](<https://devfeed.tech/tags/chainguard.md>), [chainguard-images](<https://devfeed.tech/tags/chainguard-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [cves](<https://devfeed.tech/tags/cves.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [github](<https://devfeed.tech/tags/github.md>), [go](<https://devfeed.tech/tags/go.md>), [golang](<https://devfeed.tech/tags/golang.md>), [golang-patch](<https://devfeed.tech/tags/golang-patch.md>), [linux](<https://devfeed.tech/tags/linux.md>), [melange](<https://devfeed.tech/tags/melange.md>), [merge](<https://devfeed.tech/tags/merge.md>), [monitoring](<https://devfeed.tech/tags/monitoring.md>), [safe-source-for-open-source](<https://devfeed.tech/tags/safe-source-for-open-source.md>), [security](<https://devfeed.tech/tags/security.md>), [silent-cve](<https://devfeed.tech/tags/silent-cve.md>), [tooling](<https://devfeed.tech/tags/tooling.md>), [wolfi](<https://devfeed.tech/tags/wolfi.md>)

### AI overview

Chainguard describes how it patched three Golang CVEs in under 24 hours. Its automation monitored new Go releases, opened a pull request, rebuilt the Wolfi package, and updated Chainguard Images containing Go.

### Source excerpt

See how Chainguard swiftly patched three Golang CVEs in under 24 hours, showcasing rapid response and dedication to secure software.

## How IX.BR Automates Quarantine LAN Testing

DevFeed: [How IX.BR Automates Quarantine LAN Testing](<https://devfeed.tech/articles/appreciation-of-automated-ix-quarantine-lan-testing-41612.md>)

Original publisher: [Read original article](<https://blog.benjojo.co.uk/post/ixbr-automated-quarantine>)

Author: ben@benjojo.co.uk

Published: 2024-02-01T11:27:29Z

Content type: article

Language: en

Sources: [benjojo blog](<https://devfeed.tech/sources/benjojo-blog.md>)

Topics: [Network](<https://devfeed.tech/topics/network.md>), [Ethernet](<https://devfeed.tech/topics/ethernet.md>), [Internet Traffic](<https://devfeed.tech/topics/internet-traffic.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [proxy](<https://devfeed.tech/topics/proxy.md>), [Testing](<https://devfeed.tech/topics/testing.md>)

Tags: [arp](<https://devfeed.tech/tags/arp.md>), [bgp](<https://devfeed.tech/tags/bgp.md>), [ethernet](<https://devfeed.tech/tags/ethernet.md>), [internet](<https://devfeed.tech/tags/internet.md>), [internet-traffic](<https://devfeed.tech/tags/internet-traffic.md>), [lan](<https://devfeed.tech/tags/lan.md>), [proxy](<https://devfeed.tech/tags/proxy.md>), [tests](<https://devfeed.tech/tags/tests.md>)

### AI overview

The article describes IX.BR São Paulo's automated quarantine LAN testing portal for internet exchange participants. It explains why quarantine testing matters, including the risks of Ethernet loops, management frames, and Proxy ARP on a shared Layer 2 exchange LAN.

### Source excerpt

Appreciation of automated IX Quarantine LAN testing Something that bgp.tools (my company) does a great deal is joining internet exchanges.

## Where Fediverse Instances Are Hosted

DevFeed: [Where Fediverse Instances Are Hosted](<https://devfeed.tech/articles/where-is-all-of-the-fediverse-41649.md>)

Original publisher: [Read original article](<https://blog.benjojo.co.uk/post/who-hosts-the-fediverse-instances>)

Author: ben@benjojo.co.uk

Published: 2024-01-12T12:34:50Z

Content type: article

Language: en

Sources: [benjojo blog](<https://devfeed.tech/sources/benjojo-blog.md>)

