Visualização normal

Antes de ontemCyber Security News
  • ✇Cyber Security News
  • Threema Secure Messaging Service Hit by Massive DDoS Attack Abinaya
    Threema, a privacy-focused secure messaging service, was hit by a series of large-scale distributed denial-of-service (DDoS attacks) that temporarily disrupted access for users. The incidents affected the platform on Tuesday evening and continued intermittently through Wednesday morning before normal operations were restored. According to Threema, the service was unavailable between 7:30 p.m. and 11:30 p.m. CEST on Tuesday. Users also experienced short, intermittent disruptions on Wednesda
     

Threema Secure Messaging Service Hit by Massive DDoS Attack

17 de Agosto de 2026, 08:49

Threema, a privacy-focused secure messaging service, was hit by a series of large-scale distributed denial-of-service (DDoS attacks) that temporarily disrupted access for users.

The incidents affected the platform on Tuesday evening and continued intermittently through Wednesday morning before normal operations were restored. According to Threema, the service was unavailable between 7:30 p.m. and 11:30 p.m. CEST on Tuesday.

Users also experienced short, intermittent disruptions on Wednesday morning as the attacks continued and shifted in pattern. Threema confirmed that all services had returned to normal operation by 12:23 p.m. CEST.

A distributed denial-of-service attack, commonly known as a DDoS attack, attempts to make an online service unavailable by overwhelming its infrastructure with a very high volume of traffic.

Unlike a conventional attack launched from a single system, DDoS operations use many sources, often including compromised devices spread across different networks and locations. This distributed approach makes mitigation more difficult.

Security teams cannot simply block a single malicious IP address because attackers can rapidly change traffic sources, request types, and attack patterns. The result is often a continuous contest between defenders adapting their filtering controls and attackers modifying their methods.

Threema Hit by Massive DDoS Attack

Threema said the attacks targeted both its infrastructure and its colocation partner, Nine. It remains unclear whether Threema was the sole intended target or whether the activity was part of a broader campaign against multiple organizations.

The company described the incident as an ongoing wave of attacks with constantly changing patterns, making it more challenging to block without affecting legitimate users.

Importantly, Threema stressed that the attacks affected service availability rather than the confidentiality or security of user data. A DDoS attack does not inherently provide attackers with access to servers, messages, account data, or internal systems.

Its purpose is to consume network bandwidth, processing capacity, or other infrastructure resources until valid user requests can no longer be handled reliably.

The incident also affected Threema’s public status page. The company said the page was initially not updated because of a separate technical issue unrelated to the DDoS activity.

The status page was temporarily taken offline until that issue was resolved, limiting the availability of official outage information during part of the incident.

Threema communicated updates through its social media channels and notified Threema Work business customers by email on Wednesday morning. Account managers also responded to customer inquiries as the service instability continued.

Organizations using Threema OnPrem were not affected. The OnPrem product operates on customer-managed infrastructure, meaning those deployments remained available while Threema’s hosted service was under attack.

In response to the incident, Threema implemented an additional specialized DDoS protection mechanism. The new control filters malicious traffic upstream before it reaches Threema’s core infrastructure, reducing the burden on internal systems and existing defensive layers.

The company confirmed on August 14, 2026, at 6:05 p.m. CEST that the upstream filtering protection had been activated in its production environment.

Threema also plans to expand its status page with incident history and an RSS feed. This would provide users and Threema Work administrators with an independent channel to receive system status alerts during future outages.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post Threema Secure Messaging Service Hit by Massive DDoS Attack appeared first on Cyber Security News.

  • ✇Cyber Security News
  • 1 Tbps DDoS Attacks Become the New Normal as Cloudflare Reports Record H1 Activity Abinaya
    Cloudflare has reported a sharp rise in large-scale distributed denial-of-service attacks during the first half of 2026, blocking 935 network-layer attacks exceeding 1 terabit per second. The company said hyper-volumetric attacks grew 519% between the first and second quarters, showing that attackers are increasingly capable of delivering extreme traffic floods at a rapid pace. The findings appear in Cloudflare’s 25th DDoS Threat Report, which combines data from January through June 2026.
     

1 Tbps DDoS Attacks Become the New Normal as Cloudflare Reports Record H1 Activity

13 de Agosto de 2026, 08:55

Cloudflare has reported a sharp rise in large-scale distributed denial-of-service attacks during the first half of 2026, blocking 935 network-layer attacks exceeding 1 terabit per second.

The company said hyper-volumetric attacks grew 519% between the first and second quarters, showing that attackers are increasingly capable of delivering extreme traffic floods at a rapid pace.

The findings appear in Cloudflare’s 25th DDoS Threat Report, which combines data from January through June 2026. Unlike previous reports that covered each quarter separately, this edition provides a half-year view of attacks observed and mitigated across the Cloudflare network.

During the period, Cloudflare mitigated 23.2 million network-layer DDoS attacks and 29.64 trillion HTTP DDoS requests. This amounts to roughly 5,343 network-layer attacks per hour, or about 128,000 per day.

Cloudflare Blocks 935 DDoS Attacks Over 1 Tbps

The figures show that DDoS activity remains a constant operational threat for organizations operating public-facing infrastructure. Hyper-volumetric DDoS attacks are defined as attacks exceeding 1 Tbps, 1 billion packets per second, or 1 million requests per second.

Hyper-volumetric attacks (Source : cloudflare )
Hyper-volumetric attacks (Source: Cloudflare)

Cloudflare mitigated 805 attacks above 1 Tbps during the second quarter alone. These attacks can overwhelm internet connections, network equipment, and data centers before security teams have time to investigate alerts or manually activate mitigation controls.

Despite the growth of record-scale attacks, most DDoS incidents were smaller and shorter. Cloudflare said 96.62% of network-layer attacks stayed below 500 Mbps, while 90.60% ended in less than 10 minutes.

April 2026 was a peak month for DDoS activity and volume (Source : cloudflare )
April 2026 was a peak month for DDoS activity and volume (Source: Cloudflare)

However, even a 100 Mbps flood can disrupt an unprotected website or server. A short attack can also cause longer service problems, including routing instability, TCP retransmissions, application timeouts, and degraded downstream services.

The main attack vectors also changed significantly. DNS-based attacks represented 34.3% of all network-layer DDoS activity during the first half of the year. DNS floods increased from 25.7% of attacks in the first quarter to 40.0% in the second quarter.

Attackers use DNS floods to exhaust the query capacity of authoritative DNS servers, potentially making domains and related online services inaccessible.

CLDAP floods also grew 580% quarter over quarter, becoming the third-most-common network-layer attack vector in the second quarter.

Top attack source countries (Source : cloudflare )
Top attack source countries (Source: Cloudflare)

This technique abuses exposed LDAP-over-UDP services, often on UDP port 389, to reflect amplified traffic at victims using spoofed source addresses.

Geopolitical events continued to influence targeting patterns. Media, Production and Publishing was the most attacked industry in both quarters, receiving 14.2% of all mitigated HTTP DDoS requests. Cloudflare linked sustained pressure on the sector to coverage of events involving Iran, Ukraine, and the World Cup.

Government organizations also saw a major shift. The sector moved from 29th place in the first quarter to ninth place in the second quarter during Operation Epic Fury.

Meanwhile, China ranked as the most attacked location in the second quarter, followed by the United States and Turkey. Cloudflare said automated, always-on protection is essential because modern DDoS attacks can begin, peak, and end within seconds.

 Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.

The post 1 Tbps DDoS Attacks Become the New Normal as Cloudflare Reports Record H1 Activity appeared first on Cyber Security News.

❌
❌