Threats Tagged 'dos'
View all threats tagged with 'dos'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'dos'
Click on any threat for detailed analysis and mitigation recommendations
Three Linux kernel vulnerabilities have been identified and added to CISA's Known Exploited Vulnerabilities catalog. These flaws allow local attackers to cause denial-of-service conditions, memory disclosure, or unauthorized memory modification. The vulnerabilities involve issues in the TLS receive path, AF_ALG socket handling, and bridge Netfilter ebtables SNAT target. Federal agencies are urged to patch these vulnerabilities promptly. Join the discussion | SecurityWeek | 09/21/2026, 09:31:12 UTC Added: 09/21/2026, 09:31:40 UTC |
NightmareStresser was a long-running distributed denial-of-service (DDoS) for-hire service active since at least 2022, likely founded in 2016. It enabled nearly one million users to launch thousands of DDoS attacks per hour worldwide, accepting cryptocurrency payments while avoiding attacks on government, education, and hospital domains. The service was disrupted in a coordinated international law enforcement operation called Operation PowerOFF, which seized its domains and aimed to dismantle DDoS-for-hire infrastructures globally. This takedown is part of ongoing efforts by multiple countries to combat DDoS-for-hire services and hold their operators and users accountable. Join the discussion | SecurityWeek | 09/18/2026, 10:12:33 UTC Added: 09/18/2026, 10:16:37 UTC |
The U.S. Federal Bureau of Investigation (FBI) seized the domains of NightmareStresser, a long-running distributed denial-of-service (DDoS) for-hire platform. NightmareStresser allowed users to rent botnets composed of compromised routers and IoT devices to launch large-scale DDoS attacks targeting various network layers. The service had over 566,000 registered users and could launch attacks up to 200 Gbps. This takedown was part of Operation PowerOFF, a coordinated international law enforcement effort to dismantle criminal DDoS-for-hire infrastructures worldwide. Previous actions under this operation have led to multiple arrests and domain seizures of similar services. The FBI and other agencies continue to target these platforms to reduce the prevalence of DDoS attacks globally. Join the discussion | Bleeping Computer | 09/17/2026, 11:33:35 UTC Added: 09/17/2026, 12:31:58 UTC |
0 A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges. Join the discussion | CVE Database V5 | 09/16/2026, 13:03:40 UTC Added: 09/16/2026, 13:32:17 UTC |
0 An unrecovered panic in the event stream header decoder in Amazon AWS SDK for Go v2 before release-2026-03-23 might allow an unauthenticated remote actor to terminate the consuming application process via a crafted event stream response frame containing a header value type outside the valid range. To remediate this issue, users should upgrade to release-2026-03-23 or later, and patch any forked or derivative code. Join the discussion | AWS Security Bulletins | 09/11/2026, 17:09:09 UTC Added: 09/11/2026, 17:14:28 UTC |
CVE-2026-85228 is an integer overflow vulnerability in the tensor buffer validation component of the Deep Java Library (DJL), an open-source Java framework for deep learning maintained by Amazon. The flaw occurs when a crafted tensor payload declares a shape whose computed byte size exceeds the 32-bit signed integer range, causing the size to wrap and allowing an undersized buffer to pass validation. This leads to out-of-bounds reads during tensor operations. Exploitation could allow a remote, unauthenticated attacker to access adjacent process memory or cause a denial of service. A fix has been released in DJL version 0.37.0. Users are advised to upgrade to this version or later. No workaround other than upgrading is available, but limiting tensor input to trusted sources can reduce risk until patched. Join the discussion | GCVE Database | 09/10/2026, 18:31:47 UTC Added: 09/10/2026, 22:04:19 UTC |
GPUThor is a new Rowhammer attack technique targeting Nvidia Ampere GPUs with GDDR6 memory, significantly increasing the effectiveness of bit flips in video memory. It exploits a hardware behavior where repeated memory access can corrupt data in neighboring cells, bypassing standard defenses like Target Row Refresh (TRR). The attack can cause double and triple-bit errors, which are not fully corrected by ECC memory, leading to denial of service conditions such as GPU reboots and hardware faults. While arbitrary code execution has not been demonstrated, the attack shows a theoretical potential to compromise industrial GPUs and cloud infrastructure using such accelerators. Join the discussion | Kaspersky Security Blog | 09/08/2026, 16:01:41 UTC Added: 09/08/2026, 16:05:32 UTC |
0 CVE-2026-85786 is a memory-amplification denial of service vulnerability in the Amazon ion-java library. It arises from an incomplete fix for a previous vulnerability (CVE-2026-75936) related to GZIP auto-decompression. The issue allows denial of service via highly compressed data expansion. Versions of ion-java prior to 1.12.1 are affected. The vulnerability has been addressed in ion-java version 1.12.1, and no workarounds are available. Join the discussion | AWS Security Bulletins | 09/04/2026, 19:24:10 UTC Added: 09/04/2026, 19:35:13 UTC |
An uncontrolled recursion issue exists in Amazon Ion-C versions before 1.1.6 that might allow a remote unauthenticated actor to craft Ion data that exhausts the native call stack and crashes the application using the library, resulting in a denial of service. Join the discussion | CVE Database V5 | 09/02/2026, 20:19:55 UTC Added: 09/02/2026, 20:37:47 UTC |
GPUThor is a newly disclosed Rowhammer attack targeting NVIDIA Ampere-class GPUs with GDDR6 memory, including RTX A4000, A4500, A5000, and A6000. It bypasses NVIDIA's ECC protections by exploiting undocumented GPU behaviors and a non-uniform hammering pattern to induce high bit-flip rates. This enables denial-of-service conditions and root-level privilege escalation by corrupting GPU page tables. The attack was demonstrated to cause GPU resets and eventual hardware marking for replacement. NVIDIA recommends enabling SYS-ECC and IOMMU/DMA isolation, monitoring error telemetry, and restricting untrusted workloads. Complete protection likely requires future hardware-level defenses and stronger multi-bit ECC. No bit flips were observed on tested GDDR6X or HBM2e GPUs using the same attack patterns. Join the discussion | Bleeping Computer | 08/26/2026, 18:48:24 UTC Added: 08/26/2026, 18:52:16 UTC |
Showing 1 to 10 of 103 results