
6/3/2026 · Bryton Herdes, Bryce Walters, Mingwei Zhang
What this post added
This post details an investigation into route hijacks facilitated by forged BGP AS PATHs. It analyzes specific hijack examples, explains the vulnerabilities in BGP related to First AS checking, and proposes the enforcement of First AS matching the peer AS as a critical security measure. The post also describes an experiment where Cloudflare intentionally violated the First AS rule to measure its acceptance on the internet.