New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
Canonical (Ubuntu) DDoS
Not great timing in light of the Copy Fail vulnerability but according to their official Twitter account:
Canonical’s web infrastructure is under a sustained, cross-border attack and we are working to address it.
Source: https://x.com/ubuntu/status/2050112955132297652
Not sure if any threat actors have officially claimed responsibility, but feels like a bit of a low blow.

Comments
https://discourse.ubuntu.com/t/update-concerning-ddos-attack-on-canonical-and-ubuntu/81482
Oh shit! Once borders get crossed on the internet you know its fucking serious.
I want to patch my servers, ansible told me, apt-get failed.
Checked, even the bloody ubuntu repo was down.
Bloody cock block.
Mirror? (assuming they updated before the outage)
After this: https://www.omgubuntu.co.uk/2026/04/ubuntu-2604-system-requriments its out of mind using canonical services.
Looks like 313 Team are claiming responsibility: https://www.theregister.com/2026/05/01/canonical_confirms_ubuntu_infrastructure_under/
Why would they target Ubuntu?
Ubuntu is gay...
... well, that and probably because they can.
why target anything?
It seems like a smart way to slow down updates with the Copy Fail exploit out. Gives them more time to break into systems.
You'd be right, but this is an LPE. You'd actually need to break in (or publish some docker image that the reguards on reddit will blindly auto-update with watchtower while pretending they are "self hosting" or something).
When you're from Iran but use the Detroit area code for street cred.
Good news: they appear to have mitigated the DDoS attacks by migrating some of their prefixes behind Cloudflare's "magic transit" (e.g. 185.125.190.0/24.
Less good news: their account on X / Twitter appears to have been hacked...
Original malicious post: https://x.com/i/status/2052211357542453341(with comments turned off due to "suspicious links" 😂).
Screenshot for when it gets taken down:

It looks like it's some sort of scam where you connect your crypto wallet and then they drain it for you:

Everything is.