Can the Moon Be DDoSed? Exploring Future Cybersecurity Challenges for Lunar Bases
Imagine a lunar base in 2036: a handful of astronauts, dozens of rovers, sensors, and automated systems all exchanging data across NASA’s planned LunaNet architecture. The original question posed by DDoS-Guard analysts is whether this infrastructure could be taken offline by a distributed denial-of-service attack launched from Earth.
The distance alone creates a 2.6-second round-trip latency, making conventional TCP/IP assumptions invalid. NASA therefore designed Delay/Disruption Tolerant Networking (DTN) that stores bundles at intermediate nodes until the next contact window appears. While this store-and-forward approach keeps data alive during eclipses or orbital hand-offs, it also creates new queues that an attacker could deliberately fill.
Attacking a single server inside a habitat module would produce only local effects. The real targets are the scarce orbital relays and Earth-Moon gateways whose bandwidth cannot be expanded by simply adding more terrestrial bots. A million compromised devices on Earth would still be throttled by the same 622 Mbit/s laser or radio link demonstrated during the Lunar Laser Communications Demonstration.
More sophisticated scenarios involve crafting low-volume but high-cost requests that force DTN nodes to perform expensive lookups, cryptographic checks, or persistent storage operations. Because every additional relay or antenna represents years of engineering and launch mass, there are few alternate paths when one node becomes saturated.
Ground-segment compromise remains the most practical vector. Command centers, telemetry servers, and mission-control networks on Earth use ordinary IP infrastructure and could be flooded with traffic generated by large botnets. Once those links are degraded, lunar assets lose remote oversight even if local systems continue to function.
The article stresses that any future lunar network will inherit familiar terrestrial problems—limited capacity, single points of failure, and the need for strict traffic prioritization—despite operating in an environment where mistakes carry far higher consequences.
Related articles
Central Bank of Russia Confirms Digital Ruble Will Be Free for Citizens with No Commissions
The Bank of Russia has announced that all operations with the digital ruble will be completely free of charge for individual citizens. Director of the National Payment Systems Department Alla Bakina stated that transfers and payments for private users will incur zero commissions. Businesses will still face fees, but the regulator promises they will be minimal and lower than standard bank rates for similar transactions. Starting 1 September, Russians will be able to open digital ruble wallets through mobile apps of systemically important banks and other payment-significant credit institutions. A dedicated button with the new currency logo will appear on the main screen of these applications. Payments will be made via a special QR code that buyers scan in their banking app before selecting the digital ruble wallet and confirming the transaction. Large retail chains with annual revenue exceeding 120 million rubles must begin accepting digital ruble payments from September, with the requirement later expanding to smaller merchants. The Bank of Russia emphasizes that the digital ruble represents a third form of the national currency alongside cash and bank deposits, available for voluntary use by citizens.
Power Outage at Major Russian Telecom Node Disrupts Reg.ru Services and Affects Runet Nationwide
A large-scale power failure at a key communication node in Russia caused widespread disruptions to internet services on August 17. Hosting provider and domain registrar Reg.ru experienced a major outage, preventing users from accessing its main website and personal accounts. Multiple sites relying on Reg.ru infrastructure also went down or became unstable, with evidence pointing to problems with DNS servers responsible for translating domain names into network addresses. Users reported simultaneous issues with banking apps, messengers, social networks, and other Russian online resources, though it remains unclear whether all incidents stemmed directly from the Reg.ru-related problems. Reg.ru stated that the issue originated outside its own infrastructure due to electricity supply problems at the major node. The company expressed hope for quick restoration but provided no details on the incident's full scale or recovery timeline at the time of reporting.
Yandex Maps Adds Upcoming Speed Limits and Camera Direction Details to Navigation
Yandex Maps has updated its navigation mode to display speed restrictions on upcoming road segments along the entire route. Drivers can now see a sequence of limits in advance, such as 80 km/h followed by 60 km/h after an interchange and then 40 km/h. The application also provides more detailed information about the two nearest traffic cameras, including the specific lane they target and whether they monitor oncoming or same-direction traffic. Voice alerts now warn users when a camera measures speed after the vehicle has already passed it. Pilot testing showed positive effects on speed limit compliance. The changes aim to make urban and highway driving more predictable by removing the need to guess restrictions or camera focus ahead.
Kaspersky Releases Corporate Version of Kaspersky Password Manager for Mid-Size and Large Organizations
Kaspersky has introduced a business edition of Kaspersky Password Manager designed for centralized credential management across medium and large enterprises. The solution generates complex passwords, stores them in encrypted vaults, and audits existing credentials for strength and exposure in data leaks. Employees only need to remember a single master password while the platform also supports storage of TOTP tokens, passkeys, corporate documents, and payment card details. Administrators gain tools to enforce password policies centrally and apply role-based access controls. Supporting statistics from Kaspersky Digital Footprint Intelligence show widespread password reuse and simplicity, with 37 percent of users merely changing letter case when recycling passwords. The company links these habits to real risk, noting that credential compromise initiated one quarter of attacks against organizations in 2025.