Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'dos'

View all threats tagged with 'dos'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: dos

Threats Tagged 'dos'

Click on any threat for detailed analysis and mitigation recommendations

GPUThor: an evolution of the Rowhammer idea
0

GPUThor is a new Rowhammer attack technique targeting Nvidia Ampere GPUs with GDDR6 memory, significantly increasing the effectiveness of bit flips in video memory. It exploits a hardware behavior where repeated memory access can corrupt data in neighboring cells, bypassing standard defenses like Target Row Refresh (TRR). The attack can cause double and triple-bit errors, which are not fully corrected by ECC memory, leading to denial of service conditions such as GPU reboots and hardware faults. While arbitrary code execution has not been demonstrated, the attack shows a theoretical potential to compromise industrial GPUs and cloud infrastructure using such accelerators.

MediumVulnerability#cloud#dos#ai
Join the discussion
CVE-2026-85786 - Incomplete fix for CVE-2026-75936 memory-amplification denial of service in Amazon ion-javaCVE-2026-85786
0

CVE-2026-85786 is a memory-amplification denial of service vulnerability in the Amazon ion-java library. It arises from an incomplete fix for a previous vulnerability (CVE-2026-75936) related to GZIP auto-decompression. The issue allows denial of service via highly compressed data expansion. Versions of ion-java prior to 1.12.1 are affected. The vulnerability has been addressed in ion-java version 1.12.1, and no workarounds are available.

HighVulnerability#cloud#dos#java
Join the discussion
CVE-2026-84851: CWE-674: Uncontrolled Recursion in Amazon ion-cCVE-2026-84851
0

An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service.

Join the discussion
New GPUThor attack defeats NVIDIA ECC protection for root access
0

GPUThor is a newly disclosed Rowhammer attack targeting NVIDIA Ampere-class GPUs with GDDR6 memory, including RTX A4000, A4500, A5000, and A6000. It bypasses NVIDIA's ECC protections by exploiting undocumented GPU behaviors and a non-uniform hammering pattern to induce high bit-flip rates. This enables denial-of-service conditions and root-level privilege escalation by corrupting GPU page tables. The attack was demonstrated to cause GPU resets and eventual hardware marking for replacement. NVIDIA recommends enabling SYS-ECC and IOMMU/DMA isolation, monitoring error telemetry, and restricting untrusted workloads. Complete protection likely requires future hardware-level defenses and stronger multi-bit ECC. No bit flips were observed on tested GDDR6X or HBM2e GPUs using the same attack patterns.

Join the discussion
In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug
0

Other noteworthy stories that might have slipped under the radar: Threema DDoS attack, Evooo1Bot Linux botnet, Crypto4A secures top-tier NIST certification. The post In Other News: Zombie Card Attack, T-Mobile Cut Cable to Stop Hackers, GitHub Denies AI Caused Bug appeared first on SecurityWeek .

Join the discussion
CVE-2026-75935: CWE-789 Memory allocation with excessive size value in Amazon Ion Amazon Ion JavaCVE-2026-75935
0

Bulletin ID: 2026-083-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 12:30 PM PDT Description: ion-java is a Java library that implements the Amazon Ion data format specification. We identified CVE-2026-75935, memory-amplification denial of service via declared-length preallocation, and CVE-2026-75936, memory-amplification denial of service via highly compressed data expansion. Affected versions: < 1.12.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Join the discussion
CVE-2026-75897: CWE-1284: Improper Validation of Specified Quantity in Input in OpenSearch OpenSearch DashboardsCVE-2026-75897
0

Bulletin ID: 2026-082-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/18/2026 10:00 AM PDT Description: OpenSearch Dashboards is the open-source visualization and management UI for OpenSearch, and ships as part of Amazon OpenSearch Service. We identified CVE-2026-75897, an improper input validation in the capabilities route handler in OpenSearch Dashboards. The handler does not bound the size of the request payload, which might allow remote attackers to cause a denial of service via a crafted HTTP request. Affected Products and Versions: OpenSearch "Plugin Type" Plugin (open-source, self-managed): - Affected: All versions from 1.3.0 through 3.7.0 inclusive, including all 2.x releases up to and including 2.19.6. The issue is inherited from upstream Kibana and is also present in Kibana 7.7.1 through 7.10.2. - Fixed: 3.8.0 Amazon OpenSearch Service (AWS Managed): - Affected: Engine versions OpenSearch 1.3, 2.11, 2.13, 2.15, 2.17, 2.19, 3.1, 3.3, and 3.5, and Elasticsearch-compatibility versions using Kibana 7.9 and 7.10. - Fixed: A patched service software release is available for all affected versions. Apply the latest available service software update to your domain. Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

Join the discussion
Improper Control of Generation of Code ('Code Injection') in GitLab (CVE-2026-19478)CVE-2026-19478
0

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user data via a GraphQL directive.

Join the discussion
Large-scale DDoS attacks disrupted Threema secure messaging service
0

Multiple distributed denial-of-service (DDoS) attacks targeted the Threema secure messaging service earlier this week, causing severe disruptions to communications. [...]

Join the discussion
Kimwolf v7: An Evolution of the Kimwolf Botnet
0

Discover how Kimwolf v7 targets Android IoT devices with HTTP/2 DDoS fingerprinting, Ethereum ENS C2 resolution and Tor backup routing. The post Kimwolf v7: An Evolution of the Kimwolf Botnet appeared first on Unit 42 .

Join the discussion

Showing 1 to 10 of 12 results

Filters:Tag: dos
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses