<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:webfeeds="http://webfeeds.org/rss/1.0">
    <channel>
        <title><![CDATA[Radware Linkers Community]]></title>
        <description><![CDATA[Radware Linkers Community]]></description>
        <link>https://radware-community.customershome.com</link>
        <image>
            <url>https://tribe-s3-production.imgix.net/OXm89rWwAKdG70LO5Y8Wc?fit=max&amp;w=500&amp;auto=compress,format</url>
            <title>Radware Linkers Community</title>
            <link>https://radware-community.customershome.com</link>
        </image>
        <generator>Bettermode RSS Generator</generator>
        <lastBuildDate>Wed, 12 Aug 2026 11:11:56 GMT</lastBuildDate>
        <atom:link href="https://radware-community.customershome.com/rss/feed" rel="self" type="application/rss+xml"/>
        <pubDate>Wed, 12 Aug 2026 11:11:56 GMT</pubDate>
        <copyright><![CDATA[2026 Radware Linkers Community]]></copyright>
        <language><![CDATA[en-US]]></language>
        <ttl>60</ttl>
        <webfeeds:icon>https://tribe-s3-production.imgix.net/OXm89rWwAKdG70LO5Y8Wc?fit=max&amp;w=500&amp;auto=compress,format</webfeeds:icon>
        <webfeeds:related layout="card" target="browser"/>
        <item>
            <title><![CDATA[DDOS config signature and recommend config policies DDOS]]></title>
            <description><![CDATA[Hi Team

I have configured a Signature Profile. When configuring it, if I have two attribute types like you do, the operator should be AND, correct? So, the request must match both attribute types ...]]></description>
            <link>https://radware-community.customershome.com/ddos-protection-ibotkkf5/post/ddos-config-signature-and-recommend-config-policies-ddos-kjUoQU9B4FS5bGZ</link>
            <guid isPermaLink="true">https://radware-community.customershome.com/ddos-protection-ibotkkf5/post/ddos-config-signature-and-recommend-config-policies-ddos-kjUoQU9B4FS5bGZ</guid>
            <category><![CDATA[DDoS]]></category>
            <category><![CDATA[DDoS Protection]]></category>
            <dc:creator><![CDATA[NSO QLHT]]></dc:creator>
            <pubDate>Wed, 12 Aug 2026 03:11:14 GMT</pubDate>
            <content:encoded><![CDATA[<p>Hi Team</p><p>I have configured a Signature Profile. When configuring it, if I have two attribute types like you do, the operator should be <strong>AND</strong>, correct? So, the request must match <strong>both attribute types</strong> before it is blocked, right?</p><figure data-type="image" data-version="v2" data-id="s9W07G8Mj1oPcBoFusw9p" data-size="best-fit" data-align="center"><img src="https://tribe-s3-production.imgix.net/s9W07G8Mj1oPcBoFusw9p?auto=compress,format" data-id="s9W07G8Mj1oPcBoFusw9p"></figure><p>And would you recommend how I should configure the Signature Profile, as well as the other DDoS profiles, according to the recommended best practices?</p><p>Thanks all</p><p>Mr Hung</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Telegram Claimed Attacks Report | July 2026]]></title>
            <description><![CDATA[Germany was the most targeted country for DDoS attacks in July, according to our latest Radware Threat Intelligence report, with 134 claimed attacks.

Germany ranked ahead of Israel, France, Romania, ...]]></description>
            <link>https://radware-community.customershome.com/threat-intelligence-and-vulnerability-management-7o4wtiz3/post/telegram-claimed-attacks-report-july-2026-98cb0PFnWjXFepA</link>
            <guid isPermaLink="true">https://radware-community.customershome.com/threat-intelligence-and-vulnerability-management-7o4wtiz3/post/telegram-claimed-attacks-report-july-2026-98cb0PFnWjXFepA</guid>
            <dc:creator><![CDATA[Sharon Levin]]></dc:creator>
            <pubDate>Tue, 11 Aug 2026 07:33:28 GMT</pubDate>
            <content:encoded><![CDATA[<p>Germany was the most targeted country for DDoS attacks in July, according to our latest Radware Threat Intelligence report, with 134 claimed attacks.</p><p>Germany ranked ahead of Israel, France, Romania, and the US.</p><p>I’m curious to hear what you think: Why is Germany being targeted so heavily? Are you seeing the same trend in other threat reports or data you follow?</p><p>If you have seen other research that supports or challenges this trend, please share it in the comments.</p><p>Read the full July report here: <a href="https://webhelp.radware.com/attackreports/trc/index.html" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered">link</a></p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[From The Field: 5.6 million packets a second, and every single one looked random]]></title>
            <description><![CDATA[I want to share something that's been on my mind since it landed on my desk two days ago.

