Threat Bulletin 1316: HTTP/2 rapid reset against a airline booking platform in the UK
HTTP/2 rapid reset against a airline booking platform in the UK, peaking at 656.8 million requests per second. Mitigated in 0.815 seconds.
HTTP/2 rapid reset against a airline booking platform in the UK, peaking at 656.8 million requests per second. Mitigated in 0.815 seconds.
keeping our control plane alive when the data plane is on fire sounds like a narrow topic. It turns out to touch almost every part of how an edge network behaves under…
Rolled out to all points of presence on 11 February 2026. No action is required. API: new endpoint /v1/incidents/{id}/export. Log […]
carpet-bombing UDP flood against a municipal services platform in the Nordics, peaking at 319.9 Gbps. Mitigated in 0.719 seconds.
ACK flood against a online casino platform in Western Europe, peaking at 75.6 Gbps. Mitigated in 0.285 seconds.
search endpoint flood against a airline booking platform in Iberia, peaking at 859.4 million requests per second. Mitigated in 0.011 seconds.
UDP reflection (NTP) against a B2B SaaS platform in Iberia, peaking at 175.0 Gbps. Mitigated in 0.205 seconds.
memcached amplification against a tax authority portal platform in Southeast Asia, peaking at 211.6 Gbps. Mitigated in 0.286 seconds.
search endpoint flood against a retail banking platform in Central Europe, peaking at 227.3 million requests per second. Mitigated in 0.430 seconds.
This post is about rate limiting APIs without breaking legitimate integrations. It started, as most of our posts do, with an incident that did not go the way we expected.Latency budgetOur budget…
credential stuffing against a gaming community platform in the Middle East, peaking at 481.3 million requests per second. Mitigated in 0.460 seconds.
why we wrote our proxy data plane in Rust sounds like a narrow topic. It turns out to touch almost every part of how an edge network behaves under attack.Latency budgetOur budget…