Latest BGP hijack targets hosting software vendor
Guest Post: An analysis of the BGP hijack against Softaculous that enabled an attacker to obtain a fraudulent TLS certificate and distribute a malicious Virtualizor update.
Guest Post: An analysis of the BGP hijack against Softaculous that enabled an attacker to obtain a fraudulent TLS certificate and distribute a malicious Virtualizor update.
Guest Post: Many BGP route leaks flagged by automated systems are short-lived artifacts of normal convergence. Doug Madory draws on Cloudflare Radar, RouteViews, and Jared Mauch’s leak detector to show how these ‘ephemeral leaks’ occur, why they rarely disrupt traffic, and why they still matter for routing security.
Guest Post: Many AS-SETs have grown so large they effectively whitelist most of the routing table, defeating their purpose. How are AS-SETs actually used for filtering, and what can be done when they get too big?
Guest Post: Reviewing the latest RPKI ROV deployment metrics in light of a major milestone.
Guest Post: Investigating the unique manipulation of RPKI used in Orange España’s recent outage.
Guest Post: Investigating the historical impact of undersea landslides on submarine cables.
Guest Post: These attacks hold lessons for securing the BGP routing of any organization that conducts business on the Internet.
Guest Post: Prepending-to-all is a self-inflicted and needless risk that serves little purpose.
Guest Post: A Swiss data centre leaked over 70,000 routes to China Telecom, some for over two hours.
Guest Post: Read how one email to a NOG mailing list led to a concerted effort to kick a notorious BGP hijacker off the Internet.