网络服务商Nine.ch于2026年8月11日晚遭遇规模达500-600 Gbit/s的分布式拒绝服务攻击,其中上游提供商确认的流量峰值为260 Gbit/s1。攻击初期针对Nine的某客户,随后在三小时内转向Nine本身的基础设施1。攻击方采用UDP放大技术,利用CECbot和Katana两个僵尸网络家族发动攻击1,持续约42小时,分波次进行,于8月11日晚约19:15开始,至8月13日午12:51结束1。
此次攻击导致Deploio、官方网站、Cockpit及工单系统等多项关键服务中断1。Nine采取了黑洞路由和CDN防护等应急措施予以应对,并在攻击发起一天后启动应用迁移至bunny.net CDN的工作,次日完成迁移1。Nine确认攻击期间未发生未授权访问或系统被攻陷的情况,本次事件属纯属过载性质的攻击1。值得注意的是,首波攻击用时约90分钟才得到人工控制1。
事后调查中,Nine识别并修复了三个主要防御漏洞1。Nine建议同类服务商使用CNAME/ALIAS记录而非A记录,并在应用前置CDN防护1。
A devastating distributed denial-of-service attack targeting Swiss hosting provider Nine.ch struck on the evening of August 11, 2026, with traffic volumes reaching 500–600 Gigabits per second according to the company's assessment, though upstream providers confirmed 260 Gigabits per second 1. The assault initially focused on one of Nine's customers before shifting to Nine's core infrastructure within three hours, persisting across multiple waves for approximately 42 hours until August 13 at 12:51 PM 1.
The attackers deployed UDP amplification techniques, leveraging the CECbot and Katana botnet families to bombard Nine's network 1. The company required roughly 90 minutes before manual intervention brought the first phase under control 1. The onslaught disrupted multiple critical services including Deploio, the corporate website, Cockpit, and the ticketing system 1. Despite the severity of the assault, Nine confirmed that no unauthorized access occurred and no systems were compromised—the attack remained purely a capacity-overwhelming operation 1.
Nine began mitigating the damage by migrating applications to bunny.net's content delivery network starting one day into the attack, completing the migration the following day 1. This shift, combined with blackhole routing and additional CDN protections, gradually restored service availability 1. Following the incident, Nine identified and remedied three significant defensive gaps in its infrastructure 1. The company subsequently recommended that customers adopt CNAME or ALIAS records instead of direct A records and deploy CDN protection ahead of their applications 1.
评论
还没有评论,欢迎留下第一条。