A mobile gaming company we work with — 250M+ registered players, the kind of loyalty most products would kill ...]]></description>
            <link>https://radware-community.customershome.com/threat-intelligence-and-vulnerability-management-7o4wtiz3/post/from-the-field-5-6-million-packets-a-second-and-every-single-one-looked-FEU6T7P6y8h1HrP</link>
            <guid isPermaLink="true">https://radware-community.customershome.com/threat-intelligence-and-vulnerability-management-7o4wtiz3/post/from-the-field-5-6-million-packets-a-second-and-every-single-one-looked-FEU6T7P6y8h1HrP</guid>
            <dc:creator><![CDATA[Haim Zelikovsky]]></dc:creator>
            <pubDate>Sun, 09 Aug 2026 09:08:37 GMT</pubDate>
            <content:encoded><![CDATA[<p>I want to share something that's been on my mind since it landed on my desk two days ago.</p><p>A mobile gaming company we work with — 250M+ registered players, the kind of loyalty most products would kill for (40% of players still active after five years) — had their login page hit by a UDP flood. Peak: 53 Gbps, 5.6 million packets per second. Baseline traffic on that endpoint is roughly 500 Mbps. So for a few minutes, this login page was absorbing over 100x its normal load.</p><p>Here's the part that actually made me pay attention: the attacker didn't just throw volume at them. Every packet had a randomized source port, a randomized size, and randomized header fields — deliberately, to avoid ever repeating a pattern a signature could lock onto. The traffic came from 1,000+ source IPs across a globally distributed botnet, including a cluster we've been tracking out of Brazil that's been active on other targets too.</p><p>That's not brute force. That's someone who understands exactly what static, signature-based defenses look for, and engineered traffic specifically to never give them one.</p><p>It worked, in the sense that the traffic genuinely looked random — no two packets alike. It didn't work in practice. Two things happened almost simultaneously: the sources we already had flagged — via our Active Attackers Feed — were blocked on sight, no analysis needed. Everything else went through our Behavioral DDoS Protection (BDoS), which isn't looking for a known pattern at all. It's comparing what it sees right now to what <em>this specific endpoint's</em> traffic normally looks like. And 5.6M pps of engineered noise doesn't resemble 500 Mbps of real player logins, no matter how "random" each individual packet is.</p><p>Signature generation on our side typically kicks in within seconds — though full convergence, where the system fine-tunes to minimize false positives without letting attack traffic through, takes a few seconds more. In this case, there were no reports of player impact, which tells its own story: whatever happened, it happened fast enough that nobody noticed.</p><p>But here's what I keep coming back to: login pages are the one page almost every user touches, every session, on every platform. If you're running anything with a login flow — gaming, fintech, e-commerce, doesn't matter — ask yourself honestly:</p><p>If someone sent your login endpoint traffic specifically engineered to never repeat a pattern, would your defenses even notice? Or would you only find out from your users?</p><p>That's the question this attack actually answers. Worth checking.</p><figure data-type="image" data-version="v2" data-id="cvkmTBiesDggosPQGeoGm" data-size="best-fit" data-align="center"><img src="https://tribe-s3-production.imgix.net/cvkmTBiesDggosPQGeoGm?auto=compress,format" data-id="cvkmTBiesDggosPQGeoGm"></figure><figure data-type="image" data-version="v2" data-id="8vwxdYmGJdJ72009Cj0V1" data-size="best-fit" data-align="center"><img src="https://tribe-s3-production.imgix.net/8vwxdYmGJdJ72009Cj0V1?auto=compress,format" data-id="8vwxdYmGJdJ72009Cj0V1"></figure><p></p><p></p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Greetings]]></title>
            <description><![CDATA[Hello all. I am a senior IT security analyst in the financial services industry. I currently deal with all things SIEM: data, detections, and threat intel. We recently transitioned from Akamai to ...]]></description>
            <link>https://radware-community.customershome.com/welcome-gfeiu4oz/post/greetings-33RvMPdjBOEgKlv</link>
            <guid isPermaLink="true">https://radware-community.customershome.com/welcome-gfeiu4oz/post/greetings-33RvMPdjBOEgKlv</guid>
            <dc:creator><![CDATA[Steven Ickes]]></dc:creator>
            <pubDate>Thu, 06 Aug 2026 13:25:57 GMT</pubDate>
