Vulnerabilities ‘HTTP/2 Bomb’ Exploit Knocks Web Servers Offline in Seconds The default HTTP/2 configuration of major web servers is vulnerable to an attack chain combining a compression bomb and a Slowloris-style hold. Ionut ArghireJune 3, 2026
Vulnerabilities New HTTP Request Smuggling Attacks Impacted CDNs, Major Orgs, Millions of Websites A desync attack method leveraging HTTP/1.1 vulnerabilities impacted many websites and earned researchers more than $200,000 in bug bounties. Eduard KovacsAugust 7, 2025
Network Security Organizations Respond to HTTP/2 Zero-Day Exploited for DDoS Attacks Organizations respond to HTTP/2 Rapid Reset zero-day vulnerability exploited to launch the largest DDoS attacks seen to date. Eduard KovacsOctober 11, 2023