<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #DDoS</title><description>Cybersecurity articles tagged #DDoS on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Massive DDoS Disrupts Norway Government Digital Services</title><link>https://runtimerebel.com/blog/massive-ddos-disrupts-norway-government-digital-services</link><guid isPermaLink="true">https://runtimerebel.com/blog/massive-ddos-disrupts-norway-government-digital-services</guid><description>Norway&apos;s Digitalization Agency (Digdir) services, including e-IDs, face ongoing disruptions from a massive DDoS attack. No data breach reported.</description><pubDate>Tue, 25 Aug 2026 16:26:30 GMT</pubDate><category>DDoS</category><category>Service Disruption</category><category>Norway</category><category>Government Services</category><category>Digdir</category></item><item><title>Evooo1Bot Linux Botnet: Beyond DDoS with Exploits &amp; Credential Theft</title><link>https://runtimerebel.com/blog/evooo1bot-linux-botnet-beyond-ddos-with-exploits-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/evooo1bot-linux-botnet-beyond-ddos-with-exploits-credential-theft</guid><description>Evooo1Bot Linux botnet evolves, adding exploitation modules, credential theft, and SOCKS relays, transforming compromised devices into persistent attacker infrastructure.</description><pubDate>Mon, 17 Aug 2026 16:18:57 GMT</pubDate><category>Linux</category><category>Botnet</category><category>DDoS</category><category>Credential Theft</category><category>Evooo1Bot</category></item><item><title>Threema Secure Messaging Service Disrupted by Large-Scale DDoS Attacks</title><link>https://runtimerebel.com/blog/threema-secure-messaging-service-disrupted-by-large-scale-ddos-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/threema-secure-messaging-service-disrupted-by-large-scale-ddos-attacks</guid><description>Threema, a secure messaging service, experienced severe disruptions from large-scale DDoS attacks that continuously changed patterns, challenging mitigation efforts.</description><pubDate>Mon, 17 Aug 2026 08:33:18 GMT</pubDate><category>Threema</category><category>DDoS</category><category>Denial of Service</category><category>Cyberattack</category><category>Network Security</category></item><item><title>Evooo1Bot Linux Botnet Turns Routers Into SOCKS5 Relays</title><link>https://runtimerebel.com/blog/evooo1bot-linux-botnet-turns-routers-into-socks5-relays</link><guid isPermaLink="true">https://runtimerebel.com/blog/evooo1bot-linux-botnet-turns-routers-into-socks5-relays</guid><description>A new Mirai-based modular Linux botnet called Evooo1Bot targets internet routers, turning them into SOCKS5 traffic relay nodes.</description><pubDate>Sat, 15 Aug 2026 16:14:07 GMT</pubDate><category>DDoS</category><category>Credential Theft</category><category>D Link</category><category>TP Link</category><category>Mirai</category></item><item><title>Cloudflare H1 2026 DDoS Trends: Hyper-Volumetric &amp; Geopolitics</title><link>https://runtimerebel.com/blog/cloudflare-h1-2026-ddos-trends-hyper-volumetric-geopolitics</link><guid isPermaLink="true">https://runtimerebel.com/blog/cloudflare-h1-2026-ddos-trends-hyper-volumetric-geopolitics</guid><description>Cloudflare&apos;s H1 2026 DDoS Threat Report reveals a significant surge in hyper-volumetric attacks, DNS floods, and geopolitical influence.</description><pubDate>Tue, 11 Aug 2026 16:53:44 GMT</pubDate><category>DDoS</category><category>Cloudflare</category><category>Threat Report</category><category>Geopolitics</category><category>Cyberattack</category></item><item><title>Kimwolf v7 Botnet Evolves with Advanced DDoS and C2 Resilience</title><link>https://runtimerebel.com/blog/kimwolf-v7-botnet-evolves-with-advanced-ddos-and-c2-resilience</link><guid isPermaLink="true">https://runtimerebel.com/blog/kimwolf-v7-botnet-evolves-with-advanced-ddos-and-c2-resilience</guid><description>Kimwolf v7, an Android/IoT botnet, enhances DDoS capabilities with HTTP/2 fingerprinting and robust, multi-layered C2 infrastructure.