Cybersecurity · Wednesday, 12 August 2026
01 · Briefing · what happened
DDoS floods hit a record, and why the cheapest attacks keep winning
Giant traffic floods against news sites surged fivefold, powered by botnets of hijacked devices that cost the attacker almost nothing. Across the week, the pattern held: stolen passwords, known bugs, and cheap floods keep beating the pricey stuff.
805
record floods in one quarter
each over a trillion bits a second, up 519%
14.2%
of all floods hit news sites
the most-targeted sector this year
100M
people exposed by Snowflake
via old stolen passwords, no new hack
97%
credential attacks bypassed MFA
even a second check was defeated
At a glance
- Cloudflare stopped 805 flooding attacks over 1 trillion bits a second in one quarter, up 519%.
- News and media sites were the top target - 14.2% of all floods, six times the next sector in spring.
- The Kimwolf botnet runs on hijacked Android TV boxes, so the attacker's cost is near zero.
- Its new floods copy Chrome's fingerprint, so cheap filters can't drop them without turning away real readers.
- The Snowflake hacker pleaded guilty: he just tried old stolen passwords against accounts with no second check.
- A 2,158-org survey found stolen logins and phishing now beat software flaws as the top way into ransomware.
Forces in play
botnets of hijacked home gadgets cost the attacker almost nothing
now the top way into ransomware, ahead of software flaws
Gunra breaks in through bugs already patched months ago
Chrome-mimicking floods slip past the simple drop-the-junk filter
How it unfolded
- This quarter record 805 floods over a trillion bits a second, up 519%
- Since February rebuilt Kimwolf botnet disguises floods as Chrome traffic
- Wednesday Snowflake hacker pleads guilty over 100M-person exposure
- This week agencies warn Gunra is exploiting known, unpatched bugs
Where this points
Watch whether defenders shift from blocking to cost-shifting - forcing each request to prove itself so the flood gets expensive - now that copying Chrome has beaten the simple filters.
Full briefing
The biggest wave of attacks this quarter did not break a lock. It just made websites too busy to answer.
Cloudflare, one of the largest networks that soaks up junk traffic, says it stopped 805 attacks in three months
These floods are “denial-of-service” attacks. Thousands of hijacked computers send a site far more requests than it can handle, so real readers cannot get through
Why the flood is so cheap
These attacks keep growing because of money, or rather how little the attacker spends. A flood runs on other people’s machines. The Kimwolf botnet (also called Aisuru) is built mostly from hijacked Android TV boxes and other cheap internet gadgets
Its new trick raises the defender’s cost instead. The latest floods copy the exact fingerprint of the Chrome browser
The same lesson, everywhere this week
Attackers keep choosing the cheapest way in. On Wednesday, Connor Moucka, 26, pleaded guilty to the 2024 Snowflake break-ins
Even the ransomware gangs pick the cheap door. US and South Korean agencies warned that the Gunra gang breaks in through known, already-patched bugs in internet-facing Fortinet gear
Also this week
Microsoft’s monthly patch fixed more than 400 flaws, including one already being used to seize full control of Windows machines
02 · Lesson · why it matters
Security is a price, not a wall
You rarely stop an attack by making it impossible - you stop it by making it cost more than it earns.
How it works
- An attack is cheap to try at huge scale
- So attackers try millions of times for almost nothing
- A perfect wall is impossible and expensive
- So the defender makes each attempt cost time or money
- Once the attempt costs more than it earns, it stops
The twist
You rarely make an attack impossible - you make it not worth the money, by shifting the cost from the defender back onto the attacker.
Where you've seen this
Junk mail
postage costs made mass mailing expensive enough to limit
Shoplifting
tags and cameras raise the effort per item until theft isn't worth it
Login pages
a lockout after five wrong guesses makes trying millions pointless
The catch
Cost-shifting has limits: raise the price too high and you also turn away the real customers you meant to protect.
Full lesson
The flood that broke nothing
The biggest attack wave this quarter did not pick a single lock. It just sent a trillion fake requests a second at news sites until the real readers could not get in. Nothing was stolen. Nothing was cracked. A website was simply made too busy to answer.
That is worth sitting with. We picture hackers as lock-pickers, finding the one clever flaw. But the wave that hit hardest this quarter used no cleverness at all. It used volume. And volume, it turns out, is cheap.
The attacker spends almost nothing
Here is the trick. A flood does not run on the attacker’s own machines. It runs on yours. The botnet behind this wave is built mostly from hijacked smart-TV boxes and cheap internet gadgets sitting in people’s homes. The owners pay the electricity bill. The attacker pays close to nothing and borrows a million machines.
Now look at the other side of the table. To survive that flood, the defender must buy enough capacity to answer every fake request, or find some way to sort the bots from the real visitors. Both cost real money. One side spends pennies; the other spends a fortune. That gap is the whole story.
Cheap at scale beats clever every time
Once you see the gap, you see it everywhere this week. The Snowflake hacker who exposed a hundred million people did not invent anything. He gathered old stolen passwords and tried them against accounts that had no second check. The ransomware gangs are the same. One crew this week broke in through bugs that were already known and already patched months ago. No expensive new flaw. Just the cheapest door left unlocked.
Attackers are shoppers. They do not want the hardest way in. They want the cheapest way that works. When trying a million stolen passwords is free, they try a million passwords. When flooding a site costs nothing, they flood it. The attack you should fear is rarely the cleverest one. It is the one that scales for pennies.
The defender’s real move is a price tag
So if a perfect wall is impossible, what works? You change the math. You make each attempt cost the attacker something.
Lock an account after five wrong guesses, and trying a million passwords stops being free. Add a second check, and a stolen password alone is no longer the whole front door. Make each flood connection prove it is a real browser first, and the flood has to spend time and computing power on every fake request. None of these builds a wall. Each one raises a price. And when the price of attacking climbs past what the attack earns, the attacker walks away and finds a cheaper target.
The same lever can shut out the wrong people
There is a catch, and this week showed it plainly. The new floods copy the exact fingerprint of a real Chrome browser. Now the defender cannot tell the bot from the reader. Raise the price too high, and you also turn away the very people you were protecting. The attacker did not just flood the door. They made honesty itself expensive to check.
This is where you come in, because you are inside this system, not watching it. The hijacked machine in the flood could be your smart TV. The reused password is the cheap ammunition that makes the whole stolen-login trade profitable. The news site that goes dark for two hours is your window on a war or an election, closed at the moment it matters most.
Seeing the whole
Security is not a fortress with a single gate. It is a market. The question is never really “can they get in,” because given enough cheapness, someone always can. The question is “is it worth their while.” Every lockout, every second check, every small friction is a bid to make the answer no.
And the strange, humbling part is that the price is shared. When you switch on the second check, you are not building your own wall. You are making the entire trade in stolen passwords a little less profitable, for strangers you will never meet. No single seat sees the whole market. But every seat that raises its price makes the cheap attack a little less cheap for everyone.
03 · Lab · your turn
Price the Attacker Out
Rehearse defense as economics - stack measures to make a cheap attack cost more than it earns, without turning away the real customers.
04 · Hope · carry this
A market answers to price, not to perfect walls. Every second check you switch on makes the whole trade in stolen passwords a little less worth someone's time, for strangers you'll never meet.
More from Cybersecurity