Topics: [Fediverse](<https://devfeed.tech/topics/fediverse.md>), [ActivityPub](<https://devfeed.tech/topics/activitypub.md>), [Mastodon](<https://devfeed.tech/topics/mastodon.md>), [BGP](<https://devfeed.tech/topics/bgp.md>), [hosting](<https://devfeed.tech/topics/hosting.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [proxy](<https://devfeed.tech/topics/proxy.md>), [Server](<https://devfeed.tech/topics/server.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [Digital Ocean](<https://devfeed.tech/topics/digital-ocean.md>), [HTTP](<https://devfeed.tech/topics/http.md>)

Tags: [bgp](<https://devfeed.tech/tags/bgp.md>), [cdn](<https://devfeed.tech/tags/cdn.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [digitalocean](<https://devfeed.tech/tags/digitalocean.md>), [fediverse](<https://devfeed.tech/tags/fediverse.md>), [http](<https://devfeed.tech/tags/http.md>), [mastodon](<https://devfeed.tech/tags/mastodon.md>), [network](<https://devfeed.tech/tags/network.md>), [social-media](<https://devfeed.tech/tags/social-media.md>)

### AI overview

An investigation examines where Fediverse instances are hosted by discovering Mastodon peers, resolving their DNS records, mapping them to autonomous systems, and comparing hosting providers. It finds that proxy CDN providers can obscure the underlying hosts, so the analysis explores using ActivityPub requests to identify actual hosting infrastructure.

### Source excerpt

Where is all of the fediverse? Spurred on by the problems at Twitter, a lot of my social media timeline has "moved out" of Twitter/"X" on to what people mostly describe as mastodon or

## Find and fix HTTP/2 rapid reset zero-day vulnerability CVE-2023-44487

DevFeed: [Find and fix HTTP/2 rapid reset zero-day vulnerability CVE-2023-44487](<https://devfeed.tech/articles/find-and-fix-http-2-rapid-reset-zero-day-vulnerability-cve-2023-44487-7922.md>)

Original publisher: [Read original article](<https://snyk.io/blog/find-fix-http-2-rapid-reset-zero-day-vulnerability-cve-2023-44487/>)

Author: Jamie Smith; Kriti Dogra; Anthony Larkin

Published: 2023-10-11T23:00:00Z

Content type: tutorial

Language: en

Sources: [Blog RSS Feed | Snyk](<https://devfeed.tech/sources/blog-rss-feed-snyk.md>)

Topics: [HTTP](<https://devfeed.tech/topics/http.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Cloudflare](<https://devfeed.tech/topics/cloudflare.md>), [nginx](<https://devfeed.tech/topics/nginx.md>)

Tags: [acquisition](<https://devfeed.tech/tags/acquisition.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [aws](<https://devfeed.tech/tags/aws.md>), [azure](<https://devfeed.tech/tags/azure.md>), [blog](<https://devfeed.tech/tags/blog.md>), [cloudflare](<https://devfeed.tech/tags/cloudflare.md>), [configuration](<https://devfeed.tech/tags/configuration.md>), [container-images](<https://devfeed.tech/tags/container-images.md>), [cve](<https://devfeed.tech/tags/cve.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [developer](<https://devfeed.tech/tags/developer.md>), [http](<https://devfeed.tech/tags/http.md>), [nginx](<https://devfeed.tech/tags/nginx.md>), [pmm](<https://devfeed.tech/tags/pmm.md>), [security](<https://devfeed.tech/tags/security.md>), [snyk-container](<https://devfeed.tech/tags/snyk-container.md>), [snyk-open-source](<https://devfeed.tech/tags/snyk-open-source.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>), [vulnerability-insights](<https://devfeed.tech/tags/vulnerability-insights.md>)

### AI overview

This article explains the HTTP/2 Rapid Reset vulnerability, tracked as CVE-2023-44487, which can enable large volumetric DDoS attacks against web servers implementing HTTP/2. It recommends mitigating exposure through infrastructure providers and CDNs, then upgrading affected packages and checking container images and open source ecosystems for remediated versions.

### Source excerpt

Learn how to find and fix the HTTP/2 rapid reset vulnerability (CVE-2023-44487) that has been designated a High severity vulnerability with a CVSS score of 7.5 (out of 10).

