Cloudflare published its H1 2026 DDoS report and one number reframes the whole topic: 935 network layer attacks above 1 Tbps in the first half of the year. Q2 alone had 805 of them, a 519% jump over Q1. One record attack lasted 35 seconds.
Other bits worth knowing:
90.6% of attacks ended in under 10 minutes
DNS based vectors made up 34.3% of network layer activity, with DNS floods climbing to 40% quarter over quarter
CLDAP floods went up 580%
Media, production and publishing took the biggest share of mitigated HTTP attack traffic
The short duration is the interesting part. Ten minutes is faster than a human can react. By the time someone opens the ticket, reads a graph and enables a rule, it is already over, and what is left is routing instability and a cold cache that can drag on for hours.
Practical takeaways if you self host anything:
- Manual mitigation is not a plan anymore. Whatever you use has to be always on.
- Protect DNS, not only the web server. That is where the volume moved this year.
- Keep your origin IP out of public DNS history. Old A records leak more than people expect.
- Know the shape of your normal traffic curve, otherwise you cannot tell an anomaly from a good day.
We ship always on DDoS protection with Ultahost VPS and dedicated servers for exactly this reason, since reacting by hand stopped working years ago. The DNS point applies wherever you host though.
Has anyone here been hit by one of these short bursts? Curious what recovery actually looked like on your side, because the report says the aftershocks outlast the attack itself.
Source: r/UltaHostHub · by /u/UltaHost_