</description><pubDate>Tue, 11 Aug 2026 16:52:19 GMT</pubDate><category>Kimwolf</category><category>Botnet</category><category>Android</category><category>DDoS</category><category>IoT</category></item><item><title>TuxBot v3: LLM-Assisted IoT Botnet Framework Analysis</title><link>https://runtimerebel.com/blog/tuxbot-v3-llm-assisted-iot-botnet-framework-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/tuxbot-v3-llm-assisted-iot-botnet-framework-analysis</guid><description>Analysis of TuxBot v3 Evolution, a modular IoT botnet framework developed with LLM assistance, leveraging Telnet brute-force and C2 for DDoS.</description><pubDate>Sat, 08 Aug 2026 16:26:55 GMT</pubDate><category>IoT Botnet</category><category>DDoS</category><category>LLM</category><category>TuxBot V3</category><category>Keksec</category></item><item><title>Tengu Botnet Exploits Linux Watchdog for Reboot-Based Persistence</title><link>https://runtimerebel.com/blog/tengu-botnet-exploits-linux-watchdog-for-reboot-based-persistence</link><guid isPermaLink="true">https://runtimerebel.com/blog/tengu-botnet-exploits-linux-watchdog-for-reboot-based-persistence</guid><description>The Mirai-derived Tengu botnet utilizes hardware watchdog timers to trigger reboots when its process is terminated, ensuring persistence on Linux devices.</description><pubDate>Tue, 28 Jul 2026 17:36:22 GMT</pubDate><category>Tengu</category><category>Mirai</category><category>Linux Botnet</category><category>Iot Security</category><category>DDoS</category></item><item><title>Dysphoria Botnet: 200K Devices Engaged in DDoS and Traffic Relay</title><link>https://runtimerebel.com/blog/dysphoria-botnet-200k-devices-engaged-in-ddos-and-traffic-relay</link><guid isPermaLink="true">https://runtimerebel.com/blog/dysphoria-botnet-200k-devices-engaged-in-ddos-and-traffic-relay</guid><description>Analysis of the Dysphoria DDoS botnet, which has compromised 200,000 devices globally for denial-of-service attacks and traffic relay operations. Learn mitigation.</description><pubDate>Mon, 27 Jul 2026 21:12:36 GMT</pubDate><category>Dysphoria</category><category>Botnet</category><category>DDoS</category><category>Traffic Relay</category><category>Malware</category></item><item><title>Dysphoria Botnet Adopts Blockchain C2 for Enhanced IoT Resilience</title><link>https://runtimerebel.com/blog/dysphoria-botnet-adopts-blockchain-c2-for-enhanced-iot-resilience</link><guid isPermaLink="true">https://runtimerebel.com/blog/dysphoria-botnet-adopts-blockchain-c2-for-enhanced-iot-resilience</guid><description>Dysphoria IoT botnet evolves with blockchain-based C2 and victim relays after JackSkid disruption, posing new challenges for defenders.</description><pubDate>Mon, 27 Jul 2026 21:12:09 GMT</pubDate><category>Dysphoria</category><category>IoT Botnet</category><category>Blockchain C2</category><category>JackSkid</category><category>DDoS</category><category>Command and Control</category></item><item><title>GeoServer CVE-2024-36401 Exploit: Rondo Botnet Mitigation Guide</title><link>https://runtimerebel.com/blog/geoserver-cve-2024-36401-exploit-rondo-botnet-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/geoserver-cve-2024-36401-exploit-rondo-botnet-mitigation-guide</guid><description>Analysis of active Rondo botnet campaigns exploiting CVE-2024-36401 in GeoServer. Learn to detect unauthenticated RCE and protect your infrastructure.