Update about canonical site

Thought I would share this with everyone …

I went looking for various GitHub projects to identify some Canonical/Ubuntu individuals who published an email address (of whatever nature).

I got a couple of hits and I want to share this one with everyone. His name is associated with

  • canonical/canonical.com

IMPORTANT: his own profile on GitHub does not identify him as Canonical, unlike many others who do, but he does use the expression “our IS teams” … so he might be, just not openly!!!

(email response)

3 Likes

Right now seems to be offline…

They are indeed filtering. Which is understandable. Plenty of bots, spam, DDoS, scanners, etc. out there.

I was blocked earlier today but via a WiFi hotspot. Currently less than 50% of the web’s traffic is human. :downcast_face_with_sweat:

This is a rapidly growing issue that causes blocking of valid traffic, in admins’ attempts to mitigate. This type of reporting is very helpful.

1 Like

Canonical apparently received an ultimatum from an organization called

  • “The Islamic Cyber ​​Resistance in Iraq – 313 Team”

to pay a ransom by a deadline, or else …

2 Likes

Yes. I read that also:

The extortion angle is the eye-catching part, but what’s stuck with me more is how thin Canonical’s own disclosure has been throughout this.

The official trail is basically: the May 1 Discourse post saying they’re under a “sustained, cross-border attack,” a spokesperson quote to The Register which linked to somewhere in the forums before, and a May 6 note saying services were restored. That’s it! :eyes:

No attribution from Canonical, no acknowledgment, no peak traffic figures, no mention of mitigation specifics, and no post-incident write up.

For a DDoS that took the Ubuntu security API offline for the better part of a week, that feels light.

And what’s harder to shrug at is the operational posture. No CDN or WAF in front of the security API in 2026 is a choice. No comms during the incident is a choice. No post-mortem afterwards is a choice.

For a company that sells Ubuntu Pro on a security pitch, the silence is doing damage IMO. :confused: Hopefully more details this month.

Some examples of the bar set:

2 Likes

Day 13 and going after the public broadcast! :frowning:

I sent a “hail-mary” message to the VP (@arcticp) that posted the DDOS notification. No response yet, personal or on the site!

2 Likes