ddos

4 posts

cloudflare

Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave (opens in new tab)

Cloudflare’s H1 2026 DDoS report shows a sharp rise in extreme attacks alongside a shift toward reflection and amplification techniques. Although most attacks remained brief and relatively small, 935 network-layer attacks exceeded 1 Tbps, making automated, always-on protection essential. Geopolitical events also strongly influenced which industries and countries were targeted. ## DDoS Activity Reached Record Levels - Cloudflare mitigated: - 23.2 million network-layer DDoS attacks - 29.64 trillion HTTP DDoS requests - This equals roughly 5,343 network-layer attacks per hour, or 128,000 per day. - April was the peak month, with 6.46 trillion requests and 165 petabytes of traffic. - Activity declined afterward, possibly following Operation PowerOFF, which targeted: - More than 75,000 DDoS-for-hire users - 53 domains - 25 search warrants - Four arrests across 21 countries ## Hyper-Volumetric Attacks Surge - Cloudflare mitigated 935 network-layer attacks exceeding 1 Tbps during H1. - Q2 alone accounted for 805 such attacks, more than six times Q1’s total. - Hyper-volumetric attacks are defined as exceeding: - 1 Tbps - 1 billion packets per second - 1 million requests per second ## Most Attacks Remained Short and Small - Despite record-breaking incidents: - 96.62% of network-layer attacks stayed below 500 Mbps. - 90.60% lasted less than 10 minutes. - Even “small” attacks can be damaging: - 100 Mbps can overwhelm an individual server or website. - 100 Gbps can disable most unprotected data centers. - Attacks above 1 Tbps can stress major infrastructure. - Attackers may combine high packet rates with lower bandwidth, or the reverse, to target different network weaknesses. - Some extreme attacks lasted only 35 seconds, leaving no realistic opportunity for manual intervention. - Short attacks can still cause prolonged routing instability, retransmissions, timeouts, and downstream outages. ## Media and Government Organizations Were Major Targets - Media, Production & Publishing was the most targeted industry in both quarters. - It represented 14.2% of mitigated HTTP DDoS requests. - Coverage of conflicts in Iran and Ukraine, along with the World Cup, contributed to sustained targeting. - Following Operation Epic Fury against Iran, government organizations experienced a major spike: - Researchers recorded 149 hacktivist DDoS claims against 110 organizations in 16 countries. - Nearly 47.8% of targeted organizations were in the government sector. - Government moved from 29th place in Q1 to 9th in Q2. ## China and Turkey Rose Among Targeted Locations - China was the most attacked location in Q2, receiving 22.4% of global HTTP DDoS requests. - The United States ranked second with 18.8%. - Turkey more than doubled its share of attack traffic and reached third place. - The increase coincided with security activity surrounding the 2026 Ankara NATO Summit. ## Brazil Became the Leading Attack Source - Brazil overtook the United States as the leading source country: - Brazil: 14.9% during H1, rising to 21.4% in Q2 - United States: 13.4% - Indonesia remained the third-largest source country. ## DNS and CLDAP Attacks Gained Ground - DNS-based attacks accounted for 34.3% of network-layer activity. - DNS Floods rose from 25.7% to 40.0% of network-layer attacks between Q1 and Q2. - DNS Floods directly overwhelm authoritative DNS servers with query volume. - DNS Amplification abuses open resolvers and spoofed source addresses to send larger responses to victims. - CLDAP Floods increased 580% quarter-over-quarter and became the third-most common vector in Q2. - These attacks exploit exposed LDAP-over-UDP endpoints, particularly those associated with Active Directory. - Overall, the attack landscape shifted from conventional botnet floods toward reflection and amplification methods. Cloudflare’s findings reinforce that DDoS defenses must be automated, distributed, and continuously active. Short attack durations and rapidly increasing traffic volumes make manual or on-demand mitigation too slow to protect services reliably.

