October 10, 2023 at 10:13AM – New ‘HTTP/2 Rapid Reset’ zero-day attack breaks DDoS records

A new DDoS technique named ‘HTTP/2 Rapid Reset’ has been actively exploited as a zero-day since August, breaking all previous records in magnitude. Amazon Web Services, Cloudflare, and Google report mitigating attacks reaching 155 million requests per second (Amazon) and 201 million rps (Cloudflare). Cloudflare has detected over a thousand attacks using this technique, which exceeds their previous record. The attack exploits a zero-day vulnerability in the HTTP/2 protocol, overwhelming the target server/application and imposing a DoS state. Cloudflare recommends using HTTP-flood protection tools and bolstering DDoS resilience to counter this type of attack.