</description><pubDate>Thu, 23 Jul 2026 10:28:43 GMT</pubDate><category>CVE-2024-36401</category><category>GeoServer</category><category>Rondo Botnet</category><category>RCE</category><category>DDoS</category></item><item><title>SSDP Reflection Attacks: How to Secure Port 1900 Against DDoS</title><link>https://runtimerebel.com/blog/ssdp-reflection-attacks-how-to-secure-port-1900-against-ddos</link><guid isPermaLink="true">https://runtimerebel.com/blog/ssdp-reflection-attacks-how-to-secure-port-1900-against-ddos</guid><description>Analyze the risks of SSDP reflection attacks and how misconfigured Simple Service Discovery Protocol services on port 1900 facilitate high-volume DDoS campaigns.</description><pubDate>Thu, 23 Jul 2026 10:28:23 GMT</pubDate><category>SSDP</category><category>DDoS</category><category>UPnP</category><category>Reflection Attack</category><category>Network Security</category></item><item><title>HollowByte DDoS: OpenSSL Memory Exhaustion via 11-byte Payload</title><link>https://runtimerebel.com/blog/hollowbyte-ddos-openssl-memory-exhaustion-via-11-byte-payload</link><guid isPermaLink="true">https://runtimerebel.com/blog/hollowbyte-ddos-openssl-memory-exhaustion-via-11-byte-payload</guid><description>HollowByte enables unauthenticated DoS on OpenSSL servers, depleting memory with an 11-byte payload. Understand the impact and mitigation.</description><pubDate>Fri, 17 Jul 2026 20:58:33 GMT</pubDate><category>HollowByte</category><category>DDoS</category><category>OpenSSL</category><category>DoS</category><category>Memory Exhaustion</category></item><item><title>C0XMO Botnet Targets DD-WRT Router Firmware — Analysis and Mitigation</title><link>https://runtimerebel.com/blog/c0xmo-botnet-targets-dd-wrt-router-firmware-analysis-and-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/c0xmo-botnet-targets-dd-wrt-router-firmware-analysis-and-mitigation</guid><description>C0XMO, a Gafgyt-based botnet, exploits DD-WRT router vulnerabilities to launch DDoS attacks and eliminate rival malware on infected IoT devices.</description><pubDate>Sun, 07 Jun 2026 16:34:52 GMT</pubDate><category>C0XMO</category><category>Gafgyt</category><category>DD WRT</category><category>Iot Security</category><category>DDoS</category><category>Botnet</category></item><item><title>AI-Powered DDoS Attacks: Emerging Tactics and Defensive Strategies</title><link>https://runtimerebel.com/blog/ai-powered-ddos-attacks-emerging-tactics-and-defensive-strategies</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-powered-ddos-attacks-emerging-tactics-and-defensive-strategies</guid><description>Threat actors are leveraging artificial intelligence to automate DDoS attacks, increasing speed and evasion capabilities against traditional network defenses.</description><pubDate>Tue, 26 May 2026 13:09:46 GMT</pubDate><category>DDoS</category><category>Artificial Intelligence</category><category>Botnets</category><category>Automation</category><category>Network Security</category></item><item><title>US and Canada Charge Suspected KimWolf Botnet Operator</title><link>https://runtimerebel.com/blog/us-and-canada-charge-suspected-kimwolf-botnet-operator</link><guid isPermaLink="true">https://runtimerebel.com/blog/us-and-canada-charge-suspected-kimwolf-botnet-operator</guid><description>Authorities dismantle the KimWolf botnet following the arrest of a Canadian national linked to nearly two million global device infections and DDoS attacks.</description><pubDate>Fri, 22 May 2026 09:15:50 GMT</pubDate><category>Kimwolf</category><category>Botnet</category><category>DDoS</category><category>Law Enforcement</category><category>Matthew Filion</category></item><item><title>Kimwolf Botmaster Arrested: Impacts on IoT Botnet DDoS Mitigation</title><link>https://runtimerebel.com/blog/kimwolf-botmaster-arrested-impacts-on-iot-botnet-ddos-mitigation</link><guid isPermaLink="true">https://runtimerebel.com/blog/kimwolf-botmaster-arrested-impacts-on-iot-botnet-ddos-mitigation</guid><description>Canadian and U.S. authorities arrest the alleged operator of the massive Kimwolf IoT botnet, linked to millions of compromised devices and disruptive DDoS attacks.