Techpolicy.Press Cyberattacks Target Exiled Media as Censorship Tool
Article Content
- •DDoS attacks are increasingly used by authoritarian regimes to censor exiled media.
- •Exiled journalists face malicious web activity at a rate four times higher than other media.
- •Cloudflare's report shows 5% of requests to exile journalism sites were harmful from Feb 2025 to Jan 2026.
Authoritarian governments are increasingly using cyberattacks, particularly DDoS attacks, as a means of censorship against exiled media outlets. A report from Cloudflare indicates that exiled journalists face malicious web activity at four times the rate of other media organizations. Between February 2025 and January 2026, about 5% of requests to exile journalism websites were harmful, disrupting their connections to readers. Specific incidents include a DDoS attack on the Cuban outlet elToque in December 2025, linked to its reporting on the economy, and a similar attack on the Moscow Times in July 2025. These attacks not only render websites inaccessible but also erode the credibility of the affected outlets and lead to self-censorship. The attacks are a part of a broader trend of digital transnational repression, with implications for press freedom globally.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track China Digital Times in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…
Critical Linux Kernel Vulnerability CVE-2025-39682 Under Active Exploitation A critical vulnerability (CVE-2025-39682) in the Linux kernel allows remote code execution through mishandling of zero-length TLS records. This flaw affects kTLS-enabled hosts running vulnerable kernel versions, exposing them to attackers without authentication. CISA added this vulnerability to its Known Exploited…