Daylila

Cybersecurity · Wednesday, 12 August 2026

01 · Briefing · what happened

DDoS floods hit a record, and why the cheapest attacks keep winning

Cybersecurity 3 min 14 sources

Giant traffic floods against news sites surged fivefold, powered by botnets of hijacked devices that cost the attacker almost nothing. Across the week, the pattern held: stolen passwords, known bugs, and cheap floods keep beating the pricey stuff.

805

record floods in one quarter

each over a trillion bits a second, up 519%

14.2%

of all floods hit news sites

the most-targeted sector this year

100M

people exposed by Snowflake

via old stolen passwords, no new hack

97%

credential attacks bypassed MFA

even a second check was defeated

At a glance

  • Cloudflare stopped 805 flooding attacks over 1 trillion bits a second in one quarter, up 519%.
  • News and media sites were the top target - 14.2% of all floods, six times the next sector in spring.
  • The Kimwolf botnet runs on hijacked Android TV boxes, so the attacker's cost is near zero.
  • Its new floods copy Chrome's fingerprint, so cheap filters can't drop them without turning away real readers.
  • The Snowflake hacker pleaded guilty: he just tried old stolen passwords against accounts with no second check.
  • A 2,158-org survey found stolen logins and phishing now beat software flaws as the top way into ransomware.

Forces in play

Cheap floods High

botnets of hijacked home gadgets cost the attacker almost nothing

Stolen-login attacks High

now the top way into ransomware, ahead of software flaws

Known-bug abuse Building

Gunra breaks in through bugs already patched months ago

Cheap defenses Easing

Chrome-mimicking floods slip past the simple drop-the-junk filter

In play Cloudflare — absorbed a record wave of floods, named news sites the top target Kimwolf / Aisuru botnet — rebuilt from hijacked devices to survive takedowns Connor Moucka — pleaded guilty to the Snowflake break-ins via stolen passwords Gunra ransomware gang — breaking in through known, already-patched bugs

How it unfolded

  1. This quarter record 805 floods over a trillion bits a second, up 519%
  2. Since February rebuilt Kimwolf botnet disguises floods as Chrome traffic
  3. Wednesday Snowflake hacker pleads guilty over 100M-person exposure
  4. This week agencies warn Gunra is exploiting known, unpatched bugs

Where this points

Watch whether defenders shift from blocking to cost-shifting - forcing each request to prove itself so the flood gets expensive - now that copying Chrome has beaten the simple filters.

Full briefing

The biggest wave of attacks this quarter did not break a lock. It just made websites too busy to answer.

Cloudflare, one of the largest networks that soaks up junk traffic, says it stopped 805 attacks in three months [1][2]. Each pushed more than a trillion bits a second at its target, a 519% jump over the previous quarter [1][2]. The most-hit target was not banks or hospitals. It was news sites. Media and publishing took 14.2% of all these floods this year, six times the next-most-hit sector in the spring [1].

These floods are “denial-of-service” attacks. Thousands of hijacked computers send a site far more requests than it can handle, so real readers cannot get through [3]. The point is not to steal, but to silence. “For publishers, availability is the deliverable,” Cloudflare’s Blake Darche told The Register [1]. Knocking a news site offline for two hours during a breaking story “silences it at peak readership,” he said, even if it recovers minutes later [1]. The wars in Ukraine and Iran, and the World Cup, all drew floods from online activist groups picking targets on social media [1].

Why the flood is so cheap

These attacks keep growing because of money, or rather how little the attacker spends. A flood runs on other people’s machines. The Kimwolf botnet (also called Aisuru) is built mostly from hijacked Android TV boxes and other cheap internet gadgets [3]. Researchers at Palo Alto Networks found a rebuilt version running since February [3]. The owners of those boxes pay the electricity bill; the attacker pays close to nothing.

Its new trick raises the defender’s cost instead. The latest floods copy the exact fingerprint of the Chrome browser [3][4]. So the usual cheap defense, spotting fake traffic and dropping it, no longer works [3]. A site under attack must either answer every request and fall over, or start turning away real customers it cannot tell apart from the bots [3]. The botnet also moved its control channel onto the Ethereum blockchain to survive police takedowns [3][4]. That came months after authorities seized its old servers and arrested an alleged operator [4].

The same lesson, everywhere this week

Attackers keep choosing the cheapest way in. On Wednesday, Connor Moucka, 26, pleaded guilty to the 2024 Snowflake break-ins [6][7]. Those hit 165 companies and exposed data on at least 100 million people [6][7]. He did not crack Snowflake. He collected old passwords stolen years earlier and tried them against accounts that had no second check [6][7]. He took roughly $495,000 [7]. A survey of 2,158 ransomware-hit organisations found the same shift [5]. Stolen logins and phishing emails have now overtaken software flaws as the top way in [5]. Even accounts with a second login check were beaten in 97% of the credential attacks studied [5].

