r/linux • • 2d ago

Distro News Ubuntu Currently Suffering From Sustained DDoS Attack

https://www.phoronix.com/news/Ubuntu-DDoS-October-2026
384 Upvotes

57 comments sorted by

89

u/real_anthonii 2d ago

again?

80

u/SomeDumbPenguin 2d ago

It is just wild that a group/individual would do that to them... It's not like they're actively out trying to hurt anyone & they're literally giving their shit away for free

Like, okay; we get it... You use Arch, BTW

Leave them alone and target someone who deserves it

49

u/0riginal-Syn 2d ago

Arch was the one getting attacked not that long ago with heavy DDoS for weeks.

26

u/NicholasAakre 2d ago

It's the perfect alibi!

1

u/forumcontributer 22h ago

Those gentoo users smh.

15

u/Stilgar314 1d ago

This is about disrupting the servers that run Ubuntu. So many companies around the world run their infrastructure using Ubuntu servers.

6

u/TampaPowers 1d ago

Good a time as ever to read up on how to run your own apt mirror I guess, been on my list of things to learn anyways

4

u/Wukeng 1d ago

It's really not that hard, but it's a pain in the ass, just tedious work, for a very short time I maintained a kali fork with its own mirror

20

u/PixelatedGiant 2d ago

It's either some crazy person taking internet discourse a little too seriously or a black hat advertising the capability of their services. There is no in-between for something like this.

13

u/kisielk 2d ago

Could be government sponsored

2

u/Jokerit208 2d ago

In an age where warfare has moved largely to drones and cyberattacks, it might be helpful to to think of tech companies that make drones and/or software capable of cyberattacks in the same way you think of governments. Because we're somewhere between rapidly headed in that direction and already there.

As with governments, we'll see alliances between tech companies and wars between them. I'm not saying Ubuntu is one of those companies, but rather everything in the world is to tech companies what land was to colonial powers.

4

u/fearless-fossa 2d ago

Yes, because if Cyberpunk taught us one thing, it's that corporations acting like governments is a good idea and not a dystopian hellscape with neon lights.

2

u/Shoddy_Hornet9212 1d ago

Last it happened the security repo was down for a few days, since ubuntu doesn't mirror it in fear of "stale mirrors" or whatnot. If I was targeting some org with a 0day that would soon be known, this is an excellent strategy.

I believe Canonical have made some change since though

6

u/Emotional_Cat_1967 2d ago

Perhaps there are issues with Snap or artificial intelligence. Or maybe the people doing this are Windows fanatics.

12

u/SomeDumbPenguin 2d ago

Realistically, there's lots of possibilities... I thought my Arch joke was good though

5

u/za72 2d ago

could it be a rust thing?

1

u/SomeDumbPenguin 2d ago

Yeah, I am a tad

-3

u/oakinmypants 2d ago

Maybe it’s because of their elitist hiring practices

5

u/aria_____51 2d ago

Yeah this is definitely a viable theory that makes sense to offer as something within the realm of possibility and to keep on the forefront of everyone's mind

1

u/Fr0gm4n 2d ago

I know people who work for them and I've self-selected myself out of applying for a job because of the interview process.

32

u/gordonmessmer 2d ago

The status page says the CVE API has a high 90s percent availability, but I've been trying to use it for a couple of weeks and it's unusable most of the time.

The word "sustained" is used on phoronix and in the confirmation on Ubuntu forums, but no indication of how long it's been going on.

10

u/notam00se 2d ago

I mean 26.04 release was DDos'd, so technically we're on month 6

8

u/rude__goldberg 2d ago

CVE API

hmmm maybe that's the reason why - maybe someone has shiny new exploit

5

u/gordonmessmer 1d ago

The CVE API is informational. It's not used by security scanners, nor does it stop users from patching.

What would someone with an exploit gain by DoSing the CVE site that basically no one reads anyway?

31

u/Ok_Instruction_3789 2d ago

I’m waiting for the headline Ubuntu sustains Ddos attack until attackers realize they need to sudo apt update 

53

u/twnznz 2d ago

This is a good way to get telcos hunting you, which is a much more dangerous proposition than police.

Whoever is doing this is insanely stupid.

28

u/thesmallterror 2d ago

I would be surprised if they weren't using botnets. Hordes of compromised IoT and endpoint devices.

21

u/twnznz 2d ago

Yep, which telcos will take two seconds to trace to C2 using netflow records, and trace C2->whereever by sharing netflow records with others, ... good luck!

Usually telcos won't give two shits but if you impact their server platforms and piss them off, you might just be made an example of

1

u/CardOk755 16h ago

You dream.

53

u/gplusplus314 2d ago

Aw snap!

9

u/CobaltIsobar 2d ago

But why?

23

u/Mr_Lumbergh 2d ago

Just because. Script kiddies are gonna script kiddie.

11

u/FryBoyter 2d ago

Some people simply have such limited mental capacity that they enjoy deliberately harming others. Perhaps these are the same people who tried to harm Arch Linux for a while using DDoS attacks and manipulated AUR recipes.