## Apollo Changelog: May 5, 2023

DevFeed: [Apollo Changelog: May 5, 2023](<https://devfeed.tech/articles/apollo-changelog-may-5-2023-23171.md>)

Original publisher: [Read original article](<https://www.apollographql.com/blog/apollo-changelog-may-5-2023>)

Author: Dylan Anthony

Published: 2023-05-05T17:34:27Z

Content type: release

Language: en

Sources: [Apollo Blog](<https://devfeed.tech/sources/apollo-blog.md>)

Topics: [changelog](<https://devfeed.tech/topics/changelog.md>), [GraphQL](<https://devfeed.tech/topics/graphql.md>), [releases](<https://devfeed.tech/topics/releases.md>), [gateway](<https://devfeed.tech/topics/gateway.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [apollo-client](<https://devfeed.tech/topics/apollo-client.md>), [apollo-server](<https://devfeed.tech/topics/apollo-server.md>), [iOS](<https://devfeed.tech/topics/ios.md>), [Kotlin](<https://devfeed.tech/topics/kotlin.md>)

Tags: [apollo](<https://devfeed.tech/tags/apollo.md>), [apollo-client](<https://devfeed.tech/tags/apollo-client.md>), [attacks](<https://devfeed.tech/tags/attacks.md>), [bug](<https://devfeed.tech/tags/bug.md>), [bug-fixes](<https://devfeed.tech/tags/bug-fixes.md>), [changelog](<https://devfeed.tech/tags/changelog.md>), [community](<https://devfeed.tech/tags/community.md>), [gateway](<https://devfeed.tech/tags/gateway.md>), [graphql](<https://devfeed.tech/tags/graphql.md>), [improvements](<https://devfeed.tech/tags/improvements.md>), [ios](<https://devfeed.tech/tags/ios.md>), [kotlin](<https://devfeed.tech/tags/kotlin.md>), [preview](<https://devfeed.tech/tags/preview.md>), [releases](<https://devfeed.tech/tags/releases.md>)

### AI overview

Apollo's May 5, 2023 changelog covers three Apollo Router releases, including a preview operation-limits feature for Enterprise users. It also discusses Reddit's move from a gateway to federation, Apollo office hours, product updates, and a community spotlight.

### Source excerpt

Rapid router releases Since the last changelog, three new versions of Apollo Router have been released! We can't cover all the changes here, so check out the release notes for more details. One exciting addition is a new preview feature for Enterprise users: operation limits. You can now configure your router to reject queries exceeding certain complexity metrics.

## How Linear made the most of a DDoS

DevFeed: [How Linear made the most of a DDoS](<https://devfeed.tech/articles/how-linear-made-the-most-of-a-ddos-9770.md>)

Original publisher: [Read original article](<https://www.figma.com/blog/how-linear-made-the-most-of-a-ddos/>)

Author: Carly Ayres

Published: 2022-12-15T00:00:00Z

Content type: article

Language: en

Sources: [Figma Blog](<https://devfeed.tech/sources/figma-blog.md>)

Topics: [DDoS](<https://devfeed.tech/topics/ddos.md>), [Figma](<https://devfeed.tech/topics/figma.md>), [incident](<https://devfeed.tech/topics/incident.md>), [Internet Traffic](<https://devfeed.tech/topics/internet-traffic.md>), [Software](<https://devfeed.tech/topics/software.md>), [App](<https://devfeed.tech/topics/app.md>)

Tags: [app](<https://devfeed.tech/tags/app.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [design](<https://devfeed.tech/tags/design.md>), [figma](<https://devfeed.tech/tags/figma.md>), [incident](<https://devfeed.tech/tags/incident.md>), [internet-traffic](<https://devfeed.tech/tags/internet-traffic.md>), [reports](<https://devfeed.tech/tags/reports.md>), [software](<https://devfeed.tech/tags/software.md>)

### AI overview

The article describes how Linear responded to a DDoS attack that took down its homepage on October 13, 2022. The team restored access to the app through the login page and then used Figma designs to create a replacement homepage, turning the incident into an opportunity to showcase the redesign and reflect on the process.

