TRENDING
Rows of identical brass-colored apartment mailboxes with small locks and name labels along an orange corridor wall
October 9, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
Street-level upward view of the Monetary Authority of Singapore building and neighbouring office towers under a pale sky
October 9, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
Cast-iron late Qing dynasty coin minting press with a large flywheel, displayed in a museum case
October 9, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google
Rows of closed oak library card catalog drawers, each with a brass pull and a blank label holder
October 9, 2026
How to Encrypt PII in Python and Keep It Searchable With Blind Indexes
Close-up of a vintage Western Electric manual telephone switchboard with orange lamps, red patch cords plugged into jacks, a rotary dial and a black handset
October 9, 2026
Microsoft’s Agent Lightning v1.0 Turns Agent Training Into a Sample-Accounting Problem
09 Oct 2026
SXZ.io SXZ.io
  • Home
Search the Site
Popular Searches:
Technology Amazon AI
Recent Posts
Two orange safety relief valves on grey pressure vessels in an industrial plant
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
Yellow diamond-shaped merging traffic warning sign showing a side road joining a main road
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A lugworm lying on wet sand and mud at low tide
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
SXZ.io SXZ.io
  • Home

Categories

Articles 232 Posts
News 234 Posts
Learning Hub 204 Posts
Home/Articles/Cloudflare’s H1 2026 DDoS Report Turns the News Cycle Into an Attack Signal
Articles

Cloudflare’s H1 2026 DDoS Report Turns the News Cycle Into an Attack Signal

Cloudflare's first combined half-year DDoS report shows attacks over 1 Tbps grew sixfold quarter over quarter, with targeting increasingly tracking real-world news events from the Iran strikes to a...

August 11, 2026 6 Min Read
39

Cloudflare’s Cloudforce One threat intelligence team published its first combined half-year DDoS Threat Report on August 11, 2026, and the headline number is stark: network-layer attacks exceeding 1 Tbps grew more than sixfold between the first and second quarters of the year, a 519 percent quarter-over-quarter surge. The more interesting finding buried inside the report, though, is not about size. It is about timing. Across the report’s data, the clearest pattern is that DDoS targeting increasingly tracks the news cycle: strikes on Iran, the war in Ukraine, a World Cup, a NATO summit in Turkey. Attackers, it turns out, read the headlines too.

Table Of Content

  • A Sixfold Jump in the Heaviest Attacks
  • DNS and CLDAP Floods Push Botnets Aside
  • Where the Standing Record Still Sits
  • Media Outlets Take the Brunt, Gambling Sites Close the Gap
  • When Geopolitics Writes the Target List
  • Operation Epic Fury and the Strikes on Iran
  • Turkey’s Climb Ahead of the Ankara NATO Summit
  • Government’s Steepest Climb of the Year
  • Brazil Overtakes the US as the Top Source of Attack Traffic
  • Law Enforcement Chips Away at the Supply Side
  • What This Means for Defenders

A Sixfold Jump in the Heaviest Attacks

Cloudflare mitigated 935 network-layer DDoS attacks that exceeded 1 Tbps across the first half of 2026, more than four times the 219 such attacks the company recorded in the fourth quarter of 2025 alone. Almost all of that half-year growth landed in the second quarter: 130 attacks crossed the 1 Tbps line in Q1, and roughly 805 crossed it in Q2, the 519 percent jump that anchors the report’s headline.

Zoom out and the overall volume is larger still. Cloudflare says it mitigated 23.2 million network-layer DDoS attacks and blocked 29.64 trillion malicious HTTP requests over the six-month period, an average of about 5,343 network-layer attacks every hour, or roughly 128,000 a day. April was the single busiest month, with 6.46 trillion HTTP requests and 165 petabytes of attack traffic absorbed in thirty days, a figure independently confirmed in SiliconANGLE’s review of the report.

