Cloudflare 被指勒索 Canonical
推荐指数 38.0 NO. 021 · 2026.05.12
发布2026/05/11Score92Comments40
为什么值得看
Ubuntu 母公司 Canonical 遭 DDoS 攻击导致全站瘫痪 20 小时,攻击者声称使用了付费商业服务。事件引发对 CDN 安全厂商是否参与勒索的质疑,目前 Cloudflare 被点名但尚未回应。
媒体预览
编辑判断
这起事件的特殊之处在于攻击者主动炫耀使用了付费商业 DDoS 服务,而非传统的僵尸网络,说明 DDoS 即服务(DDoSaaS)的门槛已经低到脚本小子都能租用。更敏感的是 Cloudflare 被卷入勒索疑云——如果 CDN 厂商真存在先攻击再推销保护的灰色操作,整个互联网基础设施的信任基础会动摇。
对依赖 CDN 的 AI 创业公司来说,这是一个重新审视多 CDN 冗余架构的契机,不要把所有流量押注在单一厂商身上。另外关注后续 Canonical 是否会公开更多技术细节,这关系到整个行业能否复盘防御策略。
社区反馈
负面 106 条评论
核心争论:Cloudflare 免费保护攻击者是否构成利益冲突与勒索
Relevant post from last week: > Why is Cloudflare protecting the DDoS'er (beamed.st) attacking Ubuntu servers? https://news.ycombinator.com/item?id=48025001
They didn’t.
Right. It's more abstract than that. They protect (from legal consequence or even discovery) the attackers and host them on their infrastructure so they're untouchable. Then they sell the same "protection" to the victims. It's the classic mafia protection scam.