cloudflare

Celebrating 12 years of Project Galileo (opens in new tab)

Project Galileo, launched by Cloudflare 12 years ago, provides free cybersecurity services to more than 3,400 civil society websites across 120 countries. Its anniversary report shows that journalists, human rights groups, and nonprofits face more frequent and intense attacks than other Internet users, especially during politically sensitive work. Cloudflare is responding with expanded research, case studies, partnerships, and a call for accessible security protections. ## Project Galileo’s Mission and Reach - The program protects journalists, human rights defenders, and nonprofit organizations from being forced offline. - It now supports more than 3,400 websites in 120 countries. - Cloudflare’s global network spans more than 335 cities in 125 countries, with over 20% of the web behind its infrastructure. ## Cyberattacks Targeting Civil Society Cloudflare’s first comprehensive annual report compares threats against civil society with attacks against Internet users more broadly. - DDoS attacks were the most common threat, often lasting for days or weeks. - Civil society organizations faced website vulnerability exploitation attempts at more than seven times the rate of other Cloudflare customers. - Media organizations were especially affected. - Journalists working in exile received nearly four times more malicious traffic than journalism organizations overall. - Almost 10% of emails processed for civil society organizations contained potential phishing material. - Attacks often coincided with investigative reporting, public advocacy, or other critical organizational activities. Cloudflare calls for affordable cybersecurity, greater transparency around cyberattacks and Internet shutdowns, and default integration of AI-aware and post-quantum protections. The company plans to publish the report annually to track changing threat patterns. ## Case Studies of Project Galileo Participants Sixteen case studies illustrate the varied security needs of participating organizations, including: - Digital rights groups such as SHARE Foundation. - Investigative and independent media organizations, including OCCRP, elTOQUE, and China Digital Times. - Organizations documenting conflict and human rights abuses, such as Ukraine War Archive. - Research and public-interest institutions including Our World in Data and the Bulletin of Atomic Scientists. - Environmental, legal, scientific, and humanitarian groups such as Sea Shepherd Brazil, Activist Rights, and the Royal Meteorological Society. ## Expanding the Partner Network Project Galileo depends on 59 civil society partners that review and approve applications. - Partners contribute local expertise and help identify organizations that need protection. - Previous collaborations produced initiatives such as email security with Protect.ngo and Internet measurement work through UNICEF’s Giga project. - Cloudflare has focused on expanding access beyond North America and Europe through regional events and partnerships. - Recent Asia-Pacific partners include EngageMedia and the OpenCulture Foundation. - The anniversary announcement introduces three additional partners serving journalists, including the International Center for Journalists and Media Cluster Norway. Project Galileo’s next phase combines threat intelligence, direct protection, regional partnerships, and specialized services for journalism organizations. Its broader recommendation is that reliable cybersecurity should be treated as essential infrastructure for civil society and public discourse.

cloudflare

Introducing the 2026 Cloudflare Threat Report (opens in new tab)

