#1 Trending Cybersecurity News & Magazine
Wednesday, December 6, 2023
No Result
View All Result
The Cyber Express
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    MAPC Cyberattack

    LockBit Claims Cyberattack on Metropolitan Area Planning Council, Sets December 8 Deadline

    cyberattacks on Israeli organizations

    Cyber Toufan Team Strikes Again: Israeli Organizations Allegedly Hit by Cyberattacks

    TraCS Florida cyberattack

    ALPHV/BlackCat Claims Cyberattack on TraCS Florida, Website Outage Raises Doubts

    Income Tax Department of India

    India’s Income Tax Department Data Breach: Threat Actor Sets Price for Access

    James Yoo

    The Man Behind the Arlington Explosion: Ex-Telecom Security Chief Suspected

    SPARRSO data breach

    Cyberattack on SPARRSO Raises Concerns Over Security in Bangladesh

    Tipalti breach update

    Tipalti Data Breach Remains Unconfirmed, Hacker Claims Prompts Immediate Investigation

    GTA 6 Map Leak

    The GTA 6 Map Leaked by Rockstar Employee’s Son: What’s Disclosed?

    TrickMo Banking Trojan

    TrickMo Banking Trojan Resurfaces with New Features, Targeting Android Devices this Time Around

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    AI Security Guidelines

    Rethinking AI For Cybersecurity: The UK & US Reveals New Guidelines For AI Security

    Cyber Insurance

    Cyber Insurance and Real-Time Threat Dashboard to Mend the Gaps in Near Future

    Pledge to Stop Ransom Payment

    Pledge to Stop Ransom Payment Awaits Consensus from all Members of the CRI

    Executive Order on Artificial Intelligence

    Biden Administration’s AI Directive: A Blueprint for Ethical Use and Enhanced Cybersecurity

    Cyber Resilience

    Towards Cyber Resilience: A Data-Centric Approach to Security

    CybleGrowCon

    Cyble Partner Network GrowCon 2023: Uniting Cybersecurity Leaders

    GRC, What is GRC

    What is GRC (Governance, Risk & Compliance): A Beginner’s Guide

    Facial Recognition Ban

    New York State Education Department Bans Facial Recognition Scans in Schools

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    InsureMO

    InsureMO Partners with Cyble to Revolutionize Cyber Insurance with Real-Time Threat Intelligence

    Countdown to TimeAI Summit 2023

    Countdown to TimeAI Summit 2023: Unveiling the Future of Artificial Intelligence in Dubai

    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin
SUBSCRIBE
  • MagazineDownload
  • Firewall Daily
    • All
    • Bug Bounty & Rewards
    • Dark Web News
    • Data Breach News
    • Hacking News
    • Ransomware News
    • Vulnerabilities
    MAPC Cyberattack

    LockBit Claims Cyberattack on Metropolitan Area Planning Council, Sets December 8 Deadline

    cyberattacks on Israeli organizations

    Cyber Toufan Team Strikes Again: Israeli Organizations Allegedly Hit by Cyberattacks

    TraCS Florida cyberattack

    ALPHV/BlackCat Claims Cyberattack on TraCS Florida, Website Outage Raises Doubts

    Income Tax Department of India

    India’s Income Tax Department Data Breach: Threat Actor Sets Price for Access

    James Yoo

    The Man Behind the Arlington Explosion: Ex-Telecom Security Chief Suspected

    SPARRSO data breach

    Cyberattack on SPARRSO Raises Concerns Over Security in Bangladesh

    Tipalti breach update

    Tipalti Data Breach Remains Unconfirmed, Hacker Claims Prompts Immediate Investigation

    GTA 6 Map Leak

    The GTA 6 Map Leaked by Rockstar Employee’s Son: What’s Disclosed?

    TrickMo Banking Trojan

    TrickMo Banking Trojan Resurfaces with New Features, Targeting Android Devices this Time Around

    Trending Tags

    • blackbyte ransomware
    • Ransomware
    • lapsus$ ransomware
    • Apple
    • Apple vulnerability
  • Essentials
    • All
    • Compliance
    • Governance
    • Policy Updates
    • Regulations
    AI Security Guidelines

    Rethinking AI For Cybersecurity: The UK & US Reveals New Guidelines For AI Security