</description><pubDate>Fri, 22 May 2026 00:56:39 GMT</pubDate><category>Kimwolf</category><category>Botnet</category><category>Iot Security</category><category>DDoS</category><category>Cyber Arrest</category></item><item><title>Bot Mitigation with CAPTCHAs: Understanding Cloudflare Turnstile</title><link>https://runtimerebel.com/blog/bot-mitigation-with-captchas-understanding-cloudflare-turnstile</link><guid isPermaLink="true">https://runtimerebel.com/blog/bot-mitigation-with-captchas-understanding-cloudflare-turnstile</guid><description>Understand how Cloudflare Turnstile and other CAPTCHAs mitigate bot traffic, improve web performance, and enhance security against automated attacks.</description><pubDate>Mon, 11 May 2026 17:02:53 GMT</pubDate><category>Bot Mitigation</category><category>CAPTCHA</category><category>Cloudflare Turnstile</category><category>Web Security</category><category>Automated Attacks</category><category>DDoS</category></item><item><title>Infolink Anti-DDoS Provider Linked to Brazilian ISP Botnet Attacks</title><link>https://runtimerebel.com/blog/infolink-anti-ddos-provider-linked-to-brazilian-isp-botnet-attacks</link><guid isPermaLink="true">https://runtimerebel.com/blog/infolink-anti-ddos-provider-linked-to-brazilian-isp-botnet-attacks</guid><description>An investigation reveals Brazilian anti-DDoS firm Infolink facilitated massive DDoS attacks against regional ISPs, highlighting critical provider trust risks.</description><pubDate>Thu, 30 Apr 2026 16:39:25 GMT</pubDate><category>DDoS</category><category>Brazil</category><category>Infolink</category><category>ISP Security</category><category>Network Abuse</category><category>Botnet</category></item><item><title>Mastodon DDoS Attack: Mitigating Availability Threats on Fediverse</title><link>https://runtimerebel.com/blog/mastodon-ddos-attack-mitigating-availability-threats-on-fediverse</link><guid isPermaLink="true">https://runtimerebel.com/blog/mastodon-ddos-attack-mitigating-availability-threats-on-fediverse</guid><description>Analysis of recent DDoS attacks targeting Mastodon and Bluesky. Understand the impact on distributed social platforms and effective mitigation strategies.</description><pubDate>Wed, 22 Apr 2026 20:26:02 GMT</pubDate><category>DDoS</category><category>Mastodon</category><category>Bluesky</category><category>Fediverse</category><category>Availability</category><category>Cyberattack</category></item><item><title>CVE-2025-29635: Mirai Exploits EoL D-Link Routers</title><link>https://runtimerebel.com/blog/cve-2025-29635-mirai-exploits-eol-d-link-routers</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-29635-mirai-exploits-eol-d-link-routers</guid><description>A new Mirai campaign actively exploits CVE-2025-29635, a command-injection RCE in EoL D-Link DIR-823X routers, to expand its IoT botnet for DDoS attacks.</description><pubDate>Wed, 22 Apr 2026 20:25:12 GMT</pubDate><category>Mirai</category><category>D Link DIR 823X</category><category>CVE-2025-29635</category><category>IoT Botnet</category><category>RCE</category><category>Command Injection</category><category>DDoS</category></item><item><title>Nexcorium Mirai Variant Exploits CVE-2024-3721 in TBK DVR Botnet</title><link>https://runtimerebel.com/blog/nexcorium-mirai-variant-exploits-cve-2024-3721-in-tbk-dvr-botnet</link><guid isPermaLink="true">https://runtimerebel.com/blog/nexcorium-mirai-variant-exploits-cve-2024-3721-in-tbk-dvr-botnet</guid><description>Security researchers identify Nexcorium, a new Mirai variant targeting TBK DVRs and EoL TP-Link routers via CVE-2024-3721 for large-scale DDoS attacks.