            <content:encoded><![CDATA[<p>Hello all. I am a senior IT security analyst in the financial services industry. I currently deal with all things SIEM: data, detections, and threat intel. We recently transitioned from Akamai to Radware so I'm looking for as much insight into the data we're ingesting as possible.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[[The Linkers Pulse] Shai-Hulud is back: how a worm named after Dune took over npm]]></title>
            <description><![CDATA[On August 4, 2026, npm was hit by a new wave of an attack called Shai-Hulud. Within hours it spread to hundreds of packages with billions of monthly installs. Here's what happened, in order, with a ...]]></description>
            <link>https://radware-community.customershome.com/application-protection-f91x3tln/post/the-linkers-pulse-shai-hulud-is-back-how-a-worm-named-after-dune-took-xeMku5GIKG2kwfC</link>
            <guid isPermaLink="true">https://radware-community.customershome.com/application-protection-f91x3tln/post/the-linkers-pulse-shai-hulud-is-back-how-a-worm-named-after-dune-took-xeMku5GIKG2kwfC</guid>
            <dc:creator><![CDATA[Sharon Levin]]></dc:creator>
            <pubDate>Thu, 06 Aug 2026 10:22:11 GMT</pubDate>
            <content:encoded><![CDATA[<figure data-type="image" data-version="v2" data-id="5XHvPVK6FruFuIS57gZMC" data-size="best-fit" data-align="center"><img src="https://tribe-s3-production.imgix.net/5XHvPVK6FruFuIS57gZMC?auto=compress,format" data-id="5XHvPVK6FruFuIS57gZMC"></figure><p>On August 4, 2026, npm was hit by a new wave of an attack called Shai-Hulud. Within hours it spread to hundreds of packages with billions of monthly installs. Here's what happened, in order, with a source for each step.</p><p><strong>Why the name Shai-Hulud 🙂 </strong></p><p>Shai-Hulud is what the Fremen call the giant sandworms of Arrakis in "Dune": ancient creatures that move silently beneath the surface until the ground opens up and swallows you whole. Fitting name - the attackers picked it themselves, for their own data-leak repo</p><p><strong>How it happened</strong></p><ul><li><p>An attacker took over the GitHub account of the maintainer behind the popular package keyv (about 127 million downloads a week).</p></li><li><p>Through that account, the attacker published a new version with hidden malicious code. Because the release went through the maintainer's own normal build process, the infected version looked fully signed and trustworthy - tools that rely on signatures would not have caught it.</p></li><li><p>The moment a developer or a CI/CD system installed the package, malicious code ran automatically in the background - before the install even finished.</p></li><li><p>The code scanned the environment and stole tokens and secrets: access to npm, GitHub, AWS, and other cloud services.</p></li><li><p>For every npm token it found, the worm checked which additional packages it had publish access to, and spread itself to them automatically. That's how, within a few hours, the infection jumped from a single maintainer to hundreds of other packages. </p></li><li><p>Affected packages include keyv, cacheable, flat-cache, file-entry-cache, and others - together over 2 billion monthly installs, including as an internal dependency of common tools like ESLint.</p></li><li><p>Organizations whose code was affected include Deliveroo, OneReach, ServiceTitan, Picsart, and Qlik.</p></li><li><p>As of this writing, this is still a live event - the numbers keep climbing as the infection continues to spread.</p></li></ul><p><strong>Where Radware fits in</strong></p><p>Modern web applications rely on dozens of embedded third-party services many of which are built on open-source ecosystems that can be quietly compromised by supply chain attacks like Shai-Hulud.</p><p>Organizations must use dependency firewalls and secure pipelines to stop the actual malware from infecting their own source code.</p><p>They must also defend against the toxic byproduct of this campaign: a wake of compromised external vendor scripts running breached in the wild and &nbsp;this is where a WAF with client-side protection becomes essential, acting as a zero-trust browser barrier that neutralizes malicious payloads like Magecart, formjacking, and DOM XSS at the glass, ensuring your end users remain insulated even when an upstream open-source dependency has been actively weaponized.</p><p>&nbsp;</p><p>Stay safe and protected</p><p>Sharon</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[What does AI maturity really mean for application security?]]></title>
            <description><![CDATA[Almost every security vendor now says it uses AI. But the more important questions are where and how that AI is applied, and whether it meaningfully improves protection and security operations.

