← Latest briefing

Technology

Read the Docs weathered massive ten-day cyberattack, postmortem reveals

A mid-2026 DDoS attack peaked at 5.5 million requests per minute, according to Hacker News.

The short version

  • Read the Docs faced a sophisticated distributed denial-of-service attack spanning nearly ten days in mid-to-late June 2026.[Hacker News]
  • Traffic peaked at more than 5.5 million requests per minute, roughly 100 times the platform's standard baseline.[Hacker News]
  • The assault leveraged millions of IP addresses, randomized headers and TLS parameters, and aimed at cache misses such as 404 errors.[Hacker News]
  • Cloudflare automated systems stopped known botnets, but significant traffic bypassed initial checks and required manual rate limiting and WAF rules.[Hacker News]

Key facts

  • Read the Docs sustained a sophisticated DDoS attack in mid-to-late June 2026 lasting nearly ten days.[Hacker News]
  • Peak incoming volume reached over 5.5 million requests per minute, approximately 100 times the baseline.[Hacker News]
  • Malicious traffic stemmed from millions of distinct IP addresses distributed across residential blocks and hosting providers globally.[Hacker News]
  • The attackers randomized HTTP headers and TLS connection parameters to evade signature-based detection.[Hacker News]
  • The assault specifically targeted uncached endpoints, including non-existent 404 paths and 302 redirects.[Hacker News]
  • While automated defenses filtered known botnets, substantial malicious traffic slipped through to rate limiting and WAF controls.[Hacker News]

What remains uncertain

  • The identity, origin, and specific motivation of the threat actors behind the coordinated attack remain undisclosed.[Hacker News]

Sources

Outlet counts describe coverage, not independent confirmation. Reports may share a wire service or original source.