ELSEIF
Your brief EB
311 stories from 93 feeds 202 clusters Refreshed 10 minutes ago next pull 14:51

INFRA Signal 573

Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave

Cloudflare's H1 2026 DDoS Threat Report documents a sharp rise in hyper-volumetric attacks, with DNS and CLDAP reflection vectors displacing botnet floods as the dominant threat pattern.

WHY IT MATTERS

The shift toward reflection-amplification vectors means attackers can generate terabit-scale floods without large botnets, lowering the barrier to catastrophic attacks. With 90% of attacks ending in under 10 minutes and some lasting only 35 seconds, manual mitigation is structurally impossible, only always-on automated protection can respond in time.

Written by elseif from the cluster below · every claim links back to a source

The three things worth knowing

01

Cloudflare mitigated 935 network-layer attacks exceeding 1 Tbps in H1 2026, with an 805-attack surge in Q2 alone representing a more than six-fold increase over Q1.

02

DNS Floods grew from 25.7% to 40.0% of network-layer attacks quarter-over-quarter, and CLDAP Floods surged 580% to become the third-ranked vector.

03

Operation PowerOFF, a 21-country law enforcement action targeting over 75,000 DDoS-for-hire users, coincided with a decline in attack volume after April's peak.

THE READ

What the cluster adds up to.

ORIGINAL ANALYSIS

The defining change in H1 2026 is the migration of attack volume from botnet-driven floods to reflection and amplification techniques. DNS-based attacks alone accounted for 34.3% of all network-layer activity, and DNS Floods jumped from 25.7% to 40.0% of network-layer attacks between Q1 and Q2. CLDAP Floods surged 580% quarter-over-quarter to become the third-ranked vector. For engineers, this means attackers no longer need a massive compromised host fleet to generate enormous traffic, they can abuse open resolvers and amplification protocols to achieve similar or greater volume with fewer resources.

The scale of hyper-volumetric attacks grew dramatically. Cloudflare mitigated 935 network-layer attacks exceeding 1 Tbps across H1 2026, with 805 of those occurring in Q2, a more than six-fold increase over Q1. April 2026 alone saw 6.46 trillion requests and 165 petabytes of DDoS traffic. For teams operating their own infrastructure without cloud-scale scrubbing, even the median attack is dangerous: 96.62% of network-layer attacks stayed under 500 Mbps, but Cloudflare notes that a 100 Mbps flood can overwhelm a single server and a 100 Gbps attack can knock most unprotected data centers offline.

The temporal profile of attacks makes manual response a non-starter. 90.60% of attacks ended in under 10 minutes, and Cloudflare observed record-breaking assaults that lasted only 35 seconds. By the time an alert reaches a security analyst, the attack has already completed. The cascading effects, routing instability, TCP retransmissions, application timeouts, and downstream service degradation, can persist for hours or days after the burst itself ends. This reality favors always-on automated mitigation over on-demand or human-in-the-loop solutions.

Geopolitical events shaped the targeting patterns in ways that matter for capacity planning and threat modeling. Media, Production & Publishing was the most-attacked industry in both quarters at 14.2% of all mitigated HTTP DDoS requests, driven by coverage of Iran, Ukraine, and the World Cup. Turkey rose to the third most-attacked country ahead of the NATO Summit in Ankara. The Government sector jumped from rank 29 to rank 9, the largest single-sector movement of the period, during something the report calls Operation Epic Fury. Organizations adjacent to these sectors or events should expect elevated risk during similar geopolitical flashpoints.

Law enforcement activity appears to have had a measurable dampening effect. After April's peak, request and volume levels declined, which Cloudflare attributes to Operation PowerOFF, a coordinated action across 21 countries that targeted over 75,000 DDoS-for-hire users, took down 53 domains, issued 25 search warrants, and resulted in four arrests. This is a single data point from one operator's perspective, and the report does not claim a permanent reduction. But it suggests that takedowns of booter services can produce short-term drops in attack volume, even if the underlying vector ecosystem remains intact.

Written by elseif from the cluster below · checked for specifics the sources never contained

THE CLUSTER

Same story, 1 feed.

ORDERED BY FIRST SEEN
Cloudflare Cloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new wave Open ↗