On November 9, 2023, the hacktivist group Anonymous Sudan claimed responsibility for initiating a distributed denial-of-service (DDoS) attack on Cloudflare's website. While Cloudflare acknowledged the DDoS attack, the outage was confined to the?www[.]cloudflare[.]com?site and did not impact other services or products. The company clarified that its website operates on separate infrastructure, ensuring no disruption to Cloudflare's core services. Anonymous Sudan, also known as Storm-1359, asserted involvement in various cyber incidents, including a recent DDoS attack on OpenAI's ChatGPT bot and disruptions to Microsoft's Outlook.com, OneDrive, and Azure Portal in June. The group claims to target entities interfering with Sudanese politics, but some analysts question its authenticity, suggesting potential links to Russia. Cloudflare is actively investigating a current outage that displays Google errors on its website, featuring a message apologizing for potential automated queries. The error message, adorned with a Google logo, raises suspicions due to a font inconsistency. Cloudflare's status page notes that?www[.]cloudflare[.]com?is experiencing issues, but the Cloudflare Dashboard remains accessible through dash.cloudflare.com, and all other services are unaffected. Last week, Cloudflare faced a dashboard and API outage stemming from a power outage in its core North American data center. The recent disruption impacted various Cloudflare services, including Logpush, WARP/Zero Trust device posture, Stream API, Workers API, and the Alert Notification System. Customers reported difficulties accessing their accounts, encountering authentication errors (Code: 10000), and internal server errors on the Cloudflare dashboard. Another outage occurred on October 30, affecting multiple products due to a misconfiguration during the deployment of a new Workers KV build, as detailed in a subsequent post-mortem report by Cloudflare. These incidents highlight the challenges of maintaining stable online services amid cyber threats and technical issues.
A large-scale phishing campaign has been identified leveraging RFQ (Request for Quotation) themed emails to distribute credential-stealing malware. Attackers disguise malicious HTM...
Two critical vulnerabilities in Progress ShareFile have been identified that can be chained to achieve pre-authentication remote code execution (RCE). Discovered by watchTowr resea...
The FBI has issued a warning highlighting potential security and privacy risks associated with widely used mobile applications developed by Chinese companies. These applications, a...