Tag
#Alibaba
4 stories taggedAlibaba.

Vulnerabilities
The 'CDN Tsunami' Attack Turns a Trickle of Traffic Into a Flood at the Origin
Researchers show how the way big content delivery networks translate modern HTTP/3 requests into older HTTP/1.1 can multiply a small attack stream by up to 350 times against the website behind them.
4 min read

Threat Intelligence
Fake npm Packages Pose as Alibaba Developer Tools, Drop Remote-Control Malware
Researchers found 18 booby-trapped packages on the npm registry aimed at Chinese-speaking developers, using a classic name-squatting trick to smuggle in a cross-platform remote access trojan.
4 min read

Vulnerabilities
Hackers Hit Unpatched Fastjson Bug in Spring Boot Apps, No Fix Yet
CVE-2026-16723 lets attackers run code on vulnerable Java servers without a password. Alibaba scores it 9.0. No patch is available.
4 min read

Vulnerabilities
Unpatched Flaw in Alibaba's XQUIC Lets Anyone Crash HTTP/3 Servers With 260 Bytes
A researcher at FoxIO disclosed the bug on 8 July. There is no fix, no login required, and no malformed packets involved.
3 min read