### Source excerpt

On a good day, the Linear team helps companies build better software by streamlining issue tracking and project management. When they're not doing that, they're trying to get back to doing that as quickly as possible.

## Stuff The Internet Says On Scalability For December 2nd, 2022

DevFeed: [Stuff The Internet Says On Scalability For December 2nd, 2022](<https://devfeed.tech/articles/stuff-the-internet-says-on-scalability-for-december-2nd-2022-33608.md>)

Original publisher: [Read original article](<https://highscalability.com/stuff-the-internet-says-on-scalability-for-december-2nd-2022/>)

Author: High Scalability

Published: 2022-12-02T17:08:30Z

Content type: article

Language: en

Sources: [High Scalability](<https://devfeed.tech/sources/high-scalability-3.md>)

Topics: [Scalability](<https://devfeed.tech/topics/scalability.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [API](<https://devfeed.tech/topics/api.md>), [AWS Lambda](<https://devfeed.tech/topics/aws-lambda.md>), [Caching](<https://devfeed.tech/topics/caching.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Memory Safety](<https://devfeed.tech/topics/memory-safety.md>), [ibm](<https://devfeed.tech/topics/ibm.md>)

Tags: [api](<https://devfeed.tech/tags/api.md>), [aws-lambda](<https://devfeed.tech/tags/aws-lambda.md>), [caching](<https://devfeed.tech/tags/caching.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [ddos](<https://devfeed.tech/tags/ddos.md>), [hot-links](<https://devfeed.tech/tags/hot-links.md>), [memory-safety](<https://devfeed.tech/tags/memory-safety.md>), [scalability](<https://devfeed.tech/tags/scalability.md>)

### AI overview

A December 2, 2022 HighScalability roundup collects statistics and observations about internet-scale systems, including GraphQL traffic, AWS Lambda usage, cloud migrations, caching, edge latency, DDoS mitigation, and memory safety.

### Source excerpt

Never fear, HighScalability is here! 1958: An engineer wiring an early IBM computer 2021: An engineer wiring an early IBM quantum computer. @enclanglement My Stuff: I'm proud to announce a completely updated and expanded version of Explain the Cloud Like I'm 10! This version adds 2x

## Our approach to security at speed

DevFeed: [Our approach to security at speed](<https://devfeed.tech/articles/our-approach-to-security-at-speed-9992.md>)

Original publisher: [Read original article](<https://www.figma.com/blog/our-approach-to-security-at-speed/>)

Author: Greg Guthe

Published: 2022-10-13T00:00:00Z

Content type: article

Language: en

Sources: [Figma Blog](<https://devfeed.tech/sources/figma-blog.md>)

Topics: [Security](<https://devfeed.tech/topics/security.md>), [Cloud](<https://devfeed.tech/topics/cloud.md>), [vulnerability](<https://devfeed.tech/topics/vulnerability.md>), [DDoS](<https://devfeed.tech/topics/ddos.md>), [Server](<https://devfeed.tech/topics/server.md>)

Tags: [attacks](<https://devfeed.tech/tags/attacks.md>), [cloud](<https://devfeed.tech/tags/cloud.md>), [cloud-native](<https://devfeed.tech/tags/cloud-native.md>), [development](<https://devfeed.tech/tags/development.md>), [figma](<https://devfeed.tech/tags/figma.md>), [security](<https://devfeed.tech/tags/security.md>), [vulnerability](<https://devfeed.tech/tags/vulnerability.md>)

### AI overview

Figma describes a security operating model designed to help teams ship products quickly while managing risks through transparency, reusable solutions, office hours, and early review of product workflows. The article uses rich preview links as an example, covering SSRF, denial-of-service, malicious HTML, and isolating link-scraping code in a cloud function.

### Source excerpt

Learn about how the Figma security team helps us ship products securely, without impacting the pace of development.

[Next page](<https://devfeed.tech/topics/ddos.md?cursor=WyIyMDIyLTEwLTEzVDAwOjAwOjAwKzAwOjAwIiwgImFlYjU2N2I2LTA0MWMtNDhlMS1hNThlLWJjNzg1NGNhZjgzYiJd>)