logo

Enforcing the First AS in BGP AS_PATHs

ID: cf12d603-287a-5414-a9de-5e011428a106

STIX ID: report--cf12d603-287a-5414-a9de-5e011428a106

Feed Name: Cloudflare Blog

Threat Score
75/100

Date Published: 2026-06-03

Date Updated: 2026-06-04

Author: Bryton Herdes

...
...

This report analyzes recent BGP route hijacks that used forged AS_PATHs and unused ASNs to misdirect traffic, documents concrete examples (including paths involving AS199524/Gcore and Cloudflare’s ASN), describes measurements where Cloudflare purposely injected malformed first-AS announcements to test which Tier 1 networks accept them (finding roughly half accepted), explains vendor default behaviors, and urges operators to enforce First AS checking as an effective mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.