The new...]]></description>
            <link>https://radware-community.customershome.com/application-protection-f91x3tln/post/what-does-ai-maturity-really-mean-for-application-security-M41fdHPJdwERcxo</link>
            <guid isPermaLink="true">https://radware-community.customershome.com/application-protection-f91x3tln/post/what-does-ai-maturity-really-mean-for-application-security-M41fdHPJdwERcxo</guid>
            <dc:creator><![CDATA[Dan Schnour]]></dc:creator>
            <pubDate>Wed, 05 Aug 2026 06:45:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>Almost every security vendor now says it uses AI. But the more important questions are where and how that AI is applied, and whether it meaningfully improves protection and security operations.</p><p>The new QKS AI Maturity Matrix examines how vendors embed AI across Application Protection, API Security, bot and agent management, DDoS protection, LLM and agentic AI protection, and security operations. QKS positioned Radware as the Most Valuable Pioneer, noting:</p><p><em>“No other vendor in this evaluation has advanced as comprehensively into both the Web &amp; API Economy and the emerging Agentic Economy.”</em></p><p>For me, one of the report’s most important points is that AI maturity cannot be based on an isolated detection feature. It requires AI to work across the full security lifecycle, from understanding behavior and identifying risk to enforcing protections, investigating incidents, and supporting response.</p><p>As your organization adopts more APIs, LLM applications, or autonomous agents, where do you see the biggest security challenge: visibility, controlling access and behavior, protecting agent-to-API interactions, or responding to incidents quickly?</p><p>I’d be interested to hear what you are seeing in your own environments.</p><p><strong>Read the full QKS AI Maturity Matrix </strong><a href="https://www.radware.com/ai-maturity-matrix/" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered"><strong>Here</strong></a><strong>.</strong></p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[The 2.5 minutes that decide everything]]></title>
            <description><![CDATA[Somewhere in a SOC right now, an alert just fired. An analyst looks at the screen. Is this a real attack, or noise? They have maybe a minute to decide before the window to stop it closes.

That minute ...]]></description>
            <link>https://radware-community.customershome.com/ai-protection-discusstions-nyhat5bz/post/the-two-and-a-half-minutes-that-decide-everything-u7iyfrPnBSbuTZL</link>
            <guid isPermaLink="true">https://radware-community.customershome.com/ai-protection-discusstions-nyhat5bz/post/the-two-and-a-half-minutes-that-decide-everything-u7iyfrPnBSbuTZL</guid>
            <dc:creator><![CDATA[Sharon Levin]]></dc:creator>
            <pubDate>Mon, 03 Aug 2026 15:31:50 GMT</pubDate>
            <content:encoded><![CDATA[<p>Somewhere in a SOC right now, an alert just fired. An analyst looks at the screen. Is this a real attack, or noise? They have maybe a minute to decide before the window to stop it closes.</p><p>That minute is the whole problem.</p><h2 id="02df9d1f-7e3a-4dd9-9631-e2db5be574cb" data-toc-id="02df9d1f-7e3a-4dd9-9631-e2db5be574cb" class="text-xl"><a href="https://www.radware.com/getattachment/6a7a7a87-c7c1-4f6f-b1e2-4f87a53c59c8/Radware_Osterman-Report_2026_RWI6-386-(1).pdf.aspx?utm_source=https%3A%2F%2Fradware-community.customershome.com%2F&amp;utm_medium=brighttalk&amp;utm_campaign=669667" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered">A new global survey from Osterman Research, commissioned by Radware</a>, put a number on something security teams have felt for years: the average time to fully resolve an application security incident is 2.8 hours. Only 1.1% of organizations resolve an incident in under 15 minutes. Meanwhile, the average breakout time of an attacker is often shorter than that resolution window.