Cloudflare’s 2026 Threat Report argues that cyberattacks are shifting from brute-force intrusion toward high-trust exploitation. Attackers increasingly prioritize “Measure of Effectiveness” (MOE)—the greatest operational result for the least effort—using stolen tokens, AI, trusted cloud services, and social engineering rather than costly custom exploits. The report concludes that defenders must focus on identity, integrations, infrastructure resilience, and continuous monitoring of legitimate tools. ## Measure of Effectiveness (MOE) - MOE measures the ratio between an attacker’s effort and the operational outcome. - Threat actors favor: - Stolen session tokens over expensive zero-day exploits. - Reputation-based infrastructure such as LotX over custom servers. - AI-assisted automation over manually written tooling. - The most dangerous actors are those able to combine intelligence and technology into continuous, high-speed operations. ## Eight trends shaping the 2026 threat landscape - **AI-driven attacker operations** - Generative AI supports real-time network mapping, exploit development, and deepfake creation. - Lower-skilled attackers can now conduct more sophisticated, high-impact campaigns. - **State-sponsored infrastructure pre-positioning** - Groups such as Salt Typhoon and Linen Typhoon are targeting North American telecommunications, government, commercial, and IT services. - Their goal is to maintain access that can provide long-term geopolitical leverage. - **Over-privileged SaaS integrations** - Third-party APIs can expand a single compromise across hundreds of organizations. - The GRUB1 breach of Salesloft demonstrates the risks created by excessive integration privileges. - **Weaponized trusted cloud tools** - Attackers use services such as Google Calendar, Dropbox, GitHub, Google Drive, Microsoft Teams, and Amazon S3 to conceal malicious activity. - Legitimate enterprise traffic makes command-and-control communications harder to distinguish from normal use. - **Deepfake-based insider placement** - North Korean operators are using fraudulent identities and deepfakes to place remote IT workers inside Western companies. - These operatives support espionage and illicit revenue generation. - **Session-token theft** - Infostealers such as LummaC2 harvest active authentication tokens. - Attackers can then bypass multi-factor authentication and begin post-authentication activity. - **Internal brand spoofing** - Phishing-as-a-service tools exploit mail-relay blind spots where sender identity is not re-verified. - This enables convincing impersonation messages to arrive directly in trusted user inboxes. - **Hyper-volumetric DDoS attacks** - Botnets such as Aisuru are generating increasingly large distributed denial-of-service attacks. - The speed and scale of these attacks can overwhelm infrastructure before human responders can react. ## Living off legitimate cloud infrastructure - Attackers increasingly avoid known malicious servers and instead use legitimate SaaS, IaaS, and PaaS platforms. - Cloud services can be used to host payloads, redirect victims, deliver malware, or scale campaigns. - Amazon SES and SendGrid, for example, can be abused for phishing and malware distribution. - This “living off the land” approach—or “living off anything-as-a-service”—allows attackers to hide behind the reputation and normal traffic patterns of trusted providers. - Cloud-resource abuse is evolving from opportunistic infrastructure misuse into a deliberate nation-state strategy. Defenders should treat identity tokens, SaaS permissions, cloud activity, and trusted integrations as critical security boundaries. Organizations need least-privilege access, stronger token protection, continuous monitoring, automated DDoS mitigation, and detection that evaluates behavior—not just whether a service is legitimate.

figma

How Linear made the most of a DDoS | Figma Blog (opens in new tab)

Linear’s website went down during a DDoS attack shortly after a major redesign launch. Rather than leave visitors at a login page, the team turned the crisis into an opportunity by publishing the redesign directly as a Figma file. The unexpected workaround generated significant attention and demonstrated the value of fast, creative incident response. ## The Redesign and Its Complexity - Linear’s team had spent months exploring ideas for the new website. - The Figma file contained thousands of iterations, frames, large images, and design inspirations. - The file became so large that Figma warned it was approaching the browser’s memory limits. - Although the redesign took months to develop, the final work came together during the last 24 hours before launch. ## The DDoS Attack - On October 13, 2022, Linear’s homepage became unavailable. - The team initially suspected that the new redesign had introduced a technical problem. - Investigation revealed that the outage was caused by a distributed denial-of-service attack overwhelming the site with traffic. - Their immediate priority was restoring access to the application, so visitors were redirected from site pages directly to the login page. ## Turning the Outage into an Alternative Homepage - The direct login redirect restored app access but made the public launch feel anticlimactic. - As social media discussions about the redesign continued, Jori Lallo suggested publishing the Figma design file itself. - Paco Coursey and Edgar Ambartsoumian were initially hesitant, but Jori encouraged them to proceed. - The Figma file became an unconventional replacement for the unavailable homepage and attracted widespread attention online. The incident shows how a team can respond constructively under pressure: stabilize critical functionality first, then use creativity to preserve the user-facing experience when the normal solution is unavailable.