A Brazilian cybersecurity firm specializing in DDoS protection has allegedly been enabling a botnet responsible for massive attacks against other Brazilian network operators, according to KrebsOnSecurity.
The anti-DDoS company's infrastructure was used to launch an extended campaign of distributed denial-of-service attacks targeting competing ISPs and network operators in Brazil.
The firm's CEO attributed the malicious activity to a security breach, claiming a competitor orchestrated the attacks to damage the company's reputation.
DDos attacks overwhelm networks by flooding them with traffic from multiple sources, rendering services unavailable. The fact that a firm built to defend against such attacks became a vector for them raises questions about the company's internal security practices.
KrebsOnSecurity's investigation uncovered the connection between the firm's systems and the botnet infrastructure. The disclosure highlights risks inherent when security-focused companies themselves become compromised, potentially turning them into weapons against their own industry peers.
The incident underscores the importance of robust internal security measures, even—or especially—for firms whose business depends on protecting others from cyber threats.
Manchester Airports Group disclosed a breach affecting Manchester, Stansted, and East Midlands airports. Hackers accessed data from approximately 8.7 million customers.
A lawsuit alleges that Elon Musk's xAI trained its Grok language models using child sexual abuse material, including both real and AI-generated imagery.
The ShinyHunters extortion group has published sensitive data from nearly 13 million Carhartt customer accounts stolen earlier this month, according to data breach notification service Have I Been Pwned.
A Russian-speaking ransomware gang called Aur0ra exploited SpaceX's Cursor AI coding assistant to breach at least seven companies between mid-April and late May, according to security firm Gambit Security.