Threat Bulletin 1426: credential stuffing against a sports betting platform in Central Europe
credential stuffing against a sports betting platform in Central Europe, peaking at 115.3 million requests per second. Mitigated in 0.476 seconds.
credential stuffing against a sports betting platform in Central Europe, peaking at 115.3 million requests per second. Mitigated in 0.476 seconds.
carpet-bombing UDP flood against a B2B SaaS platform in North America, peaking at 310.0 Gbps. Mitigated in 0.755 seconds.
UDP reflection (NTP) against a sports betting platform in the Nordics, peaking at 59.3 Gbps. Mitigated in 0.884 seconds.
HTTP POST flood against a tax authority portal platform in Latin America, peaking at 863.4 million requests per second. Mitigated in 0.303 seconds.
CLDAP reflection against a video streaming platform in Latin America, peaking at 253.3 Gbps. Mitigated in 0.407 seconds.
Here is a question we could not answer well a year ago: what really happens with anycast is not magic: how we route attacks across 40 PoPs? We can answer it now.Measuring…
search endpoint flood against a online casino platform in the Nordics, peaking at 359.8 million requests per second. Mitigated in 0.841 seconds.
Slowloris against a tax authority portal platform in the Middle East, peaking at 595.8 million requests per second. Mitigated in 0.937 seconds.
Rolled out to all points of presence on 2 August 2026. No action is required. Security: updated TLS library to […]
HTTP/2 rapid reset against a video streaming platform in Western Europe, peaking at 812.9 million requests per second. Mitigated in 0.194 seconds.
UDP reflection (DNS) against a tax authority portal platform in Western Europe, peaking at 80.3 Gbps. Mitigated in 0.788 seconds.
TLS handshake exhaustion against a municipal services platform in the UK, peaking at 956.4 million requests per second. Mitigated in 0.922 seconds.