
New HTTP/2 Bomb Attack, Trump's AI Security Reviews, Android Zero-Day & The Patching Crisis
A newly disclosed attack called HTTP/2 Bomb can crash major web servers in seconds using a single computer and a modest internet connection. Researchers say the attack combines two known techniques into a powerful memory-exhaustion exploit affecting widely used platforms including Apache, NGINX, Microsoft IIS, and Envoy. The attack also highlights a growing trend in cybersecurity research: the use of artificial intelligence to uncover dangerous combinations of existing vulnerabilities. The episode also examines President Trump's new executive order creating a voluntary framework for reviewing advanced AI models before public release. The administration says the goal is to...
Transcript
Automatically generated from the audio. May contain errors.
Cybersecurity today would like to thank Material Security for supporting the podcast. Material Security provides faster, more complete detection and responses for email identity and data threats inside Google Workspace and Microsoft 365. Contact them at material.security.
An HTTP2 bomb can crash web servers in seconds. Trump creates a voluntary AI security review as the government seeks visibility into frontier models. The cybersecurity industry's patch strategy may be breaking down, and a CESA warning shows attackers don't care whether a vulnerability is new or old.
This is Cybersecurity Today. I'm your host, Jim Love. Researchers have discovered a new denial-of-service technique called HTTP2-BOM that can exhaust a web server's memory and take it offline in less than a minute. The ATT&CK targets HTTP2 implementations used by major web servers including Apache,
N-Jinks, Microsoft's Internet Information Services or IIS, and Envoy. What makes it unusual is that it doesn't require a botnet or a massive bandwidth. Researchers say a single computer on a 100 megabit connection could knock vulnerable servers offline within the seconds. The attack combines two older techniques. First, it abuses HTTP2's H-Pack compression system
to force a server to allocate far more memory than the attacker actually sends across the network. Then it uses HTTP to flow control features to prevent that memory from being released. The result is a server that keeps consuming memory until it runs out. Quickly. In testing researchers were able to consume and hold 32 gigabytes of memory
on Apache and Envoy servers in roughly 20 seconds. IIS servers with 64 gigabytes of RAM were exhausted in about 45 seconds. The researchers describe it as a memory amplification attack. In some cases, every byte sent by the attacker triggered thousands of bytes of memory allocation on the target server. Because the attack exploits normal HTTP2 behavior,
traditional denial of service protections that focus on traffic volume may not detect it immediately. And there's another interesting twist to this story. The researchers say the attack chain was first identified with the assistance from open AI's codecs. The underlying techniques were already known, but the AI helped connect them into a practical exploit that had not
previously been recognized. It may be an early example of a trend security researchers are watching closely. Artificial intelligence not discovering new vulnerabilities, but uncovering dangerous combinations of the existing ones that humans overlooked.
The Trump administration assigned an executive order creating a voluntary framework for reviewing advanced artificial intelligence models before they're released to the public. Under the program, developers can provide frontier AI systems to government agencies for cybersecurity and national security assessments up to 30 days before launch.
The order specifically states that participation is voluntary and does not create any licensing, permitting, or pre-approval requirements for AI companies. So on the surface, the order appears to be a compromise between two competing goals. The administration wants to maintain American leadership in artificial intelligence while
also acknowledging growing concerns about the security risks posed by increasingly powerful models. The Cybersecurity and Infrastructure Security Agency, the National Security Agency, and the National Institute of Standards and Technology will play roles in the review process. For cybersecurity professionals, the interesting question is why the government wants early
access at all. Recent research has shown that advanced AI systems are becoming increasingly capable of identifying software vulnerabilities, analyzing code, and accelerating security research. Those same capabilities could potentially be used to accelerate cyber attacks, discover previously unknown flaws, or support nation-state operations. Those abilities may have already
arrived with Mythos, with Microsoft's M-Dash and OpenAI's 5.6 model. But the executive order suggests that Washington wants greater visibility into those capabilities before they reach the public. The challenge is that visibility and control are not the same thing.
The government is signaling concern about the cybersecurity implications of Frontier AI while stopping well short of imposing any meaningful oversight. In effect, it's asking companies to voluntarily share information about technologies that It could have national security implications, but whether that approach proves sufficient
as AI capabilities continue to advance remains an open question. A new report from the Cloud Security Alliance suggests that organizations are struggling with a problem that has been quietly growing for years. There are simply too many vulnerabilities to patch.
The report has found that 89% of organizations experienced a security incident linked to an unpatched vulnerability over the past year, while more than half said they cannot keep up with the number of vulnerabilities requiring attention. For decades, the advice from security professionals was straightforward.
Patch your systems as quickly as possible. But today's environments are very different from the data centers of 20 years ago. Organizations now manage cloud services, containers, software as a service platforms, Notepad, note endpoints, APIs, and a growing number of third-party applications.
Every one of those technologies generates its own stream of vulnerabilities and updates. And the result is that many security teams are no longer deciding how quickly to patch. They're deciding what not to patch. According to the report, limited staff, resource constraints, and incomplete visibility
into assets are making it increasingly difficult to keep pace. In practice, many organizations are forced to prioritize a small subset of vulnerabilities while accepting risk elsewhere. That may be the most important takeaway from the report.
The cybersecurity industry's tools for finding vulnerabilities continue to improve.
This is the opening of the episode. Open the player for the full interactive transcript with clickable words, translation and flashcards.
Open full transcriptAudio belongs to its publisher and is played from their feed. Rights holders can request removal — copyright & takedown policy











