Tag
#Apache
3 stories taggedApache.

Threat Intelligence
Chinese-Speaking Crew Slips Malicious Apache Modules Onto Brazilian .gov and .edu Sites
Check Point tracks the cluster as Gambling Goblin, with medium-confidence links to Chinese-speaking SEO-poisoning operators active since mid-2025.
4 min read

Vulnerabilities
HTTP/2 Bomb: A Decade-Old Compression Trick Finally Gets a CVE
A chained HPACK attack lets small packets force runaway memory allocation on nginx, Apache, IIS, Envoy, and Cloudflare's Pingora. Patches are partial. Exposure is wide.
2 min read

Vulnerabilities
HTTP/2 Bomb: Default Configs in NGINX, Apache, IIS, Envoy and Pingora Open Door to Remote DoS
A chained protocol abuse discovered by OpenAI Codex and disclosed by Calif knocks over five of the most widely deployed web servers in their out-of-the-box state.
2 min read