Threat Bulletin 1101: cache-busting query flood against a B2B SaaS platform in the Nordics
cache-busting query flood against a B2B SaaS platform in the Nordics, peaking at 440.8 million requests per second. Mitigated in 0.018 seconds.
cache-busting query flood against a B2B SaaS platform in the Nordics, peaking at 440.8 million requests per second. Mitigated in 0.018 seconds.
Rolled out to all points of presence on 6 March 2025. No action is required. Log streaming now supports per-tenant […]
HTTP/2 rapid reset against a tax authority portal platform in the Nordics, peaking at 929.3 million requests per second. Mitigated in 0.487 seconds.
Rolled out to all points of presence on 23 February 2025. No action is required. New dashboard widget: CVE-2026-1127. Fixed […]
search endpoint flood against a education platform platform in Western Europe, peaking at 167.3 million requests per second. Mitigated in 0.027 seconds.
how we deploy rule changes to every edge in under 30 seconds sounds like a narrow topic. It turns out to touch almost every part of how an edge network behaves under…
WebSocket connection flood against a municipal services platform in the Nordics, peaking at 60.1 million requests per second. Mitigated in 0.521 seconds.
UDP reflection (NTP) against a ticketing platform in Western Europe, peaking at 108.1 Gbps. Mitigated in 0.897 seconds.
UDP reflection (NTP) against a crypto exchange platform in Latin America, peaking at 19.2 Gbps. Mitigated in 0.190 seconds.
GRE flood against a retail banking platform in the UK, peaking at 155.6 Gbps. Mitigated in 0.541 seconds.
We get asked about rules engine 2.0: priorities, dry runs and rollbacks more than almost anything else, so here is the long answer.Why per-route baselines matterA thousand requests per second to your…
Here is a question we could not answer well a year ago: what really happens with how we test WAF rules against seven days of real traffic? We can answer it now.The…