{"id":65,"date":"2026-08-04T15:30:00","date_gmt":"2026-08-04T15:30:00","guid":{"rendered":"https:\/\/cyberasia.io\/?p=65"},"modified":"2026-08-17T09:00:08","modified_gmt":"2026-08-17T09:00:08","slug":"israeli-lgbtq-and-cyber-conference-sites-hit-by-widespread-outages","status":"publish","type":"post","link":"https:\/\/cyberasia.io\/article\/ddos\/israeli-lgbtq-and-cyber-conference-sites-hit-by-widespread-outages\/","title":{"rendered":"Israeli LGBTQ and Cyber Conference Sites Hit by Widespread Outages"},"content":{"rendered":"<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"1024\" height=\"687\" src=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/grok_1785070784967-1024x687.jpg\" alt=\"Israeli LGBTQ and Cyber Conference\" class=\"wp-image-66\" \/ loading=\"eager\" fetchpriority=\"high\" srcset=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/grok_1785070784967-1024x687.jpg 1024w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/grok_1785070784967-300x201.jpg 300w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/grok_1785070784967-768x516.jpg 768w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/grok_1785070784967.jpg 1168w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<p class=\"wp-block-paragraph\">Israeli Websites Havruta, LGBT Olim &#038; Cybertech Offline in Suspected RipperSec DDoS<\/p>\n<p class=\"wp-block-paragraph\">Several Israeli websites experienced significant accessibility problems on July 25, 2026, according to monitoring data shared in a Telegram channel linked to hacktivist activity. Screenshots posted in the channel The Comrade\u2019s displayed Check-Host HTTP reports for three domains: havruta.org.il, lgbtolim.org, and www.cybertechisrael.com. The global node maps appeared predominantly red, indicating failed checks from the majority of testing locations.For havruta.org.il, the report showed only 6 out of 59 nodes up at the time of the check, with at least one result returning a 500 Internal Server Error. lgbtolim.org and cybertechisrael.com both registered 0 out of 59 nodes up. One capture for lgbtolim.org displayed a \u201cToo Many Requests\u201d error page.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"819\" height=\"1024\" src=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/20260726_194233-819x1024.png\" alt=\"Israeli LGBTQ and Cyber Conference\" class=\"wp-image-67\" \/ loading=\"lazy\" srcset=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/20260726_194233-819x1024.png 819w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/20260726_194233-240x300.png 240w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/20260726_194233-768x960.png 768w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/20260726_194233.png 1024w\" sizes=\"auto, (max-width: 819px) 100vw, 819px\" \/><\/figure>\n<p class=\"wp-block-paragraph\">The channel\u2019s pinned message referenced MegaMedusa.apk and .exe files. MegaMedusa is a DDoS tool previously linked to the pro-Palestinian hacktivist group RipperSec. The Comrade\u2019s Group channel appears to serve as a platform for sharing monitoring results related to this activity.Havruta is an Israeli organization supporting religiously inclined Jewish LGBTQ individuals and promoting acceptance within Orthodox communities. LGBT Olim provides advocacy, information, and social support for LGBTQ Jews making Aliyah or already living in Israel. Cybertechisrael.com serves as the official site for Cybertech Global Tel Aviv, a major international cybersecurity conference and exhibition.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"819\" height=\"1024\" src=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/20260726_194324-819x1024.png\" alt=\"Israeli LGBTQ and Cyber Conference\" class=\"wp-image-68\" \/ loading=\"lazy\" srcset=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/20260726_194324-819x1024.png 819w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/20260726_194324-240x300.png 240w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/20260726_194324-768x960.png 768w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/20260726_194324.png 1024w\" sizes=\"auto, (max-width: 819px) 100vw, 819px\" \/><\/figure>\n<p class=\"wp-block-paragraph\">The outages were documented through public Check-Host results shared by The Comrade\u2019s Group, rather than independent confirmation of a successful sustained attack. Website availability can fluctuate for many reasons, including technical issues, traffic spikes, or deliberate disruption. No official statements from the affected organizations regarding the July 25 incidents were immediately available at the time of reporting. Israeli organizations and websites have faced repeated DDoS campaigns from various hacktivist groups, particularly since October 2023. RipperSec has previously claimed responsibility for similar disruptions against Israeli targets, often using tools like MegaMedusa and publicizing results via Telegram channels, including those associated with The Comrade\u2019s Group.