Most of that volume is still small and short-lived: roughly nine in ten attacks resolved in under ten minutes, consistent with the throwaway, opportunistic pattern DDoS defenders have described for years. What changed is the tail. Attacks lasting more than three hours, still under 1 percent of the total, nearly tripled in raw count quarter over quarter, climbing from around 38,900 to roughly 109,000, a detail BleepingComputer and SiliconANGLE both flagged. That suggests at least some attackers are choosing to sustain pressure rather than fire once and move on.

DNS and CLDAP Floods Push Botnets Aside

The report also describes a shift in how attacks get built. Cloudflare says the center of gravity moved from botnet-driven floods toward reflection and amplification techniques: methods that bounce a small, spoofed request off a misconfigured third-party server to generate a disproportionately large response aimed at the real target. DNS-based attacks accounted for 34.3 percent of all network-layer activity in H1 2026, and DNS floods specifically climbed from 25.7 percent of network-layer attacks in Q1 to 40.0 percent in Q2. CLDAP floods, which abuse the Connectionless Lightweight Directory Access Protocol that many Active Directory environments still expose, surged sharply enough quarter over quarter to become the third most common network-layer vector by Q2.

Where the Standing Record Still Sits

For scale, it is worth remembering where the outer edge of this threat currently sits. Cloudflare’s own fourth-quarter 2025 report disclosed the current all-time record: a 31.4 Tbps attack that lasted just 35 seconds, followed within weeks by a separate flood that exceeded 200 million HTTP requests per second. Cloudflare attributed both to Aisuru-Kimwolf, a botnet built largely from compromised Android TV boxes rather than the routers and IoT devices that powered earlier Mirai-style swarms. The new H1 2026 report is not about a bigger record; it is about how often attackers are now approaching the 1 Tbps mark on a routine basis, a threshold that used to be exceptional and now shows up hundreds of times per quarter.

Media Outlets Take the Brunt, Gambling Sites Close the Gap

Sector data in the report reinforces the news-cycle theory. Media, production, and publishing companies were the single most-targeted industry in both quarters, absorbing about 14 percent of all mitigated HTTP DDoS requests, roughly four times as many as the second-place sector, gambling and casinos. The Register quoted Cloudflare’s Blake Darché, head of Cloudforce One and Threat Intelligence, offering a simple explanation: “DDoS attacks are uniquely effective against publishers because news expires quickly.” A newsroom knocked offline for even twenty minutes during a breaking story loses readers and ad revenue it cannot easily win back later, which makes publishers a soft, high-leverage target compared with infrastructure that can absorb a quiet overnight outage.

When Geopolitics Writes the Target List

Operation Epic Fury and the Strikes on Iran

The clearest evidence of news-driven targeting came on February 28, 2026, when Israel and the United States launched a series of strikes against Iranian leadership and infrastructure under the name Operation Epic Fury. Cloudflare says its researchers logged 149 hacktivist DDoS claims against 110 distinct organizations across 16 countries within 72 hours of the strikes, and government bodies made up roughly 48 percent of the organizations targeted worldwide during that window. It is one of the fastest, most concentrated bursts of politically motivated DDoS activity the report documents.

Turkey’s Climb Ahead of the Ankara NATO Summit

Turkey rose to the third most-attacked country in the report, a jump Cloudflare linked to the NATO summit the country hosted in Ankara in July. China and the United States remained the two most heavily targeted countries overall, per The Register’s review of the underlying data, though exact percentages for each were not disclosed in the coverage available.

Government’s Steepest Climb of the Year

The government sector overall posted the single largest sectoral move Cloudflare tracked in 2026 so far, jumping from the 29th most-targeted industry to 9th. Between the Iran strikes, the war in Ukraine, and a packed calendar of diplomatic and sporting events including a World Cup, the report reads less like a catalogue of random opportunistic noise and more like a map of wherever the world’s attention happened to be pointed that week.

