incident

Amazon Caught North Korean IT Worker By Tracing Keystroke Data

Amazon’s Chief Security Officer, Stephen Schmidt, revealed that the company thwarted over 1,800 attempts by North Korean impostors to gain employment since April 2024. These impostors, often hired by contractors, aim to raise funds for the DPRK, including its weapons programs. Schmidt emphasized the importance of thorough background checks and advanced security software to detect such fraudulent activities.

https://www.bloomberg.com/news/newsletters/2025-12-17/amazon-caught-north-korean-it-worker-by-tracing-keystroke-data

Cloudflare Outage on December 5, 2025

Cloudflare experienced a service outage on December 5, 2025, from 08:47 to 09:12 UTC, affecting 28% of HTTP traffic due to internal changes while addressing a security vulnerability in React. The incident was not caused by a cyber attack. The issue arose from configuration changes that led to HTTP 500 errors, impacting customers using specific setups with the older FL1 proxy. Cloudflare is implementing measures to prevent future incidents, including enhanced rollout protocols and improved error handling. An apology was issued acknowledging the disruption caused.

https://blog.cloudflare.com/5-december-2025-outage/

Cloudflare Blames Today’s Outage on Emergency React2Shell Patch

Cloudflare's recent outage was caused by emergency mitigations for a critical vulnerability (CVE-2025-55182) in React Server Components, allowing unauthorized remote code execution. The incident affected about 28% of Cloudflare's HTTP traffic but was not due to a cyber attack. The flaw is being actively exploited by hacking groups, primarily linked to China.

https://www.bleepingcomputer.com/news/security/cloudflare-blames-todays-outage-on-emergency-react2shell-patch/

Cloudflare Outage on November 18, 2025

On November 18, 2025, Cloudflare experienced a significant outage affecting core network traffic after a database permission change caused a feature file to double in size, leading to system failures. Initial suspicions of a DDoS attack were disproved as the issue was traced to bad configurations propagated throughout the network. The outage, which resulted in numerous HTTP 5xx error codes and impacted various services, was resolved by reverting to a stable configuration and restarting core proxies. Cloudflare acknowledged the unacceptable nature of the incident and committed to implementing measures to prevent future occurrences.

https://blog.cloudflare.com/18-november-2025-outage/

A Single DNS Race Condition Brought AWS to Its Knees

A race condition in Amazon's DynamoDB DNS management caused a major outage, disrupting services and estimated damage in the hundreds of billions. The error began on October 19, 2025, when the system left an empty DNS record due to a timing conflict between DNS planners and enactors. This led to widespread failures, impacting EC2 launches and other AWS services. Amazon has suspended the affected automation until fixes are implemented.

https://www.theregister.com/2025/10/23/amazon_outage_postmortem/

Summary of the Amazon DynamoDB Service Disruption in the Northern Virginia (US-EAST-1) Region

DynamoDB Incident Summary (Oct 19-20, 2025): Service disruption occurred in N. Virginia (us-east-1) due to DNS failures affecting API, EC2, NLB, and other services. Latent defect in DNS management led to failed connections and increased errors across multiple AWS services. Recovery actions taken included engineering interventions and system restarts, with full services restored by Oct 20. Improvements planned to prevent recurrence and enhance reliability.

https://aws.amazon.com/message/101925/

F5 Security Incident

F5 reported a security incident involving a nation-state threat actor accessing and exfiltrating files from their BIG-IP product development environment in August 2025. They confirmed some BIG-IP source code was taken, but no critical vulnerabilities were disclosed or exploited. F5 is updating their software, engaging cybersecurity experts, and implementing security measures. They advise customers to update systems, enhance monitoring, and utilize available resources to strengthen security. Ongoing efforts aim to improve the overall security posture and regain customer trust.

https://my.f5.com/manage/s/article/K000154696

Scroll to Top