Ubuntu servers taken offline by "sustained, cross-border attack"
RattlesnakeJake
114 points
21 comments
May 01, 2026
Related Discussions
Found 5 related stories in 76.3ms across 8,303 title embeddings via pgvector HNSW
- Pro-Iran crew turns DDoS into shakedown as Ubuntu.com stays down ndsipa_pomu · 79 pts · May 01, 2026 · 63% similar
- Canonical/Ubuntu have been under DDoS jtlebigot · 171 pts · May 01, 2026 · 63% similar
- Canonical Under Attack ta988 · 59 pts · May 02, 2026 · 56% similar
- Why is Cloudflare protecting the DDoS'er (beamed.st) attacking Ubuntu servers? mystraline · 76 pts · May 05, 2026 · 56% similar
- ubuntu.com is down scoops_ · 12 pts · April 30, 2026 · 53% similar
Discussion Highlights (8 comments)
tcp_handshaker
It seems Ubuntu infra is hosted at cloud provider? All have the mechanisms to protect from these types of attacks. Is this an architecure design failure?
scorpioxy
cross-border attack? The internet doesn't have borders. The title of the article has nothing to do with the title submitted here. edit: I should probably add more context as some commenters didn't understand. The DDOS attack is likely coming from compromised IoT devices. Most, if not all, of the big ones in the last few years(decades?) were that. Unless all the devices are located within a specific country and non are within the US then I think it is silly to use that term to imply that this is some sort of war from across the border. The reporting is fine for what they know so far, the submitted title is not.
_DeadFred_
dupe https://news.ycombinator.com/item?id=47975729
tonymet
When asked for ransom terms, the attackers said, “no more systemd”
sdoering
Dupe. More comments here: https://news.ycombinator.com/item?id=47972213
strenholme
Maybe they’re trying to block access to this URL: https://ubuntu.com/security/CVE-2026-31431 To address that, here is how to disable that local root access in Ubuntu 24.04: https://news.ycombinator.com/item?id=47957409
andai
Is this somehow preventing server updates? e.g. to keep the recent vulnerability unpatched for longer? I'm not sure if that makes sense, I think the apt mirrors are all over the place, hosted by universities etc.
aussieguy1234
It's an Iranian state based actor. They're targeting the most popular Linux distro, likely to prevent access to patches for the CopyFail attack so they can use it to do even more damage. (CopyFail allows any unprivileged user to be elevated to root very easily)