DDoS Attacks Surge Past Projections as Zero-Day Exploits Accelerate
Radware's latest threat report reveals web-based denial-of-service incidents have more than doubled in the first half of 2026, driven by AI-powered exploitation that now turns vulnerabilities into attacks within hours of disclosure.

Radware Ltd. released findings today showing that web-based distributed denial-of-service attacks surged dramatically during the opening six months of 2026. The company's mitigation efforts jumped 110.6% compared with the corresponding period in 2025, and climbed 36.3% relative to the latter half of 2025. During this single half-year stretch, Radware blocked nearly 83% of the total attack volume it had handled throughout all of 2025.
The H1 2026 Global Threat Analysis Report draws on telemetry collected from Radware's cloud and managed security services, supplemented by analysis from the company's threat intelligence division. The report encompasses the January-through-June period.
Should the attack trajectory from the first half persist through year-end, Radware forecasts 2026 will finish 166% higher than 2025 levels. North America faces the steepest climb, with projections indicating a 190% year-over-year increase. Other regions show considerably slower growth: Europe, the Middle East and Africa are expected to rise 60%, while Asia-Pacific trails at 27%.
Network-layer attacks averaged 110 incidents per customer daily, representing a 36.6% increase from Radware's 2025 measurements. The composition of these attacks has shifted markedly, with reflection and amplification techniques declining in prevalence. Stateless UDP floods now dominate, comprising 73% of all mitigated packets, and when fragmented UDP traffic is included, the combined share exceeds 80%.
Technology companies bore the brunt of network-layer DDoS activity, absorbing 59.4% of all attacks and averaging 509 incidents per customer daily. Financial services trailed significantly at 20.8%. Customers based in the Middle East experienced the highest attack frequency, averaging 520 assaults per day.
The Zero-Day Crisis
The report's most alarming metric concerns the speed at which vulnerabilities transform into active exploits. As of July 23, the mean time to exploit—measured from public disclosure of a Common Vulnerabilities and Exposures record to the first confirmed attack in the wild—stood at negative eight hours, according to Zero Day Clock project data cited in the report. A negative figure indicates attacks occurring before official disclosure. This represents a dramatic compression from 2025, when the same measure was 21.5 days, and 2024, when defenders had 53 days to respond. Radware's zero-day rate, tracking the proportion of flaws exploited on or before their disclosure date, has surpassed 80%.
Radware attributes much of this acceleration to frontier artificial intelligence models. The report highlights Anthropic PBC's Claude Mythos, which identified a 27-year-old flaw in OpenBSD's TCP stack that had eluded decades of human scrutiny and automated fuzzing. According to Radware, cheaper open-weight models can replicate similar discoveries when provided with appropriate supporting infrastructure.
AI Agents and Supply Chain Risk
Radware raised separate concerns about local AI agents operating on developer machines. These systems, running continuously, can invoke APIs and install software dependencies autonomously without explicit authorization. Radware identifies this capability as a significant amplifier for supply chain attacks, citing the Mini Shai-Hulud incidents targeting npm packages as evidence.
A Radware survey of 377 organizations revealed that 77% are either deploying or implementing AI agents and autonomous workflows. However, only 17.2% reported having complete visibility into the agents operating within their infrastructure. The API landscape presents similar challenges: while 81.2% of organizations push production API updates at least weekly, just 6.9% maintain full documentation of their internal APIs.
Pascal Geenens, vice president of threat intelligence at Radware, stated that attackers are now "operating at machine speed." He noted that organizations are rolling out agents and APIs without fully understanding the attack surface they are creating, and that the expanding gap between attack velocity and response capability is fundamentally reshaping the threat environment.
Hacktivist Activity and Geopolitical Patterns
Hacktivist DDoS claims have continued to reflect geopolitical tensions, with Europe accounting for 48% of all claims and Israel representing 16.9%. Public claims have been declining since peaking in the second quarter of 2025, though March broke this downward trend with a 103% spike that Radware attributes to military developments in the Middle East. The pro-Russian collective NoName057(16) was responsible for 40.5% of all recorded activity during the half-year period.


