Briefing

Canonical Suffers 20‑Hour DDoS Attack Using Cloudflare‑Busting Service

security
by speckx · Cloudflare

Configure Cloudflare to enforce ‘Under Attack Mode’ on all critical endpoints, block IP ranges associated with Beamed, and monitor certificate transparency logs for unexpected apex certificate issuance.

What to do now

Configure Cloudflare to enforce ‘Under Attack Mode’ on all critical endpoints, block IP ranges associated with Beamed, and monitor certificate transparency logs for unexpected apex certificate issuance.

Summary

On 30 April 2026 at 16:33:37 UTC, Canonical’s blog.ubuntu.com was marked down, and within ten minutes the company’s main site, security advisory APIs, developer portal, corporate site, and training platform were all offline.

The attack, lasting roughly twenty hours and restored on 1 May 2026 at 12:44 UTC, was carried out with a paid DDoS service called Beamed, which advertises techniques to bypass Cloudflare via residential IP rotation and endpoint hunting. The attack also involved a sudden reassignment of AS39287 to Materialism s.r.l. on 27 February 2026, bringing in IP ranges that were used during the assault, and a series of new apex certificates for archive.ubuntu.com and security.ubuntu.com issued on the same day, suggesting a coordinated origin‑side mitigation attempt.

During the assault, the repository endpoints security.ubuntu.com and archive.ubuntu.com flapped for 70 minutes, potentially breaking apt updates worldwide. Beamed’s domains resolved to Cloudflare’s AS13335, indicating the attackers used Cloudflare as a front to hide their origin IPs.

The incident highlights the need for stricter CDN protection and monitoring of certificate issuance to detect and mitigate similar attacks before they impact critical services.

Key changes

  • Attack used Beamed, a paid DDoS service that bypasses Cloudflare via residential IP rotation and endpoint hunting
  • Canonical’s blog.ubuntu.com went down at 16:33:37 UTC, followed by other services within minutes
  • Repository endpoints security.ubuntu.com and archive.ubuntu.com flapped for 70 minutes at 19:40 UTC, risking apt update failures
  • Attack lasted ~20 hours, restored on 1 May 2026 at 12:44 UTC
  • Beamed’s domains resolved to Cloudflare AS13335, using Cloudflare as a front
  • AS39287 reassigned to Materialism s.r.l. on 27 Feb 2026, bringing in IP ranges used during the assault
  • New apex certificates for archive.ubuntu.com and security.ubuntu.com issued on 27 Feb 2026, coinciding with routing reassignment
  • The attack exploited Cloudflare’s reverse proxy to hide origin IPs

Affects

enterprise internal

Customer impact

Analyzing matches…

Ask about this story

Impact on an agency? Which customers? Compare historically Risks of waiting