Brazil Overtakes the US as the Top Source of Attack Traffic

The report also tracks where attacks originate, not just where they land. Brazil overtook the United States as the largest source of DDoS traffic for the half, responsible for 15 percent of mitigated attack traffic against the United States’ 13 percent, a shift driven by a second-quarter surge that pushed Brazil’s individual quarterly share to 21 percent. Indonesia held a steady third place in both quarters, according to SiliconANGLE’s reporting on the data. None of this necessarily means the people directing the attacks are sitting in Sao Paulo or Jakarta: DDoS traffic is generated by compromised devices, so a country’s ranking as a “source” mostly reflects how many poorly secured routers, cameras, and other connected gadgets sit on its networks, not the nationality of whoever is renting the botnet.

Law Enforcement Chips Away at the Supply Side

The report’s one piece of good news for defenders came from outside Cloudflare’s own telemetry. In April, a 21-country law enforcement operation called Operation PowerOFF targeted the booter and stresser services that rent out DDoS capacity to anyone with a credit card. The action produced four arrests, 53 seized domains, and warnings issued to more than 75,000 users of DDoS-for-hire platforms. It is a small dent against 23.2 million attacks, but it targets the supply side of an industry that otherwise makes launching a multi-gigabit flood about as easy as checking out on an e-commerce site.

What This Means for Defenders

The practical takeaway for security teams has less to do with the raw growth numbers and more to do with how to read them. If your organization sits in a sector Cloudflare flags as newly popular with attackers, media, gambling, or anything adjacent to a live geopolitical story, your DDoS exposure now tracks the news cycle around your industry, not just your own visibility or size. That argues for always-on mitigation rather than reactive scaling: with most attacks resolving in minutes, there usually is not time to stand up defenses after the first packets already arrive. It also argues for hardening the reflection surfaces attackers are leaning on hardest right now. DNS and CLDAP floods do not require compromising the victim at all; they require finding misconfigured, open, third-party servers elsewhere on the internet to bounce traffic off. Organizations running their own DNS or LDAP infrastructure should confirm those services are not open to abuse from arbitrary source IPs, since that exact kind of misconfiguration is what fueled the vector shift Cloudflare is describing.

Tags:

CloudflareCybersecurityddosNetwork SecurityThreat Intelligence

Share

Front view of an NVIDIA DGX Spark AI computer, one of the hardware platforms that runs Nemotron 3.5 Lightning
Previous Post

NVIDIA’s Nemotron 3.5 Lightning Ships With Day-One Ubuntu Support From Canonical

The muddy Fraser River meeting the blue-green Thompson River at their confluence near Lytton, British Columbia
Next Post

How to Fix Broken Distributed Traces Between Python Microservices With OpenTelemetry

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Latest
08 Oct
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
08 Oct
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
Trending
October 8, 2026
How to Add Backpressure and Load Shedding to a Python Service Before Overload Takes It Down
October 8, 2026
GitHub’s Git Rebuild Turns Repository Durability and Read Scale Into Two Separate Problems
October 8, 2026
A Compromised Admin Account Put the Shai-Hulud Worm Into AI Sandbox Maker Tensorlake’s npm SDK
October 8, 2026
How to Prevent Broken Object Level Authorization (IDOR) in a FastAPI App
October 8, 2026
Singapore’s AI Guidelines Turn Independent Review Into a Question of Who Sets the Risk Rating
October 8, 2026
Attackers Hijacked the .gh, .sl and .as Country Domains and Minted HTTPS Certificates for Google

Related Posts

Blue-lit server racks in a modern data center, illustrating the compute infrastructure behind the AI boom.
Articles

The AI Boom Is Spending Real Money Before Proving Real Returns

June 7, 2026
Rows of server racks in a data center representing network infrastructure targeted by botnets
News

C0XMO Botnet Shows Why Old Router Firmware Still Matters

June 7, 2026
Technician working with a laptop beside server racks, representing enterprise AI retrieval infrastructure
Articles

Google’s Agentic RAG Push Makes Enterprise AI Less of a One-Shot Guess

June 7, 2026
A person with a laptop and smartphone, representing digital attention and AI-assisted work
Articles

AI Chatbots Are Making Attention a Design Problem

June 7, 2026
SXZ.io SXZ.io
  • [email protected]

Categories

Articles
Learning Hub
News

All Rights Reserved by SXZ.io ©2026