</h2><p>Read that again. The people defending are, on average, structurally slower than the people attacking. This is not a story about bad security teams. It is a story about a fight where the clock was never set fairly.</p><h2 id="a6a91f0c-078d-499c-ac36-a99db80d1871" data-toc-id="a6a91f0c-078d-499c-ac36-a99db80d1871" class="text-xl">Why the clock is broken</h2><p>For years, "good enough" security meant having the right tools and trusting people to make the right call when something looked wrong. That worked when attacks were slower than defenses. It stops working the moment the attacker's side has automation that can find a vulnerability, chain it into an exploit, and execute, all without a human pausing to think.</p><p>The survey backs this up: <strong><u>63.4% of security leaders are highly or extremely concerned about AI-driven cyberattacks, but only 21.2% say they have the highest level of readiness to manage them</u></strong>. Everyone sees the wave coming. Most people know they are not ready for it.</p><p>And the reason is not a lack of effort. It is simple math. A human reading an alert, checking context across several tools, and deciding if it is real, cannot move at the speed the other side now moves at. Not because they are bad at their job. Because the job was never designed to run at that speed.</p><h2 id="1e40bf63-7fdd-409c-b2ef-93642791352f" data-toc-id="1e40bf63-7fdd-409c-b2ef-93642791352f" class="text-xl">What actually closes the gap</h2><p>Here the conversation usually jumps straight to "buy more AI tools," and that is too easy an answer. Organizations are already doing that: 58.1% now use AI-based security tools, up from 7.6% a year earlier. But adoption is not readiness. <strong><u>Across twelve measures of security maturity, only 21% of organizations on average report the highest level for any single control.</u></strong></p><p>In other words, the tools are showing up faster than the trust in them.</p><p>The real shift is not another dashboard. It is deciding, deliberately, which decisions still need a human, and which ones cost you the fight if you insist on making them yourself. Spotting a real attack, correlating signals across a WAF, an API layer, and bot management, blocking a source in real time: these are exactly the decisions taking hours, and exactly the ones attackers no longer wait for. Automation is not there to replace judgment. It is there to buy back the minutes that judgment needs.</p><h2 id="1a70c674-80ed-4274-9841-288bbb728509" data-toc-id="1a70c674-80ed-4274-9841-288bbb728509" class="text-xl">The uncomfortable question</h2><p>If your resolution time is measured in hours, and the thing attacking you does not need hours, you are not really defending in real time. You are defending after the fact, and calling it real time out of habit.</p><p>The organizations in a different position a year from now will not be the ones with the most tools. They will be the ones honest enough to ask which minutes cost them the most, and build automation around exactly those, not around the ones that are easy to sell in a slide deck.</p><p><em>The </em><a href="https://www.radware.com/getattachment/6a7a7a87-c7c1-4f6f-b1e2-4f87a53c59c8/Radware_Osterman-Report_2026_RWI6-386-(1).pdf.aspx?utm_source=https%3A%2F%2Fradware-community.customershome.com%2F&amp;utm_medium=brighttalk&amp;utm_campaign=669667" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered">full report </a><em>breaks this down across twelve areas of AI, API, and application security posture, with the industry-by-industry numbers, charts, and comparisons that didn't make it into this post, the kind of data worth having on hand the next time you need to make the case for AI security investment.</em></p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[Free Training: How Security Policies save time and keep your protection uniform]]></title>
            <description><![CDATA[I’m always looking for practical resources to save you time, and this one hits right at the manual setup trap.

