Radware: Web DDoS attacks doubled in H1 2026, zero-day window turns negative
Radware's H1 2026 report shows web DDoS attacks more than doubled and average time-to-exploit turned negative, as AI compresses patch windows.
If the first-half pace holds, Radware projects full-year 2026 web DDoS volumes to close 166% above 2025. North American infrastructure is expected to see the sharpest increase, with a projected 190% rise by year's end. By contrast, Europe, the Middle East and Africa are seen rising 60%, a region that historically absorbed more than half of all web DDoS attacks, while Asia-Pacific is projected to grow just 27%.
Customers absorbed an average of 110 network-layer attacks per day, up 36.6% from Radware's 2025 baseline. The report found that reflection and amplification attacks have fallen out of favor, making way for direct-path volumetric floods. Stateless UDP floods alone accounted for 73% of mitigated packets, and adding fragmented UDP traffic pushed the share above 80%.
The technology sector absorbed 59.4% of network DDoS activity, averaging 509 attacks per customer each day, well ahead of financial services at 20.8%. Geographically, customers in the Middle East were hit most often, at 520 attacks a day.
Perhaps the sharpest figure in the report is negative. Measured from public disclosure of a CVE record to the first confirmed in-the-wild attack, mean time to exploit stood at negative eight hours as of July 23, based on Zero Day Clock project data cited in the report. The clock starts at disclosure, so an attack that lands earlier counts as negative time. In 2025, the same measure sat at 21.5 days; in 2024, defenders had 53 days. Radware's zero-day rate, the share of flaws exploited on or before the day they are disclosed, has passed 80%.
Radware attributes much of that compression to frontier artificial intelligence models. The report points to Anthropic PBC's Claude Mythos, which surfaced a 27-year-old flaw in OpenBSD's TCP stack that survived decades of human review and fuzzing. Cheaper open-weight models can reproduce much of that work when the scaffolding around them is built properly, Radware said.
Local AI agents drew a separate warning. Running continuously on developer endpoints, they can call APIs and install software dependencies without being asked, which Radware flags as an amplifier for supply chain attacks. The report cites the Mini Shai-Hulud attacks on npm packages as an example.
Radware's survey of 377 organizations found 77% deploying or implementing AI agents and autonomous workflows, yet only 17.2% reported full visibility into the agents running in their environment. The API picture is similar: 81.2% push production API updates at least weekly, while 6.9% fully document their internal APIs.
Pascal Geenens, vice president of threat intelligence at Radware, said attackers are now operating at machine speed. Organizations are deploying agents and APIs without a complete view of the attack surface they are creating, and the widening gap between attack speed and response time is changing the threat landscape, he said.
The report also tracks hacktivist DDoS claims, which continued to follow geopolitics. Europe drew 48% of all claims and Israel 16.9%. Public claims have been contracting since a peak in the second quarter of 2025, but March broke that trend with a 103% jump that Radware ties to military events in the Middle East. Pro-Russian collective NoName057(16) generated 40.5% of everything recorded in the half.