Press Releases September 9, 2026 06:00 AM

Radware H1 2026 Global Threat Report Shows Web DDoS Attacks Jump More Than 110% as Cyber Threats Accelerate

Radware reports a significant surge in Web DDoS and AI-accelerated cyberattacks in H1 2026, highlighting escalating cybersecurity challenges and evolving threat landscape.

By Maya Rios
Share
Twitter Reddit Facebook LinkedIn
RDWR

Radware Ltd. (NASDAQ: RDWR) released its H1 2026 Global Threat Analysis Report revealing a sharp increase in cyberattack activities, including a 110.6% rise in Web DDoS attacks and a doubling of malicious web application and API attacks compared to 2025. The report emphasizes rapid exploitation of vulnerabilities, accelerated by AI technologies, and increased volumes of network- and application-layer attacks, with North America experiencing the highest growth. The findings underscore growing cybersecurity challenges as attackers leverage AI to escalate threats while organizations struggle with visibility and response capabilities.

Radware H1 2026 Global Threat Report Shows Web DDoS Attacks Jump More Than 110% as Cyber Threats Accelerate
RDWR
Summarize with
ChatGPT Perplexity Claude Grok Gemini

Key Points

  • Web DDoS attacks surged 110.6% year-over-year in H1 2026, with projections of a 166% annual increase if trends continue, severely impacting network security sectors.
  • AI is accelerating vulnerability discovery and exploitation, with zero-day exploits surpassing 80% and attackers using AI-driven automation to launch sophisticated attacks, influencing cybersecurity technology and AI innovation sectors.
  • North America faces the highest attack growth rates in Web and network DDoS, particularly targeting the technology and financial services industries, highlighting regional cybersecurity demand and risk management.
  • Bad bot activity and hacktivist attacks remain elevated, influenced by geopolitical events, which affects government and critical infrastructure cybersecurity efforts.

Malicious web application and API transactions increase 104%

AI accelerates vulnerability discovery; attackers exploit flaws before they are publicly announced

MAHWAH, N.J., Sept. 09, 2026 (GLOBE NEWSWIRE) -- Radware® (NASDAQ: RDWR), a global leader in AI and application security and delivery solutions for multi-cloud environments, today released its H1 2026 Global Threat Analysis Report, revealing a sharp escalation in cyberattack activity across network and application layers during the first six months of the year. The new report analyzes data from Radware’s cloud and managed security services and research from its threat intelligence team, highlighting the increasing speed and scale of DDoS attacks, vulnerability exploitation and AI-driven threats facing organizations worldwide.

In the H1 2026 report:

Web DDoS Attack Activity Skyrockets

Web DDoS attacks surged 110.6% compared with H1 2025 and rose 36.3% compared with the second half of 2025. In just the first six months of 2026, Web DDoS mitigations reached nearly 83% of the total volume recorded throughout all of 2025.

  • Attack Volume: If attack volumes continue at the same pace, based on a straight-line extrapolation of H1 2026 data, Web DDoS attacks could increase by approximately 166% year over year in 2026.
  • Geographic Targets: Based on H1 2026 trends, North America is estimated to see the highest projected growth in Web DDoS attacks in 2026 at approximately 190%, compared with an estimated 60% in EMEA, 39% in Central and Latin America (CALA), and 27% in APAC, assuming current-pace conditions continue through year-end.

Network DDoS Attacks Intensify

Network-layer DDoS attacks reached an average of 110 attacks per customer per day during H1 2026, a 36.6% increase over the 2025 baseline, as attackers shifted away from traditional reflection and amplification techniques toward direct-path volumetric floods.

  • Attack Vectors: Direct-path User Datagram Protocol (UDP) floods, which overwhelm targets with traffic, accounted for 73% of total mitigated packets and more than 80% when combined with fragmented UDP traffic.
  • Industry Targets: The technology sector accounted for 59.4% of all network DDoS attacks, averaging 509 attacks per customer per day. Financial services followed, accounting for 20.8% of network attacks.
  • Geographic Targets: North America absorbed the largest share of network DDoS attacks at 43.1%, while the Middle East recorded the highest attack frequency, averaging 520 attacks per customer per day.

Application and API Attacks Double

Malicious web application and API transactions increased 104% over 2025 levels, exceeding 14,000 malicious transactions per application per day in H1 2026.

  • Vulnerability Exploitation: Vulnerability exploitation accounted for 62.1% of all recorded web application and API attacks.
  • Geographic Targets: North America accounted for 79.5% of all global malicious web application and API transactions.

Vulnerability Exploitation Outpaces Defenders

The window between vulnerability disclosure and active exploitation has narrowed dramatically. The mean time from official Common Vulnerabilities and Exposures (CVE) announcement to the first detected attack in the wild dropped to below zero compared with a mean of 21.5 days post-disclosure in 2025 and 53 days in 2024, based on Radware's threat intelligence data.

  • Zero-Day Exploitation: The zero-day rate surpassed 80%, meaning more than four out of five vulnerabilities were exploited before their official CVE announcement.

AI Accelerates Cybersecurity Risks

Autonomous AI systems are creating new attack vectors and accelerating vulnerability discovery. Local AI agents that operate continuously on user devices can access systems, execute tasks, call APIs and autonomously download software dependencies, creating risks ranging from prompt injection to software supply chain attacks.

Advanced AI models are also accelerating attack execution. The report highlights how frontier models can use semantic reasoning and vulnerability chaining to identify flaws that have escaped years of human review and traditional security testing. At the same time, increasingly capable open-weight models are making advanced offensive capabilities more broadly accessible.