Even the ransomware gangs pick the cheap door. US and South Korean agencies warned that the Gunra gang breaks in through known, already-patched bugs in internet-facing Fortinet gear [11][12][13]. No expensive new flaw is required. Victims get five to seven days to pay before their data is dumped [11].

Also this week

Microsoft’s monthly patch fixed more than 400 flaws, including one already being used to seize full control of Windows machines [8][9]. The North Carolina Ports Authority spent days recovering after an August 4 attack froze gates at Wilmington and two other terminals [10]. When the systems went dark, the cargo stopped too [10]. Federal defenders also added three more actively-exploited bugs to the must-patch list [14].

02 · Lesson · why it matters

Security is a price, not a wall

You rarely stop an attack by making it impossible - you stop it by making it cost more than it earns.

How it works

  1. An attack is cheap to try at huge scale
  2. So attackers try millions of times for almost nothing
  3. A perfect wall is impossible and expensive
  4. So the defender makes each attempt cost time or money
  5. Once the attempt costs more than it earns, it stops

The twist

You rarely make an attack impossible - you make it not worth the money, by shifting the cost from the defender back onto the attacker.

Where you've seen this

Junk mail

postage costs made mass mailing expensive enough to limit

Shoplifting

tags and cameras raise the effort per item until theft isn't worth it

Login pages

a lockout after five wrong guesses makes trying millions pointless

The catch

Cost-shifting has limits: raise the price too high and you also turn away the real customers you meant to protect.

Full lesson

The flood that broke nothing

The biggest attack wave this quarter did not pick a single lock. It just sent a trillion fake requests a second at news sites until the real readers could not get in. Nothing was stolen. Nothing was cracked. A website was simply made too busy to answer.

That is worth sitting with. We picture hackers as lock-pickers, finding the one clever flaw. But the wave that hit hardest this quarter used no cleverness at all. It used volume. And volume, it turns out, is cheap.

The attacker spends almost nothing

Here is the trick. A flood does not run on the attacker’s own machines. It runs on yours. The botnet behind this wave is built mostly from hijacked smart-TV boxes and cheap internet gadgets sitting in people’s homes. The owners pay the electricity bill. The attacker pays close to nothing and borrows a million machines.

Now look at the other side of the table. To survive that flood, the defender must buy enough capacity to answer every fake request, or find some way to sort the bots from the real visitors. Both cost real money. One side spends pennies; the other spends a fortune. That gap is the whole story.

Cheap at scale beats clever every time

Once you see the gap, you see it everywhere this week. The Snowflake hacker who exposed a hundred million people did not invent anything. He gathered old stolen passwords and tried them against accounts that had no second check. The ransomware gangs are the same. One crew this week broke in through bugs that were already known and already patched months ago. No expensive new flaw. Just the cheapest door left unlocked.

Attackers are shoppers. They do not want the hardest way in. They want the cheapest way that works. When trying a million stolen passwords is free, they try a million passwords. When flooding a site costs nothing, they flood it. The attack you should fear is rarely the cleverest one. It is the one that scales for pennies.

The defender’s real move is a price tag

So if a perfect wall is impossible, what works? You change the math. You make each attempt cost the attacker something.

Lock an account after five wrong guesses, and trying a million passwords stops being free. Add a second check, and a stolen password alone is no longer the whole front door. Make each flood connection prove it is a real browser first, and the flood has to spend time and computing power on every fake request. None of these builds a wall. Each one raises a price. And when the price of attacking climbs past what the attack earns, the attacker walks away and finds a cheaper target.

The same lever can shut out the wrong people

There is a catch, and this week showed it plainly. The new floods copy the exact fingerprint of a real Chrome browser. Now the defender cannot tell the bot from the reader. Raise the price too high, and you also turn away the very people you were protecting. The attacker did not just flood the door. They made honesty itself expensive to check.

This is where you come in, because you are inside this system, not watching it. The hijacked machine in the flood could be your smart TV. The reused password is the cheap ammunition that makes the whole stolen-login trade profitable. The news site that goes dark for two hours is your window on a war or an election, closed at the moment it matters most.

Seeing the whole

Security is not a fortress with a single gate. It is a market. The question is never really “can they get in,” because given enough cheapness, someone always can. The question is “is it worth their while.” Every lockout, every second check, every small friction is a bid to make the answer no.

And the strange, humbling part is that the price is shared. When you switch on the second check, you are not building your own wall. You are making the entire trade in stolen passwords a little less profitable, for strangers you will never meet. No single seat sees the whole market. But every seat that raises its price makes the cheap attack a little less cheap for everyone.

03 · Lab · your turn

Price the Attacker Out

Rehearse defense as economics - stack measures to make a cheap attack cost more than it earns, without turning away the real customers.

04 · Hope · carry this

A market answers to price, not to perfect walls. Every second check you switch on makes the whole trade in stolen passwords a little less worth someone's time, for strangers you'll never meet.

Across the beats