Web DDoS attacks double as AI shrinks exploit windows to zero
A report from Radware indicates that web DDoS attacks increased by 110.6% in the first half of 2026, with AI-driven vulnerability discovery reducing the mean time to exploit to negative eight hours. The findings highlight a shift toward direct-path volumetric UDP floods, posing significant risks to streaming infrastructure availability.
Key Takeaways
- Direct-path volumetric UDP floods now account for over 80% of all mitigated packets, replacing traditional reflection techniques.
- North American infrastructure faces the highest risk, with projected attack volumes expected to rise 190% by year-end.
- Anthropic PBC’s Claude Mythos demonstrated AI's capability by identifying a 27-year-old flaw in the OpenBSD TCP stack.
- Only 17.2% of surveyed organizations report full visibility into the autonomous AI agents running within their environments.
Why It Matters
The shift toward direct-path volumetric UDP floods poses a critical threat to streaming availability, as these attacks can overwhelm the high-bandwidth infrastructure required for live video delivery. With AI models like Claude Mythos accelerating vulnerability discovery, the 'negative' patch window means defenders must now mitigate threats before they are even publicly documented. For the streaming ecosystem, this necessitates a move away from reactive patching toward automated, AI-driven edge security that can identify anomalous traffic patterns in real-time. Watch for whether CDN providers integrate local AI agents to counter the 80% zero-day exploit rate reported by Radware.
Additional Context
Radware's threat intelligence has become a key benchmark for CDN and streaming infrastructure operators assessing volumetric attack trends. In its 2025 Global Threat Analysis Report, Radware documented a 44% year-over-year increase in DDoS attacks globally, with application-layer attacks rising fastest among media and entertainment targets, establishing the trajectory that culminated in the 110.6% web DDoS surge reported for H1 2026. The company's research team, led by Pascal Geenens, has consistently flagged the gaming and streaming verticals as disproportionate targets, a pattern that aligns with the direct-path UDP flood vectors identified in the latest data. Competing threat intelligence from Cloudflare corroborates the acceleration: Cloudflare reported mitigating a record 7.3 Tbps DDoS attack in Q2 2026, a 40% increase over the previous quarter's peak, underscoring that the volumetric escalation Radware describes is not isolated to its sensor network but reflects a broader industry-wide trend affecting content delivery networks.
The business implications for streaming and CDN providers are intensifying as regulatory pressure mounts around service availability. The EU's NIS2 Directive, which entered full enforcement in October 2024, requires operators of essential services including digital infrastructure providers to report significant incidents within 24 hours and implement proportionate risk-management measures, creating compliance exposure for streaming platforms that suffer prolonged outages from DDoS events. In the United States, the SEC's cybersecurity disclosure rules adopted in July 2023 already compel public companies to report material incidents within four business days, a requirement that could apply to streaming companies whose services are disrupted by the attack patterns Radware describes. On the vendor side, Radware announced in March 2026 that it had expanded its DDoS protection service with AI-driven behavioral analysis capabilities specifically targeting zero-day exploit traffic, positioning the product as a direct response to the negative patch window phenomenon. Meanwhile, Akamai reported in its Q2 2026 earnings call that DDoS mitigation revenue grew 28% year-over-year, driven by demand from media and entertainment customers, signaling that the threat environment Radware quantifies is translating into measurable commercial demand across the CDN sector.
Technical benchmarks from independent testing highlight the gap between current mitigation capacity and the attack volumes Radware's data implies. NETSCOUT's ATLAS threat intelligence reported that the average DDoS attack duration targeting media and entertainment infrastructure increased to 4.2 hours in H1 2026, up from 2.8 hours a year earlier, suggesting that streaming services face sustained multi-hour disruption windows that exceed typical failover recovery times. The AI dimension of the threat is further illustrated by Anthropic's own disclosures: Anthropic published research in May 2026 showing that Claude models can identify exploitable software vulnerabilities at rates comparable to human security researchers, with some categories of bugs discovered in under 30 minutes, providing a technical basis for Radware's finding that the mean time to exploit has turned negative. For CDN operators, the convergence of AI-accelerated vulnerability discovery and volumetric attack escalation means that traditional signature-based mitigation is insufficient, pushing the industry toward behavioral anomaly detection deployed at the network edge.
Read full article at siliconangle.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source