SECURITYTHE REGISTER
OpenAI's agent chained decade-old DoS attacks to crash web servers in seconds
OpenAI's Codex agent discovered a new denial-of-service (DoS) attack named HTTP/2 Bomb, which combines two decade-old techniques to crash vulnerable web servers in seconds. The exploit affects default HTTP/2 configurations on servers like nginx, Apache, and Microsoft IIS, with some vendors having released patches while others dispute the findings.
Mentioned
Related Signal
Adjacent reporting
- New 'HTTP/2 Bomb' DoS attack crashes web servers in under a minute
- New HTTP/2 Bomb Vulnerability Allows Remote DoS on NGINX, Apache, IIS, Envoy & Cloudflare
- NGINX Rift attackers waste no time targeting exposed servers
- Microsoft warns of Exchange zero-day flaw exploited in attacks
- Ubuntu services hit by outages after DDoS attack
- Ivanti warns of new EPMM flaw exploited in zero-day attacks