</description><pubDate>Sat, 18 Apr 2026 08:19:28 GMT</pubDate><category>Nexcorium</category><category>Mirai</category><category>CVE-2024-3721</category><category>TBK DVR</category><category>IoT</category><category>DDoS</category></item><item><title>Compromised DVRs: Identifying and Mitigating IoT Botnet Threats</title><link>https://runtimerebel.com/blog/compromised-dvrs-identifying-and-mitigating-iot-botnet-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/compromised-dvrs-identifying-and-mitigating-iot-botnet-threats</guid><description>Explore how Digital Video Recorders (DVRs) are compromised and incorporated into IoT botnets.</description><pubDate>Thu, 16 Apr 2026 00:48:59 GMT</pubDate><category>DVR</category><category>Iot Security</category><category>Botnet</category><category>Shodan</category><category>Compromise</category><category>DDoS</category></item><item><title>Masjesu Botnet DDoS-for-Hire: Analysis of IoT Malware Campaigns</title><link>https://runtimerebel.com/blog/masjesu-botnet-ddos-for-hire-analysis-of-iot-malware-campaigns</link><guid isPermaLink="true">https://runtimerebel.com/blog/masjesu-botnet-ddos-for-hire-analysis-of-iot-malware-campaigns</guid><description>The Masjesu botnet targets IoT devices across multiple architectures to facilitate DDoS-for-hire services via Telegram, posing risks to global infrastructure.</description><pubDate>Wed, 08 Apr 2026 20:18:14 GMT</pubDate><category>Masjesu Botnet</category><category>DDoS</category><category>Iot Security</category><category>Malware Analysis</category><category>Telegram Botnet</category></item><item><title>Global Law Enforcement Action Disrupts Major IoT DDoS Botnets</title><link>https://runtimerebel.com/blog/global-law-enforcement-action-disrupts-major-iot-ddos-botnets</link><guid isPermaLink="true">https://runtimerebel.com/blog/global-law-enforcement-action-disrupts-major-iot-ddos-botnets</guid><description>Authorities from the US, Germany, and Canada dismantled C2 infrastructure for the Aisuru, KimWolf, JackSkid, and Mossad botnets used in global DDoS attacks.</description><pubDate>Fri, 20 Mar 2026 08:17:53 GMT</pubDate><category>AISURU</category><category>Kimwolf</category><category>JackSkid</category><category>Mossad</category><category>IoT</category><category>DDoS</category><category>Botnet</category></item><item><title>DOJ Disrupts Aisuru, Kimwolf, JackSkid, and Mossad IoT Botnets</title><link>https://runtimerebel.com/blog/doj-disrupts-aisuru-kimwolf-jackskid-and-mossad-iot-botnets</link><guid isPermaLink="true">https://runtimerebel.com/blog/doj-disrupts-aisuru-kimwolf-jackskid-and-mossad-iot-botnets</guid><description>Federal authorities dismantle infrastructure for four major IoT botnets controlling 3 million devices used in record-breaking DDoS attacks worldwide.</description><pubDate>Fri, 20 Mar 2026 04:38:34 GMT</pubDate><category>AISURU</category><category>Kimwolf</category><category>JackSkid</category><category>Mossad</category><category>DDoS</category><category>Iot Security</category><category>Botnet Disruption</category></item><item><title>Hacktivist DDoS Surge: Keymous+ and DieNet Target Middle East</title><link>https://runtimerebel.com/blog/hacktivist-ddos-surge-keymous-and-dienet-target-middle-east</link><guid isPermaLink="true">https://runtimerebel.com/blog/hacktivist-ddos-surge-keymous-and-dienet-target-middle-east</guid><description>Post-conflict, hacktivist groups Keymous+ and DieNet launched 149 DDoS attacks against 110 organizations across 16 countries in the Middle East.