Dupe. More comments here: https://news.ycombinator.com/item?id=47972213
It seems Ubuntu infra is hosted at cloud provider? All have the mechanisms to protect from these types of attacks. Is this an architecure design failure?
When asked for ransom terms, the attackers said, “no more systemd”
cross-border attack? The internet doesn't have borders. The title of the article has nothing to do with the title submitted here.
edit: I should probably add more context as some commenters didn't understand. The DDOS attack is likely coming from compromised IoT devices. Most, if not all, of the big ones in the last few years(decades?) were that. Unless all the devices are located within a specific country and non are within the US then I think it is silly to use that term to imply that this is some sort of war from across the border. The reporting is fine for what they know so far, the submitted title is not.
Maybe they’re trying to block access to this URL: https://ubuntu.com/security/CVE-2026-31431
To address that, here is how to disable that local root access in Ubuntu 24.04:
https://news.ycombinator.com/item?id=47957409