OpenAI’s Codex helps detect HTTP/2 Bomb DoS attacks that can nuke over 30GB of RAM in seconds, knocking web servers offline before they can react


  • New DoS technique called HTTP/2 Bomb
  • Utilizes compression and flow control that stalls
  • Large web servers confirmed vulnerable

We can thank AI for a new denial-of-service (DoS) technique that can knock a server offline in seconds using nothing more than a single computer with a 100 Mbps connection.

Earlier this week, California cybersecurity researchers revealed that they discovered a new DoS technique called the HTTP/2 Bomb. They used OpenAI’s Codex software agent to detect it, saying it combines two previously known HTTP/2 DoS methods: the HPACK compression enhancement and Slowloris-style resource retention via HTTP/2 flow control stalling.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top