</description><pubDate>Wed, 04 Mar 2026 20:13:44 GMT</pubDate><category>Hacktivism</category><category>DDoS</category><category>Keymous</category><category>DieNet</category><category>Middle East Conflict</category><category>Cyber Warfare</category></item><item><title>Analysis of the Kimwolf Botnet and Threat Actor &apos;Dort&apos;</title><link>https://runtimerebel.com/blog/analysis-of-the-kimwolf-botnet-and-threat-actor-dort</link><guid isPermaLink="true">https://runtimerebel.com/blog/analysis-of-the-kimwolf-botnet-and-threat-actor-dort</guid><description>An analysis of the Kimwolf botnet operator &apos;Dort&apos;, including retaliatory TTPs like DDoS, swatting, and the exploitation of undisclosed vulnerabilities.</description><pubDate>Sat, 28 Feb 2026 12:12:58 GMT</pubDate><category>Kimwolf</category><category>Dort</category><category>Botnet</category><category>DDoS</category><category>Swatting</category><category>Threat Actor Profile</category></item><item><title>Spanish Authorities Dismantle Anonymous Fénix Hacktivist Node</title><link>https://runtimerebel.com/blog/spanish-authorities-dismantle-anonymous-fenix-hacktivist-node</link><guid isPermaLink="true">https://runtimerebel.com/blog/spanish-authorities-dismantle-anonymous-fenix-hacktivist-node</guid><description>Spain&apos;s National Police arrested four members of Anonymous Fénix, a hacktivist group targeting government infrastructure with DDoS and data exfiltration.</description><pubDate>Tue, 24 Feb 2026 12:24:21 GMT</pubDate><category>Anonymous F U00e9nix</category><category>Spain</category><category>Hacktivism</category><category>DDoS</category><category>Law Enforcement</category><category>Data Theft</category></item><item><title>Spanish Police Disrupt Anonymous Sudan Hacktivist DDoS Operations</title><link>https://runtimerebel.com/blog/spanish-police-disrupt-anonymous-sudan-hacktivist-ddos-operations</link><guid isPermaLink="true">https://runtimerebel.com/blog/spanish-police-disrupt-anonymous-sudan-hacktivist-ddos-operations</guid><description>Spanish authorities arrest three individuals linked to the Anonymous Sudan hacktivist group for executing DDoS attacks against government and critical infrastructure.</description><pubDate>Tue, 24 Feb 2026 08:20:53 GMT</pubDate><category>Anonymous Sudan</category><category>DDoS</category><category>Spain</category><category>Hacktivism</category><category>Law Enforcement</category><category>Cybercrime</category></item><item><title>Technical Analysis: Multi-Vector Threats Spanning Web Skimming, AI Prompt Injection, and Volumetric DDoS</title><link>https://runtimerebel.com/blog/technical-analysis-multi-vector-threats-spanning-web-skimming-ai-prompt-injection-and-volumetric-ddos</link><guid isPermaLink="true">https://runtimerebel.com/blog/technical-analysis-multi-vector-threats-spanning-web-skimming-ai-prompt-injection-and-volumetric-ddos</guid><description>A deep dive into redundant Magecart exfiltration techniques, PromptSpy AI exploitation frameworks, and the escalation of 30Tbps volumetric DDoS attacks.</description><pubDate>Mon, 23 Feb 2026 16:23:32 GMT</pubDate><category>DDoS</category><category>Magecart</category><category>Container Security</category><category>AI Security</category><category>Botnets</category></item><item><title>Kimwolf Botnet Integration Impairs I2P Network Infrastructure</title><link>https://runtimerebel.com/blog/kimwolf-botnet-integration-impairs-i2p-network-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/kimwolf-botnet-integration-impairs-i2p-network-infrastructure</guid><description>The Kimwolf IoT botnet has weaponized the Invisible Internet Project (I2P) to harden its C2 infrastructure, leading to widespread peer instability and network-wide…</description><pubDate>Mon, 23 Feb 2026 08:21:39 GMT</pubDate><category>IoT</category><category>Botnet</category><category>I2P</category><category>C2</category><category>DDoS</category><category>Anonymization</category></item></channel></rss>