• Sources: primary, discussion
  • Summary: Read the Docs reports that the June 2026 attack peaked at 5.5 million requests per minute against a normal daily peak under 100k, ran for nearly ten days, and came from millions of IP addresses across hundreds of ASNs. The attackers randomized HTTP headers and TLS parameters, so JA3 and JA4 fingerprinting did not help, and they targeted cache misses such as 404s and uncached 302 redirects in a yo-yo pattern timed to rate-limit windows. The team credits a penalty box that rate limits on the ratio of expensive uncached responses per fingerprint, ASN or domain, with edge and WAF rules managed in Terraform.
  • Why it matters: The mitigation keys on the cost of the response rather than on client identity, which is the part that survives randomized fingerprints.

send feedback on this story