    Cyber Insurance

    Cyber Insurance and Real-Time Threat Dashboard to Mend the Gaps in Near Future

    Pledge to Stop Ransom Payment

    Pledge to Stop Ransom Payment Awaits Consensus from all Members of the CRI

    Executive Order on Artificial Intelligence

    Biden Administration’s AI Directive: A Blueprint for Ethical Use and Enhanced Cybersecurity

    Cyber Resilience

    Towards Cyber Resilience: A Data-Centric Approach to Security

    CybleGrowCon

    Cyble Partner Network GrowCon 2023: Uniting Cybersecurity Leaders

    GRC, What is GRC

    What is GRC (Governance, Risk & Compliance): A Beginner’s Guide

    Facial Recognition Ban

    New York State Education Department Bans Facial Recognition Scans in Schools

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    US Cybersecurity Regulations: Tracing the Past and Predicting the Future

    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • All
    • Appointments
    • Budgets
    • Mergers & Aquisitions
    • Partnerships
    • Press Release
    • Startups
    InsureMO

    InsureMO Partners with Cyble to Revolutionize Cyber Insurance with Real-Time Threat Intelligence

    Countdown to TimeAI Summit 2023

    Countdown to TimeAI Summit 2023: Unveiling the Future of Artificial Intelligence in Dubai

    Emerging Tech Summit

    The Emerging Tech Summit – Saudi Arabia 2023

    Business Cybersecurity

    Prioritizing Business Cybersecurity Plans During Mergers and Acquisitions

    TimeAI Summit

    TimeAI Summit is Uniting Tech Giants and Visionaries in Dubai to Shape the Future of AI

    CyberDSA 2023

    CyberDSA 2023: Forging a Resilient Digital Future Through Unprecedented Collaboration

    Summit MENA 2023

    MENA Summit 2023: Exploring the Future of Digital Identity & Authentication

    Cyble Raises 24 Million in Series B Funding

    Cyble Raises 24 Million in Series B Funding: Leveraging AI and Threat Intelligence to Revolutionize Cybersecurity

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    Alarming 66% Quarterly Growth in Ransomware Attacks Notes Cyble’s Q2-2023 Ransomware Report

    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • EventsCyberCon
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • ProductsTools
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin
No Result
View All Result
The Cyber Express
No Result
View All Result
Home Cybersecurity News

Dubbed the Largest DDoS Attack, What is CVE-2023-44487 HTTP/2 ‘Rapid Reset’?

CISA issued an alert about the Rapid Reset vulnerability, urging organizations with HTTP/2 services to apply available patches promptly.

Avantika Chopra by Avantika Chopra
October 12, 2023 - Updated on October 13, 2023
in Cybersecurity News, Firewall Daily
0
Rapid Reset
617
SHARES
3.4k
VIEWS
Share on LinkedInShare on Twitter

Earlier this week, Amazon Web Services, Cloudflare, and Google jointly disclosed their efforts in combating highly potent HTTP/2-based Distributed Denial of Service (DDoS) attacks using an undisclosed ‘Rapid Reset’ zero-day technique, which is now documented as vulnerability CVE-2023-44487.

This vulnerability has been actively exploited from August 2023 to October 2023 in the wild.

You might also like

LockBit Claims Cyberattack on Metropolitan Area Planning Council, Sets December 8 Deadline

Cyber Toufan Team Strikes Again: Israeli Organizations Allegedly Hit by Cyberattacks

ALPHV/BlackCat Claims Cyberattack on TraCS Florida, Website Outage Raises Doubts

The Cybersecurity and Infrastructure Security Agency (CISA) issued an alert regarding the detected Rapid Reset vulnerability, advising organizations that offer HTTP/2 services to apply any available patches promptly and to contemplate implementing configuration adjustments and other protective measures discussed in the provided references.

The assault, documented under the vulnerability identifier CVE-2023-44487, sent shockwaves through the cybersecurity community due to its unparalleled scale and destructive potential, with many terming it the largest DDoS attack. 

This article aims to explain CISA’s alert about the CVE-2023-44487 HTTP/2 vulnerability and shed light on the warning for the Rapid Reset DDoS attack, underscoring the need for immediate action.

Unprecedented Rapid Reset DDoS Attack Magnitudes 

The statistics surrounding the ‘Rapid Reset’ DDoS attacks were nothing short of staggering. Amazon successfully mitigated attacks at an astonishing rate of 155 million requests per second, while Cloudflare grappled with an even more overwhelming 201 million requests per second.