Configuring security settings application by application might work when you have just a ...]]></description>
            <link>https://radware-community.customershome.com/application-protection-f91x3tln/post/free-training-how-security-policies-save-time-and-keep-your-protection-5j2znCFtJUzPwGZ</link>
            <guid isPermaLink="true">https://radware-community.customershome.com/application-protection-f91x3tln/post/free-training-how-security-policies-save-time-and-keep-your-protection-5j2znCFtJUzPwGZ</guid>
            <dc:creator><![CDATA[Sharon Levin]]></dc:creator>
            <pubDate>Mon, 03 Aug 2026 13:32:00 GMT</pubDate>
            <content:encoded><![CDATA[<p>I’m always looking for practical resources to save you time, and this one hits right at the manual setup trap.</p><p>Configuring security settings application by application might work when you have just a few. But as your environment grows, setting them up manually one by one becomes a major time-sink—and increases the risk of inconsistencies across your setup.</p><p>A <strong>Security Policy</strong> fixes this by acting as a single, comprehensive template. You define your protection parameters once and apply them across multiple applications instantly. It doesn't just save you hours of manual effort; it makes your entire security posture completely uniform and standardized.</p><p>We set up a quick, free training to show you how to build and apply these policies step-by-step:</p><p><strong>Link to Free Training: </strong><a href="https://deeplinks.mindtickle.com/LM2PKTg9c3b" rel="noopener noreferrer nofollow" class="text-interactive hover:text-interactive-hovered"><strong>https://deeplinks.mindtickle.com/LM2PKTg9c3b</strong></a></p><p></p><figure data-type="image" data-version="v2" data-id="BtQVWwYWyA5gO5NcWMZRq" data-size="best-fit" data-align="center"><img src="https://tribe-s3-production.imgix.net/BtQVWwYWyA5gO5NcWMZRq?auto=compress,format" data-id="BtQVWwYWyA5gO5NcWMZRq"></figure>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[About me]]></title>
            <description><![CDATA[Hello everyone, my name is Juan Hernandez. I've worked as a cybersecurity analyst and recently focused on infrastructure-related topics. I've implemented and worked as a pre-sales engineer for ...]]></description>
            <link>https://radware-community.customershome.com/welcome-gfeiu4oz/post/about-me-yuBlVWwATh3mTm9</link>
            <guid isPermaLink="true">https://radware-community.customershome.com/welcome-gfeiu4oz/post/about-me-yuBlVWwATh3mTm9</guid>
            <dc:creator><![CDATA[Juan Alberto Hernandez]]></dc:creator>
            <pubDate>Tue, 21 Jul 2026 17:24:25 GMT</pubDate>
            <content:encoded><![CDATA[<p>Hello everyone, my name is Juan Hernandez. I've worked as a cybersecurity analyst and recently focused on infrastructure-related topics. I've implemented and worked as a pre-sales engineer for perimeter networking solutions, application firewalls, and infrastructure pre-sales. I enjoy learning about all aspects of cybersecurity and am constantly developing my skills and knowledge. I look forward to learning from the community and sharing my expertise.</p>]]></content:encoded>
        </item>
        <item>
            <title><![CDATA[From the Field: What happened when a mobile carrier suddenly received 100x its normal traffic]]></title>
            <description><![CDATA[This week, one of the world's largest mobile carriers, serving more than 100 million subscribers, was hit by a large-scale HTTPS DDoS attack. The carrier supports a broad range of digital services, ...]]></description>
            <link>https://radware-community.customershome.com/ddos-protection-ibotkkf5/post/from-the-field-modern-ddos-attacks-don-t-stand-still-7SYmgwxh1Am2IxY</link>
            <guid isPermaLink="true">https://radware-community.customershome.com/ddos-protection-ibotkkf5/post/from-the-field-modern-ddos-attacks-don-t-stand-still-7SYmgwxh1Am2IxY</guid>
            <dc:creator><![CDATA[Haim Zelikovsky]]></dc:creator>
            <pubDate>Mon, 20 Jul 2026 08:19:37 GMT</pubDate>
            <content:encoded><![CDATA[<p>This week, one of the world's largest mobile carriers, serving more than 100 million subscribers, was hit by a large-scale HTTPS DDoS attack. The carrier supports a broad range of digital services, including entertainment, financial services, retail, and technology platforms.</p><p>A globally distributed botnet of more than 4,000 source IPs generated peaks of 670,000 HTTPS requests per second, nearly 100 times the carrier's normal traffic. Throughout the attack, the attackers continuously changed their techniques, making it much harder to distinguish malicious traffic from legitimate users.</p><p>Incidents like this are a good reminder that defending against modern HTTPS floods is not just about blocking high traffic volumes. The real challenge is recognizing malicious requests that closely resemble legitimate user activity while the attack continues to evolve.</p><p><strong>A simple tabletop exercise for your team:</strong></p><p>Imagine your main customer-facing application suddenly receives 100 times its normal HTTPS traffic.</p><ul><li><p>How would your team determine whether this is a DDoS attack, a successful marketing campaign, or an unexpected traffic spike?</p></li><li><p>Who makes that decision?</p></li><li><p>If the attack changes techniques while it is already in progress, does your mitigation adapt automatically, or does someone need to manually update the protection?</p></li></ul><p>The answers often reveal operational gaps long before a real attack does.</p><p>In this incident, Radware's Web DDoS Protection automatically adapted as the attack evolved, allowing legitimate users to continue accessing services without interruption.</p><p>Best,</p><p>Haim</p>]]></content:encoded>
        </item>
    </channel>
</rss>