Radware finds web DDoS attacks doubled as the patch window turns negative
A new report out today from Radware Ltd. finds that web distributed denial-of-service attacks more than doubled over the first six months of 2026.
Mitigations rose 110.6% against the same period last year, and 36.3% against the second half of 2025. The half alone came to nearly 83% of everything the company mitigated across all of 2025.
The H1 2026 Global Threat Analysis Report covers January through June. Radware built it from telemetry across its cloud and managed security services. The company’s threat intelligence team supplied the rest.
If web DDoS volumes hold at the first-half pace, Radware projects 2026 to close 166% above 2025. North American infrastructure fares worst in the projection, with the rise there reaching 190% by year’s end.
Elsewhere the projected growth is a fraction of that. Radware has Europe, the Middle East and Africa rising 60% this year, in a region that historically absorbed more than half of all web DDoS attacks. Asia-Pacific comes in lowest at 27%.
Customers were found to have absorbed an average of 110 network-layer attacks a day. That is up 36.6% on Radware’s 2025 baseline.
Reflection and amplification have fallen out of favor. Direct-path volumetric floods took over, with stateless UDP floods alone accounting for 73% of mitigated packets. Add fragmented UDP traffic and the share passes 80%.
The technology sector absorbed 59.4% of network DDoS activity, averaging 509 attacks per customer each day, well ahead of financial services on 20.8%. Customers in the Middle East were hit most often, at 520 attacks a day.
The sharpest figure in the report is a negative one. Measured from public disclosure of a Common Vulnerabilities and Exposures record to the first confirmed attack in the wild, mean time to exploit stood at negative eight hours as of July 23, on Zero Day Clock project data cited in the report.
The clock starts at disclosure, so an attack that lands earlier counts as negative time. In 2025 the same measure sat at 21.5 days. Defenders had 53 days in 2024. Radware’s zero-day rate, the share of flaws exploited on or before the day they are disclosed, has passed 80%.
Radware attributes much of that compression to frontier artificial intelligence models. The report points to Anthropic PBC’s Claude Mythos, which surfaced a 27-year-old flaw in OpenBSD’s TCP stack that survived decades of human review and fuzzing. Cheaper open-weight models can reproduce much of that work when the scaffolding around them is built properly, Radware said.
Local AI agents drew a separate warning. Running continuously on developer endpoints, they can call APIs and install software dependencies without being asked, which Radware flags as an amplifier for supply chain attacks. The report cites the Mini Shai-Hulud attacks on npm packages.
Radware’s own survey of 377 organizations found 77% deploying or implementing AI agents and autonomous workflows. Only 17.2% reported full visibility into the agents running in their environment. The API picture is much the same. Some 81.2% push production API updates at least weekly, while 6.9% fully document their internal APIs.
Pascal Geenens, vice president of threat intelligence at Radware, said attackers are now “operating at machine speed.” Organizations are deploying agents and APIs without a complete view of the attack surface they are creating, he said, and the widening gap between attack speed and response time is changing the threat landscape.
Hacktivist DDoS claims continued to track geopolitics, with Europe drawing 48% of all claims and Israel 16.9%. Public claims have been contracting since a peak in the second quarter of 2025. March broke that trend with a 103% jump Radware ties to military events in the Middle East. Pro-Russian collective NoName057(16) generated 40.5% of everything recorded in the half.
Image: Radware
A message from John Furrier, co-founder of SiliconANGLE:
Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.
- 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
- 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network
Are you an AWS customer? Support SiliconANGLE financially by buying your AWS services from our Marketplace portal page and links: https://siliconangle.com/aws-marketplace/
About SiliconANGLE Media
Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.