Threat Brief — 2026-08-13 — DDoS at terabit scale, Boeing hijack for $100
Executive Summary
Today's fresh intel is lighter on zero-days and heavier on infrastructure and physical-security exposure. Cloudflare reports 930+ massive DDoS attacks in six months with terabit-per-second throughput now normalized — a trend that demands capacity-planning attention. A $100 coin-sized device demonstrated the ability to hijack Boeing 737 navigation, highlighting continued gaps in avionics physical-access controls. On the privacy front, a new service exposes how ad-tech intermediaries auction real-time geolocation data, and Facebook is actively blocking uBlock Origin functionality.
Top items
- Cloudflare: 930+ massive DDoS attacks in six months, terabit/s is the new normal. The report quantifies the largest DDoS attack in history and confirms sustained escalation in attack volume and frequency. This is infrastructure threat-planning signal: upstream scrubbing capacity and peering arrangements may need review. (src: securitylab-ru)
- $100 coin-sized device can hijack a Boeing 737. A physical-access attack demonstration shows how a small, cheap device can covertly manipulate flight navigation toward terrain or ocean. Relevant to any organisation with aviation-asset or executive-travel risk exposure; underscores persistent avionics bus-security gaps. (src: securitylab-ru)
- Facebook intentionally breaks uBlock Origin. The uBlock Origin team alleges Facebook is deliberately counteracting the open-source ad blocker, degrading privacy tooling for end users. This signals a broader platform trend of adversarial design against content control, with implications for enterprise browser-policy and user-privacy posture. (src: securitylab-ru)
- Ad-tech geolocation auctions exposed: websites silently sell real-time location data. A new transparency service traces the full chain from website to advertising intermediaries, revealing how user geolocation is auctioned without informed consent. Relevant to data-governance and privacy-compliance teams assessing third-party exposure from web properties. (src: securitylab-ru)
- Deepfake scammer exposed by a one-second glitch after stealing 30 identities. A near-perfect deepfake fraud operation was undone by a transient rendering bug that revealed the perpetrator. Illustrates the growing sophistication of identity-fraud attacks and the thin margin of current detection — a signal for KYC and video-verification controls. (src: securitylab-ru)
- Russian AI models must pass a "traditional values" test to qualify for state support. A regulatory development affecting only models seeking national or sovereign status; low direct operational impact but worth noting for organisations evaluating Russian AI supply chains. (src: securitylab-ru)
Themes
Privacy erosion across layers. Three of today's items — Facebook blocking ad blockers, geolocation auctioning, and deepfake-enabled identity theft — point to a pattern where user data and identity are increasingly commodified or weaponised with minimal user awareness. For engineering teams, this reinforces the need for privacy-preserving defaults and robust third-party script controls on owned properties.
Physical-digital convergence. The Boeing 737 hack device and last week's malicious-SIM EV-charger research both demonstrate that sub-$100 physical payloads can compromise critical systems through legacy or under-secured interfaces. Hardware attack-surface assessments deserve a place alongside network and application testing.
