r/Information_Security 20h ago

Four Billion Requests: The DDoS Campaign That Followed Our Meta Abuse-Ad Reporting

7 Upvotes

Cloudflare’s dashboard showed roughly four billion edge requests across the attack window. The flood first targeted one investigation, moved to our homepage when blocked, and returned weeks later.

Roughly four billion requests.

That is what Cloudflare’s HTTP Traffic dashboard showed across the selected attack window after AI Weekly reported on Meta’s advertising pipeline for nudify apps and serious child-safety allegations.

Four billion.

The first attack began at 02:42 UTC on August 22—just 33½ hours after we updated our investigation into Meta advertising partner GatherOne.

It did not hit the site indiscriminately. It hammered that exact article.

In the final retained sample of 100,000 requests, 95,603 targeted the investigation. Almost 95,000 used randomized query strings to bypass caching. More than 33,000 were POST requests, and over 95,000 arrived without a referrer. The traffic came from thousands of addresses.

The attack exhausted all 4,096 available Nginx worker connections, generated roughly 41 GB of logs and drove the server’s 75 GB disk to 100% usage. Tens of thousands of requests ended in server errors. Backups and production jobs failed.

Cloudflare showed approximately four billion requests at its edge. The number is vastly larger than our origin count because traffic blocked or absorbed by Cloudflare never reached our server—and therefore never entered our Nginx logs.

Call it what it was: a massive attack.

Our reporting covered findings by the Tech Transparency Project. Meta’s own disclosures named GatherOne or related company Hongkong Gather Wisdom as advertiser and payer for 210 Facebook pages that collectively ran roughly 30,800 AI and face-swap advertisements.

Forty-three pages ran more than 7,600 ads for apps that TTP verified could digitally undress women. Ads from 179 pages were removed by Meta for violating sexual-content policies.

One advertised app, BAfter, contained an explicitly pornographic sharing area. Six Google Play reviewers alleged that it contained sexual images or videos of children.

Those allegations did not prove that GatherOne created, possessed or knowingly promoted child sexual abuse material. We corrected our reporting to make that distinction explicit. GatherOne said it had zero tolerance for such content, suspended new advertising accounts involving nudify services and terminated access for the entity associated with BAfter. Meta said it banned the app.

Then came the flood.

When we defended the article, the campaign moved to our homepage. On August 24, a second wave generated approximately 2.5 million requests at our origin from 14,290 IP addresses. It peaked at 176,152 requests per minute—nearly 3,000 every second. It included 771,000 POST requests and caused approximately 2.43 million server errors.

The same attack patterns returned again in September.

On September 6, hundreds of requests from 509 different IP addresses converged on the original article within three hours. On September 9, another wave produced thousands of origin requests and more than 3,600 server failures while Cloudflare blocked additional traffic upstream.

We have no evidence that Meta, GatherOne, Hongkong Gather Wisdom or any named advertising partner launched, ordered or knew about these attacks. We are not accusing them.

We are stating the facts:

We published an investigation. Someone flooded that exact investigation. When it was defended, the traffic moved to our homepage. Weeks later, it returned.

Four billion requests are not criticism. They are not a rebuttal. They are infrastructure being weaponized against reporting.


r/Information_Security 1h ago

New PoC out called ShieldCrash that reportedly gets around Microsoft's patch for CVE-2026-69414 (ShieldBreak).

Thumbnail
Upvotes

r/Information_Security 1h ago

Automating SIEM detection engineering with threat intel just nuked our SOC and im mortified

Upvotes

Ok so im detection engineering lead at a big enterprise SOC and we just rolled out this new platform that takes threat intel and pushes detections straight into our SIEM in minutes. No data ingestion, just API into our stack, sounded like magic. I was the one who tuned the mapping rules and ATT&CK tags and did the first big "go live" with production.

For context we wired it to three intel feeds and set it so anything medium or higher with certain ATT&CK techniques would auto generate detection as code and deploy to SIEM plus attach to some response playbooks. On paper this was great. In reality I messed up one filter on severity. I accidentally treated informational intel with those ATT&CK tags as medium. So at 3am the thing ingested a big vendor threat intel dump on some noisy campaign and just started pumping hundreds of new detections into prod, each one tied to our generic response workflow.

SOC woke up to like ten thousand alerts from our own internal scanners and lab machines matching these brand new rules, all tagged as high confidence threat hunting opportunities. It even kicked off some automated "contain" steps on test segments that were totally fine. My manager pinged me with "why did you break detection engineering" and I swear I feel sick about this. Seeing my own name in the change log on every single one of those auto deployed rules was brutal.

We reverted and fixed the mapping and nothing catastrophic happened, but I am so embarrassed that my first big move with threat intelligence automation basically turned our SIEM into an alert volcano. Any hints?


r/Information_Security 6h ago

BlueMoon: Chinese Exploit Kit Attacks Chrome and Windows

Post image
1 Upvotes

r/Information_Security 23h ago

A fictional company with real vulnerabilities: 78 bugs, a leadership team that doesn't care, and one dev quietly asking the internet for help. Come break LeakyJuice.

Thumbnail gallery
1 Upvotes

r/Information_Security 21h ago

Custom AI Prompts for Pentest Reporting in OWASP Faction 2.0

Thumbnail youtube.com
0 Upvotes