<\/p>\n<figure class=\"wp-block-image size-large\"><img decoding=\"async\" width=\"819\" height=\"1024\" src=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/20260726_194417-819x1024.png\" alt=\"Israeli LGBTQ and Cyber Conference\" class=\"wp-image-69\" \/ loading=\"lazy\" srcset=\"https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/20260726_194417-819x1024.png 819w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/20260726_194417-240x300.png 240w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/20260726_194417-768x960.png 768w, https:\/\/cyberasia.io\/people\/wp-content\/uploads\/2026\/07\/20260726_194417.png 1024w\" sizes=\"auto, (max-width: 819px) 100vw, 819px\" \/><\/figure>\n<p class=\"wp-block-paragraph\">Organizations operating websites in geopolitically sensitive environments are advised to maintain robust DDoS protection, monitor traffic anomalies, and ensure backup communication channels remain available. Details on the duration and exact cause of these specific outages remain limited.<\/p>\n<p class=\"wp-block-paragraph\">\n<h2 id=\"verification-july25\"  style=\"color: #facc15;\">Verification Status<\/h2>\n<p>The 25 July 2026 cards for havruta.org.il, lgbtolim.org, and cybertechisrael.com come from Check-Host maps posted by The Comrade\u2019s Group, with MegaMedusa binaries pinned in the same channel. CyberAsia did not run its own probes. Node maps can go red for rate-limits, hosting faults, or a flood. No organisation statement was on record at publication. Score this as a claimed multi-site disruption, not as a confirmed application breach or data theft.<\/p>\n<h2 id=\"why-these-three\"  style=\"color: #facc15;\">Why These Three Domains Sit on the Same Card<\/h2>\n<p>Havruta and LGBT Olim are civil-society sites. Cybertech Global Tel Aviv is a commercial conference property. Grouping them on one Telegram card is a political signal, not proof of a shared hosting stack. MegaMedusa\u2019s HTTP\/2 flooder does not need a shared vulnerability. It needs DNS that resolves to an origin the operators can hammer. A conference site on a marketing CMS is as fragile as a small NGO on a single VPS.<\/p>\n<h2 id=\"mitigation-july25\"  style=\"color: #facc15;\">Mitigation &#038; Prevention Strategies<\/h2>\n<p><strong style=\"color: #facc15;\">For the affected organisations \/ IT.<\/strong><\/p>\n<ul>\n<li><strong style=\"color: #facc15;\">Put a DDoS-capable edge in front of origin.<\/strong> The pinned MegaMedusa files are built for TLS request floods, not for SQLi.<\/li>\n<li><strong style=\"color: #facc15;\">Separate the conference registration host from the brochure site<\/strong> so a homepage flood does not take ticket or donor payments down.<\/li>\n<\/ul>\n<p><strong style=\"color: #facc15;\">For attendees and community members.<\/strong><\/p>\n<ul>\n<li>If a site is down, use the organisation\u2019s official social account. Do not click \u201cbackup registration\u201d links that appear in comments during the outage.<\/li>\n<\/ul>\n<h2 id=\"analyst-note-july25\"  style=\"color: #facc15;\">Analyst Note<\/h2>\n<p>Three unrelated organisations on one Telegram card is a narrative choice. Havruta, LGBT Olim, and a commercial conference site do not share a threat model. If you run any of them, measure your own origin 5xx rate. If you do not, do not amplify the card. MegaMedusa binaries in a pinned message tell you the intended technique, not whether it worked for twelve minutes or twelve hours.<\/p>\n<h2 id=\"follow-july25\"  style=\"color: #facc15;\">What Would Upgrade This From a Claim<\/h2>\n<p>Origin 5xx logs from the three operators, a hosting-provider ticket, or a public statement. Check-Host redness plus a pinned MegaMedusa zip is below that bar. Civil-society sites and a conference brochure should not share an incident channel with each other in your SOC just because they shared a Telegram card. Measure each origin. Then decide if you even have an incident.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Israeli Websites Havruta, LGBT Olim &#038; Cybertech Offline in Suspected RipperSec DDoS Several Israeli websites experienced significant accessibility problems on July 25, 2026, according to monitoring data shared in a Telegram channel linked to hacktivist activity. Screenshots posted in the channel The Comrade\u2019s displayed Check-Host HTTP reports for three domains: havruta.org.il, lgbtolim.org, and www.cybertechisrael.com. The [&hellip;]<\/p>\n","protected":false},"author":3,"featured_media":66,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[10,14,21,23,22,24],"threat_actors":[409],"class_list":["post-65","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ddos","tag-cyberattack","tag-ddos-attack","tag-hacktivist","tag-israel","tag-lgbtq","tag-rippersec","threat_actor-rippersec"],"_links":{"self":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts\/65","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/comments?post=65"}],"version-history":[{"count":7,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts\/65\/revisions"}],"predecessor-version":[{"id":3958,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/posts\/65\/revisions\/3958"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/media\/66"}],"wp:attachment":[{"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/media?parent=65"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/categories?post=65"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/tags?post=65"},{"taxonomy":"threat_actor","embeddable":true,"href":"https:\/\/cyberasia.io\/people\/wp-json\/wp\/v2\/threat_actors?post=65"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}