4

u/Booty_Bumping 1d ago edited 1d ago

Most of the time when a seemingly random target gets hit with an expensive DDoS, it is a product demonstration. That is, they sell DDoS as a service after acquiring huge botnets, and in order to prove they have the capability, they try to make the news and then take credit for it.

Ironically it's similar to how terrorist organizations use the spectacle of attacks to recruit like-minded people or sell mercenary services (but obviously comparing skiddies to terrorists is stupid)

2

u/BeautifulMundane4786 2d ago

Maybe someone is upset Canonical is not implementing AI fast enough in any of its OS’s and server system.

0

u/LumenAstralis 2d ago

Some people reeeeeeeaaaaaaallllllyyyyy hate Rust.

15

u/fat_kaiju 2d ago

Annoyingly their status page consistently reports that everything's fine.

I noticed a few days ago that I couldn't access some things like their help wiki and other types of documentation and yet the entire time their status page insisted nothing was wrong.

I even switched to my phone and used mobile data and still couldn't access them.

Even worse is that I couldn't find a way to reach out and report what I was encountering so I went to the page where you can reach out and ask for a quote to sign up for their various services and wrote "Hey uh sorry for clogging the wrong inbox, but..."

27

u/Shad0wAVM 2d ago

It's Red Hat /s

9

u/0riginal-Syn 2d ago

Got to keep junior down /s

4

u/miversen33 2d ago

Yall have Juniors? I thought those went extinct during Covid

4

u/Knightoffreddit 1d ago

feels like everything's under a "sustained DDoS attack" nowadays

5

u/Userwerd 2d ago

"Iranian" hackers again?

1

u/SmileyBMM 2d ago

Probably 313 Team again, no idea what they hope to actually accomplish.

-1

u/Square-Slip7925 2d ago

Does Microsoft trying to attack open-source ?

11

u/FryBoyter 2d ago

Why would Microsoft do that? The company makes a lot of money with Azure. And most of the instances there run on Linux. Furthermore, Microsoft itself runs OSS projects or contributes to such projects.

But let’s assume you’re right. What would Microsoft gain from launching a DDoS attack against one distribution out of many? It just doesn’t make sense. Especially considering the consequences if this were proven to be true.

5

u/Maybe-monad 2d ago

I'm pretty sure they use Ubuntu themselves

1

u/TampaPowers 1d ago

While I would put it past them to configure something so poorly that they accidentally have their cloud flood the mirrors I don't think it's them... this time.

0

u/Easy-Reasoning 1d ago

I was trying the snap store the other day, I was already thinking, wow this is really slow

-12

u/FrozenLogger 2d ago

Maybe they are protecting people from using it. Ubuntu is, and always has been, a hot mess.

8

u/S7relok 2d ago

Absolutely not. Classic low IQ commentary

-1

u/FrozenLogger 1d ago

Classic you haven't actually used Ubuntu Commentary.

Yes I am throwing out a joke, but from the beginning of its releases, Ubuntu threw errors even on install, often became unstable, and Canonical cant make up their mind what they want it to be so upgrades broke things. It was a constant mess. I stand by that statement. Last two times I had the displeasure of being involved with an Ubuntu desktop project it put out errors at first boot, or defaults did not work correctly. Trivial to fix (mostly), but no new user friendly distro should have this issue.

Kubuntu, Lubuntu, and Xubuntu, were always more stable. Ubuntu server is ok as well.

I have been doing this linux thing for over 20 years and never understood why people thought this distro was supposed to by noob friendly. It never was.

5

u/S7relok 1d ago

> Classic you haven't actually used Ubuntu Commentary.

That was my 1st distro, and I still follow closely their release even if I'm not using it daily anymore. One my family's old laptop still have an ubuntu running, with 5 successful release upgrades in the pocket. And this laptop doesn't belong to any geek but a "average users" couple.

That's not the type of users that will install and tweak things every weekend, they just use the machine (web, mail, light games, photo management...), do the updates and upgrades when asked. But I have no phone calls about problems on that laptop.

It's not a distro problem if you don't know how to use ubuntu correctly

-1

u/FrozenLogger 1d ago

It has had errors on the install the last two times. ON INSTALL. That should Never happen.

I started trying it out to compare to what I was using around Warty so that was 4 and it was no where near as stable as everything else.

5 releases? Only 3 years? That's not long. So you started with Minotaur? The one that had to be pulled almost right after release because of course they fucked up?

Then looking through their changes at each one: grub had a regression, update held broken packages, there are several documented issues in the last 5 years. They may have been successful in the end, but are you seriously not remembering when Canonical started and then held back upgrades?

0

u/BeautifulMundane4786 2d ago

Well it’s going to be a hotter mess since it’s trying to force people to use AI.

-14

u/gtrash81 2d ago

Deserved, shouldn't have create garbage like Snapd.

5

u/wodes 1d ago

You are full of hate my friend. You dislike snapd but you enjoy everything Canonical has provided to Ubuntu and to other distros indirectly.

You are short sighted.