In their blog, the IT service management company stated that the attack was nearly 3x bigger than their previous biggest attack on record, which was a 71 million request-per-second DDoS attack

To top it off, Google faced an unprecedented 398 million requests per second during the attacks. This zero-day technique had already been under active assault back in August, prompting heightened concerns in the cybersecurity domain. 

The CVE-2023-44487 HTTP/2 Rapid Reset DDoS Attack Explained 

The ‘Rapid Reset’ attack is a crafty exploitation of the HTTP/2 protocol’s ‘stream multiplexing’ feature. 

This nefarious tactic inundates the server with multiple requests and immediate cancellations, overloading it while keeping attacker costs minimal.

Essentially, it exploits HTTP/2’s unique ability to repeatedly send and cancel requests, rendering the target website or application inoperative. In theory, HTTP/2 includes a protective feature to limit concurrent streams and guard against Denial of Service (DoS) attacks.

However, in practice, this safeguard can fail, as the protocol allows clients to unilaterally cancel streams without server consent. The vulnerability is mercilessly exploited by the ‘Rapid Reset’ technique, posing a grave threat, especially when orchestrated by botnets.

The Biggest DDoS Attack on Record 

The attackers exploited a security vulnerability that affected the very foundation of internet delivery services. As a result, numerous organizations (Microsoft, Cisco, Adobe) and networks found themselves under an unrelenting barrage of malicious traffic, causing widespread outages, service disruptions, and financial losses. 

The vulnerability allows fraudsters to illegally control computer systems, allowing malicious code execution, malware installation, and sensitive data theft.

It was among the ‘Five Actively Exploited Vulnerabilities’ detailed in a recent report: CVE-2023-21608 (Adobe), CVE-2023-20109 (Cisco), CVE-2023-41763 (Microsoft), CVE-2023-36563 (Microsoft), and CVE-2023-44487 (HTTP/2 protocol). 

Rapid Reset DDoS Attack: CISA’s Urgent Warning  

Understanding the severity of the situation, CISA promptly issued a warning to organizations responsible for critical internet delivery services.

The agency urged them to take immediate action by applying patches and other mitigations to address the vulnerability. This call to action was not a suggestion but a necessity, as the consequences of inaction were too dire to contemplate. 

The consequences of not heeding CISA’s warning are severe. Failure to address the security vulnerability promptly could leave organizations vulnerable to relentless DDoS attacks, leading to prolonged downtime, loss of user trust, and substantial financial repercussions. 

To lessen the impact of DoS attacks, organizations can consider adopting proactive measures, utilizing advisories and reports provided by CISA.

These resources, including “Understanding and Responding to Distributed Denial-of-Service Attacks” and “Additional DDoS Guidance for Federal Agencies,” offer valuable insights for addressing the issue.

Rapid Reset DDoS Attack: Collaborative Effort Required 

Given the gravity of the CVE-2023-44487 vulnerability, which heaps additional load on web servers through rapid stream generation and cancellation, addressing this issue is paramount.

Organizations with their own HTTP/2-enabled web servers should work closely with their vendors to swiftly apply necessary patches. This action is crucial to fortify defenses against the emerging threat and protect vital web infrastructures. 

The ‘Rapid Reset’ DDoS attack, with its unprecedented scale and impact, underscores the necessity for a collective and proactive response to evolving cybersecurity challenges.

In a constantly evolving digital landscape, the lessons learned emphasize the importance of vigilance, collaboration, and timely patch management to secure online infrastructure against unforeseen threats. 

Collaboration is essential in mitigating this threat, extending beyond the responsibilities of critical internet service providers.

Technology vendors, internet service providers, and government agencies must unite in this effort, emphasizing collaboration and information sharing to proactively address vulnerabilities before they are exploited by malicious actors.

Share this:

  • Click to share on LinkedIn (Opens in new window)
  • Click to share on Reddit (Opens in new window)
  • Click to share on Twitter (Opens in new window)
  • Click to share on Facebook (Opens in new window)
  • More
  • Click to email a link to a friend (Opens in new window)
  • Click to share on WhatsApp (Opens in new window)

Related

Previous Post

Israeli Military Data on Sale: Hacker Claims Access to Soldier Data

Next Post

Safexpay Clarifies Fraud Transactions Involving Rs.16,180 Crore Unrelated to Company

Avantika Chopra

Avantika Chopra

Associate Editor, The Cyber Express

Related Posts

MAPC Cyberattack
Firewall Daily

LockBit Claims Cyberattack on Metropolitan Area Planning Council, Sets December 8 Deadline

by Samiksha Jain
December 6, 2023
cyberattacks on Israeli organizations
Firewall Daily

