Habr•August 20, 2026•🇷🇺Translated from Russian

Can the Moon Be DDoSed? Exploring Future Cybersecurity Challenges for Lunar Bases

Imagine a lunar base in 2036: a handful of astronauts, dozens of rovers, sensors, and automated systems all exchanging data across NASA’s planned LunaNet architecture. The original question posed by DDoS-Guard analysts is whether this infrastructure could be taken offline by a distributed denial-of-service attack launched from Earth.

The distance alone creates a 2.6-second round-trip latency, making conventional TCP/IP assumptions invalid. NASA therefore designed Delay/Disruption Tolerant Networking (DTN) that stores bundles at intermediate nodes until the next contact window appears. While this store-and-forward approach keeps data alive during eclipses or orbital hand-offs, it also creates new queues that an attacker could deliberately fill.

Attacking a single server inside a habitat module would produce only local effects. The real targets are the scarce orbital relays and Earth-Moon gateways whose bandwidth cannot be expanded by simply adding more terrestrial bots. A million compromised devices on Earth would still be throttled by the same 622 Mbit/s laser or radio link demonstrated during the Lunar Laser Communications Demonstration.

More sophisticated scenarios involve crafting low-volume but high-cost requests that force DTN nodes to perform expensive lookups, cryptographic checks, or persistent storage operations. Because every additional relay or antenna represents years of engineering and launch mass, there are few alternate paths when one node becomes saturated.

Ground-segment compromise remains the most practical vector. Command centers, telemetry servers, and mission-control networks on Earth use ordinary IP infrastructure and could be flooded with traffic generated by large botnets. Once those links are degraded, lunar assets lose remote oversight even if local systems continue to function.

The article stresses that any future lunar network will inherit familiar terrestrial problems—limited capacity, single points of failure, and the need for strict traffic prioritization—despite operating in an environment where mistakes carry far higher consequences.

Related articles

Securitylab•Other

Neuromorphic Processors Deliver Reflex-Like Responses for Robots, Drones and Edge Sensors

Neuromorphic chips are optimized for sparse, event-driven data rather than dense matrix operations, making them ideal for always-on peripheral devices that must react instantly while conserving power. The technology pairs naturally with event cameras and temporal sensors in robotics, drones, automotive systems, medical wearables, industrial monitoring and space applications. Platforms such as Intel Loihi 2, BrainChip Akida, SynSense Speck and SpiNNaker2 already demonstrate working prototypes that activate only on meaningful changes in the input stream. Researchers at TU Delft have flown autonomous drones using spiking networks on Loihi, while NASA has tested radiation-tolerant neuromorphic designs for onboard decision making. The approach complements rather than replaces GPUs and NPUs, creating hybrid systems where the neuromorphic layer handles fast reflexes and conventional accelerators manage complex models.

Habr•Other

K2 Cloud Adds Native OVN Traffic Mirroring for NTA/NDR Deployment in Public Cloud

K2 Cloud has implemented traffic mirroring for virtual machine interfaces inside overlay networks built on OVN, solving a long-standing gap that prevented NTA/NDR systems from operating in Russian public clouds. The company contributed the feature upstream, and the patch was accepted into the main OVN codebase. The solution supports source, destination, and mirroring session objects together with optional match/action filters that eliminate duplicate packets, reduce load on sensors, and allow traffic distribution across multiple analyzers. Testing with Positive Technologies PT NAD showed sustained throughput above 3 Gbit/s with approximately 400 000 packets per second and minimal packet loss. The feature works inside a single availability zone; multi-AZ deployments require one PT NAD sensor per zone. Management is available through the web console, an EC2-compatible API, and the official Terraform provider.

Securitylab•Other

Bitrix24 Introduces Cowork/Code AI Agent for Corporate Task Automation and App Building

Bitrix24 has launched Cowork/Code, an AI application that combines file management, company data access, and application development inside a controlled corporate environment. The tool features an AI agent capable of executing multi-step workflows such as locating records, comparing documents, generating tables, and saving results to shared folders. It operates in two modes: Cowork for one-time tasks like overdue task reports or client preparation, and Code for creating reusable tools such as dashboards or notification bots. A memory technology called Radiant stores context from chats, tasks, meetings, and employee data to deliver more accurate, personalized responses over time. The platform addresses common risks of vibe coding by keeping code, data access, and distribution within the Bitrix24 ecosystem hosted on Russian infrastructure. A free tier provides limited usage, with paid plans required for sustained team operation.

Habr•Other

Klark and Klara Launch Self-Hosted Corporate Messenger and Task Manager for On-Premise Data Control

Klark and Klara are two integrated products designed to keep corporate communication and task management entirely within company infrastructure. Klark functions as a Telegram-like messenger with personal chats, supergroups, channels, voice messages, file sharing, and video calls powered by LiveKit. Klara serves as a streamlined task and knowledge base system replacing complex setups like Jira and Confluence. Both run via Docker Compose on customer servers using PostgreSQL, Redis, FastAPI, and React, with built-in antivirus scanning via ClamAV. Key security measures include mandatory TOTP two-factor authentication, LDAP integration, content security policies, and automatic session invalidation on token reuse. The combination allows direct task creation from chat messages and displays tasks alongside conversations in a unified interface.