Monday , September 28 2026
15

Azure hit by Record 15 Tbps DDoS attack using 500,000+ IP addresses

On October 24, 2025, Azure DDoS Protection detected and mitigated the largest cloud DDoS attack at 15.72 Tbps with nearly 3.64 billion packets per second, aimed at one endpoint in Australia.

Azure’s global DDoS Protection system quickly identified and mitigated threats, filtering out harmful traffic and ensuring continuous service for customer workloads.

Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

Microsoft has fixed a serious security flaw in Azure AI Foundry that could let bad actors gain privilege escalation. The...
Read More
Microsoft Patches CVSS 10.0 Azure AI Foundry Vulnerability Allowing Privilege Escalation

AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Amazon Web Services cannot restore access to its cloud-computing facility in Bahrain and ‌one of three data-hosting zones in the...
Read More
AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

A threat actor is allegedly offering a private remote code execution exploit for Fortinet FortiGate SSL VPN appliances, claiming that...
Read More
Cisco Warns of Critical ISE 0-Day Flaw and Hackers Allegedly Selling Fortinet FortiGate 1-Day Flaw

Anthropic prepares “Claude Money” to analyze bank account and financial data

Anthropic is making a new Claude feature called “Money.” It's a separate tab in the mobile app. The new interface...
Read More
Anthropic prepares “Claude Money” to analyze bank account and financial data

GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

GhostCode is a new phishing kit that changes a regular Microsoft 365 sign-in into an account theft. It doesn't need...
Read More
GhostCode Phishing Kit Evades Microsoft 365 MFA to Hijack Accounts in 78 Seconds

CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

CISA has added a serious Cisco Secure Email Gateway flaw to its list of known exploits. They warn that attackers...
Read More
CISA Warns of Cisco Secure Email Gateway 0-Day Flaw Actively Exploited in Attacks

VPN flaw exposed 246,000 personnel records in japan

Japan’s Digital Agency found a data leak that may have exposed about 246,000 records with personal information of government workers....
Read More
VPN flaw exposed 246,000 personnel records in japan

Hackers deploy Casbaneiro Trojan that activates on bank websites

Casbaneiro is going after online banking users by sending fake messages that seem like urgent bills or legal papers. The...
Read More
Hackers deploy Casbaneiro Trojan that activates on bank websites

German police read Signal, Telegram, WhatsApp messages without breaking encryption

German law enforcement agencies are using features built into apps such as WhatsApp to monitor people’s messages without breaking their...
Read More
German police read Signal, Telegram, WhatsApp messages without breaking encryption

Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

GitLab has released an important security update to fix two serious problems. These issues could allow unauthorized file access and...
Read More
Urgent Patch! cPanel, GitLab Flaws Expose Users to RCE, File and Credential Theft

The attack originated from Aisuru botnet. Aisuru is a Turbo Mirai-class IoT botnet that frequently causes record-breaking DDoS attacks by exploiting compromised home routers and cameras, mainly in residential ISPs in the United States and other countries.

The attack featured high-rate UDP floods aimed at a specific public IP, originating from over 500,000 unique IPs. These sudden UDP bursts had little source spoofing and random ports, making traceback easier and allowing for provider enforcement.

An Azure attack surpasses recent records, indicating a worrying trend. Last month, on September 15, 2025, Cloudflare disclosed that it stopped a 22.5 Tbps attack, driven by a Mirai variant infecting smart devices.

In March 2025, Google Cloud fended off a 10.2 Tbps attack from Asia-Pacific botnets that used SYN floods and DNS amplification.

In 2024, AWS reported an 8.9 Tbps attack on a U.S. e-commerce site, linked to hacked routers in Eastern Europe.

Cloudflare’s 2025 Q1 DDoS Report from April showed a record number of DDoS attacks mitigated last year, marking a 198% increase from the previous quarter and a 358% rise compared to the previous year.

It blocked 21.3 million DDoS attacks against its customers in 2024, plus 6.6 million attacks on its infrastructure during an 18-day multi-vector campaign.

DDoS Scandals Hit Bangladesh ISP Sector: BTRC Prepares Crackdown

Check Also

AI models

CISA Says Chinese Firms Extracted Billions of Tokens From Frontier AI Models

Six Chinese AI companies ran large-scale attacks on American AI models since late 2024, according …