Cyber Toufan Team Strikes Again: Israeli Organizations Allegedly Hit by Cyberattacks

by Ashish Khaitan
December 6, 2023
TraCS Florida cyberattack
Firewall Daily

ALPHV/BlackCat Claims Cyberattack on TraCS Florida, Website Outage Raises Doubts

by Samiksha Jain
December 6, 2023
Income Tax Department of India
Data Breach News

India’s Income Tax Department Data Breach: Threat Actor Sets Price for Access

by Samiksha Jain
December 5, 2023
James Yoo
Cybersecurity News

The Man Behind the Arlington Explosion: Ex-Telecom Security Chief Suspected

by Samiksha Jain
December 5, 2023
Next Post
Safexpay

Safexpay Clarifies Fraud Transactions Involving Rs.16,180 Crore Unrelated to Company

Latest Issue is Out. Subscribe Now

Cybersecurity Magazine



Follow Us On Google News

Latest Cyber News

MAPC Cyberattack
Firewall Daily

LockBit Claims Cyberattack on Metropolitan Area Planning Council, Sets December 8 Deadline

December 6, 2023
cyberattacks on Israeli organizations
Firewall Daily

Cyber Toufan Team Strikes Again: Israeli Organizations Allegedly Hit by Cyberattacks

December 6, 2023
TraCS Florida cyberattack
Firewall Daily

ALPHV/BlackCat Claims Cyberattack on TraCS Florida, Website Outage Raises Doubts

December 6, 2023
Income Tax Department of India
Data Breach News

India’s Income Tax Department Data Breach: Threat Actor Sets Price for Access

December 5, 2023

Categories

Web Stories

Top 10 CISOs to Follow in 2023
Top 10 CISOs to Follow in 2023
Top 10 Ransomware Gangs in 2023
Top 10 Ransomware Gangs in 2023
Top 5 IoT Security Risks in 2023
Top 5 IoT Security Risks in 2023
Top 10 CTF Platforms in 2023
Top 10 CTF Platforms in 2023
Types of Risks Covered by Cyber Insurance
Types of Risks Covered by Cyber Insurance

About

The Cyber Express by Cyble

#1 Trending Cybersecurity News and Magazine

The Cyber Express  by Cyble is a handbook for all stakeholders of the internet that provides information security professionals with the latest news, updates and knowledge they need to combat cyber threats.

 

Contact

For editorial queries: [email protected]

For marketing and Sales: [email protected]

For Events & Conferences related information: [email protected]

 

Quick Links

  • About Us
  • Advertise With Us
  • Contact Us
  • Editorial Calendar

Our Address

We’re remote friendly, with office locations around the world:

San Francisco, Atlanta, Rome,
Dubai, Mumbai, Bangalore, Hyderabad,  Singapore, Jakarta, Sydney, and Melbourne

 

Headquarters:

The Cyber Express LLC
555 North Point Center E
Alpharetta, GA 30022, USA.

 

India Office:

Cyber Express Media Network
HD-021, 4th Floor, C Wing, Building No.4. Nesco IT Park, WE Highway, Goregaon East, Mumbai, Maharashtra, India – 4000063

Subscribe to Our Feed

RSS Feeds

Follow Us On Google News
  • Privacy Statement
  • Terms of Use
  • Write For Us

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

No Result
View All Result
  • Magazine
  • Firewall Daily
  • Essentials
    • Regulations
    • Compliance
    • Governance
    • Policy Updates
  • Features
    • Cyber Warfare
    • Espionage
    • Workforce
      • Learning & Development
  • Business
    • Startups
    • Mergers & Aquisitions
    • Partnerships
    • Appointments
    • Budgets
    • Research
      • Whitepapers
      • Sponsored Content
      • Market Reports
    • Interviews
      • Podcast
  • Events
    • World CyberCon India 2023
    •  Cyber Security Webinar
    • Endorsed Events
  • Products
    • Cyble Vision
    • Cyble Hawk (LEA, Govt.)
    • Am I Breached
    • Cyble Odin

© 2023 The Cyber Express (Cybersecurity News and Magazine) | By Cyble Inc.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In

Add New Playlist

This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.
Top 10 CISOs to Follow in 2023 Top 10 Ransomware Gangs in 2023 Top 5 IoT Security Risks in 2023 Top 10 CTF Platforms in 2023 Types of Risks Covered by Cyber Insurance