LIVE · cybersecurity feed
Live wire
ddos

DDoS attacks hit record scale as 1 Tbps+ campaigns become more common

DDoS attacks grew in scale during the first half of 2026, bringing larger traffic floods, shorter attack durations, and increasingly automated campaigns. Cloudflare’s H1 2026 DDoS Threat Report shows threat actors relying on multi-vector techniques and large-scale network-layer attacks to disrupt online services across multiple industries. L3/4 attack-size distribution (bitrate), H1 2026 (Source:

zeroday.news ·

Distributed denial-of-service (DDoS) attacks reached unprecedented scales in the first half of 2026, with campaigns generating traffic in excess of one terabit per second (Tbps) becoming increasingly common. Cloudflare's H1 2026 DDoS Threat Report indicates a rise in both the volume and sophistication of these attacks, characterized by larger traffic floods, shorter durations, and greater automation.

April 2026 marked a peak month for DDoS activity, with Cloudflare reporting a high of 6.46 trillion requests and 165 petabytes of data mitigated. Despite this hyper-volumetric growth, the median DDoS attack remained relatively small and brief, with 96.62% of network-layer attacks registering under 500 Mbps and 90.60% concluding in less than ten minutes. This suggests a trend toward short, intense bursts of activity.

Attackers frequently employed multi-vector techniques, combining network-layer attacks with application-layer HTTP floods. This strategy allows threat actors to shift attack methods during an incident, complicating mitigation efforts and increasing the likelihood of service disruption. The availability of DDoS-for-hire platforms, compromised Internet of Things (IoT) devices, and automated attack tools has lowered the barrier for launching large-scale attacks, enabling threat actors to generate significant traffic without extensive infrastructure.

Government organizations experienced a notable surge in HTTP DDoS attacks during the second quarter of 2026. This increase followed "Operation Epic Fury," a period during which security researchers documented 149 hacktivist DDoS claims targeting 110 organizations across 16 countries within 72 hours, with 47.8% of these targets belonging to the government sector.

The media, production, and publishing sector was the most targeted industry throughout the first half of 2026, accounting for 14.2% of all mitigated HTTP DDoS requests, nearly four times the share of the second-ranked industry. These attacks were often short-duration and high-intensity, with many lasting less than one minute, underscoring the importance of continuous monitoring and automated defenses.

Geographically, China was the most targeted location for HTTP DDoS requests in the second quarter, accounting for 22.4% of mitigated traffic, followed by the United States at 18.8%. Turkey climbed to third place, more than doubling its share of global attack traffic. This increase in Turkey coincided with preparations for the 2026 Ankara NATO Summit, during which Turkish authorities conducted extensive pre-summit security operations.

Brazil emerged as the leading source country for DDoS attacks during the reporting period, surpassing the United States. Brazil accounted for 14.9% of mitigated DDoS request traffic, driven by a sharp increase in the second quarter where it generated 21.4% of all mitigated traffic. Indonesia maintained its position as the third-largest source country.

DNS-based attacks remained the most prevalent network-layer attack vector, with DNS Flood and DNS Amplification attacks constituting 34.3% of all such attacks. CLDAP Flood attacks saw a significant quarter-over-quarter increase of 580%, becoming the third most common network-layer attack vector in the second quarter of 2026. CLDAP attacks exploit exposed LDAP-over-UDP services to amplify traffic and overwhelm targeted systems.

ddoscloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-68820high

17th August – Threat Intelligence Report

Several significant cyber incidents were reported this week, including a ransomware attack on Colombia's Ministry of Justice and a data breach affecting Poland's primary healthcare platform, MyDr, potentially exposing data of 19 million citizens. Additionally, Levi Strauss & Co. and IEH Corporation reported cyberattacks involving social engineering and phishing, respectively, with no consumer data compromised in the former. In the realm of AI threats, researchers detailed a suspected China-linked campaign using autonomous AI agents against Taiwanese government systems and noted North Korea-linked Kimsuky's efforts to build an offline AI environment for cyberespionage. Microsoft, Apple, Adobe

CVE-2026-69414high

ShieldBreak bypasses Microsoft’s patch for earlier Defender flaw

A new vulnerability dubbed ShieldBreak (CVE-2026-69414) has been discovered in Microsoft Defender, which bypasses a previous patch for a similar flaw called RoguePlanet. This elevation of privilege vulnerability requires initial access to a machine and is dependent on Microsoft Defender being active. Microsoft has acknowledged the issue and is working on a fix, advising users to maintain security updates and exercise caution with untrusted code.

CVE-2026-15826critical

WordPress Plugin Flaw Exposes 40,000 Sites to Admin Takeover

A critical vulnerability in the WordPress User Profile Builder plugin, affecting over 40,000 sites, allows unauthenticated attackers to gain administrator access. The flaw, CVE-2026-15826, stems from a type confusion error that can trick the plugin into granting administrative privileges if specific configurations are met, such as the administrator using user ID 1 and automatic login after registration being enabled. The plugin developer has released a patch, version 3.16.5, to address the issue.

ransomware

Philips and GE investigating Clop ransomware data theft claims

Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data. [...]

security

Hacking Public Wi-Fi DNS to Steal Credentials

Criminals are hacking into public Wi-Fi devices—at hotels, conference centers, and so on—around the world and changing their DNS settings. The goal is to redirect users to fake login pages and steal their credentials.

security

Fake TikTok rewards promise cash you’ll never get

TikTok-branded rewards pages offer cash for simple tasks and daily check-ins. But getting your hands on the money is another story.