  • AI Agent Adoption: According to Radware's survey research, 77% of organizations are actively deploying or implementing AI agents and autonomous workflows, yet only 17.2% report full visibility into the AI agents operating in their environments.
  • API Development: According to Radware's survey research, more than 70% of organizations increased their use of internally developed APIs over the past year, and 81.2% now push production API updates at least weekly.
  • API Visibility: Despite the rapid pace of development, Radware's survey research found that only 6.9% of organizations fully document their internal APIs, while 43% document less than 70% of them.

“Attackers are increasingly operating at machine speed — launching direct-path DDoS attacks, exploiting vulnerabilities and using agentic AI to automate and speed up their attacks,” said Pascal Geenens, vice president of threat intelligence at Radware. “At the same time, organizations are rapidly deploying AI agents and APIs without complete visibility into their expanding attack surfaces. The growing gap between the speed of attacks and the ability of organizations to detect and respond to them is fundamentally changing the threat landscape.”

Bad Bot Activity Continues to Rise

Bad bot activity remained elevated in H1 2026, reaching nearly 60% of the total volume recorded throughout 2025.

  • Geographic Targets: North America accounted for 50.1% of global bad bot activity, followed by APAC at 23.2%.

Hacktivism Tracks Geopolitical Conflict

Geopolitical conflict continued to dictate hacktivist DDoS activity during the first half of 2026. While overall public attack claims entered a multi-quarter contraction after peaking in Q2 2025, activity surged in direct response to military events, including a 103% month-over-month increase in March 2026 that corresponded with reported military events in the Middle East.

  • Regional Concentration: Europe remained the primary target, accounting for 48% of all hacktivist DDoS attack claims.
  • Nation and Industry Targets: Israel was the most targeted country, accounting for 16.9% of claimed attacks, followed by Ukraine (8.4%) and the United States (7.7%). Government remained the most targeted industry at 37.2% of all claims.
  • Most Active Threat Actor: Pro-Russian threat collectives continued to dominate hacktivist activity. NoName057(16) alone generated 40.5% of all recorded claims in H1 2026.

Radware’s complete H1 2026 Global Threat Analysis Report can be downloaded here.

Radware Webinar on H1 2026 Global Threat Analysis Report

Radware will host a webinar on October 1, 2026, at 11:00am EDT on The Automated Tipping Point: AI Agents, Zero-Day Exploitation and the H1 2026 Threat Landscape, where Pascal Geenens, vice president of threat intelligence at Radware, will discuss the report and the network, application, AI and hacktivist threat trends shaping the first half of 2026.

Security leaders and researchers are invited to attend and explore the report and its data on cyberattack activity during H1 2026.

Radware conducts threat research on behalf of the wider cybersecurity community, helping equip security professionals with timely insights into attacker techniques, tools, and emerging threat trends. Research, including technical breakdowns and defense recommendations, is available at Radware’s Security Research Center.

THIS PRESS RELEASE AND THE RADWARE H1 2026 GLOBAL THREAT REPORT ARE PROVIDED FOR INFORMATIONAL PURPOSES ONLY. THESE MATERIALS ARE NOT INTENDED TO BE AN INDICATOR OF RADWARE'S BUSINESS PERFORMANCE OR OPERATING RESULTS FOR ANY PRIOR, CURRENT OR FUTURE PERIOD.

Safe Harbor Statement

This press release contains “forward-looking statements” within the meaning of the Private Securities Litigation Reform Act of 1995 and other U.S. securities laws. Any forward-looking statements made herein that are not statements of historical fact, including statements about Radware’s plans, objectives, expectations, beliefs, projections, future financial performance, business strategies, market opportunities, and developments in our industry, are forward-looking statements. In some cases, forward-looking statements can be identified by words such as “believe,” “expect,” “anticipate,” “intend,” “estimate,” “plan,” “project,” “forecast,” “target,” and similar expressions, as well as future or conditional verbs such as “will,” “should,” “would,” “may,” and “could.” For example, when we say in this press release that, based on a straight-line extrapolation of H1 2026 data, Web DDoS attacks could increase by approximately 166% year over year in 2026, or that North America is estimated to see the highest projected growth in Web DDoS attacks at approximately 190% assuming current-pace conditions continue through year-end, we are using forward-looking statements.

Because such statements deal with future events, they are subject to various risks and uncertainties that could cause actual results to differ materially from those expressed or implied in such forward-looking statements. Factors that could cause or contribute to such differences include, but are not limited to: the impact of global market and economic conditions; our dependence on independent distributors; disruptions in our supply chain, including shortages of components or manufacturing capacity; our reliance on a limited number of vendors; our ability to attract, train and retain qualified personnel; intense competition in the cybersecurity and application delivery markets; our ability to develop new solutions and enhance existing solutions; risks related to defects, vulnerabilities or failures in our products or services, including cybersecurity incidents affecting our systems or those of our customers; risks associated with the use of artificial intelligence technologies, including evolving regulatory frameworks, litigation exposure and reputational considerations; risks related to our information technology systems, including failures, disruptions or security breaches; outages, interruptions, or delays in hosting or cloud-based services; risks related to the interoperability of our products; risks associated with our global operations; and geopolitical risks, including instability in the Middle East and Israel.

These factors are not exhaustive. For a more detailed description of the risks and uncertainties affecting Radware, please refer to Radware’s Annual Report on Form 20-F and other reports filed with or furnished to the Securities and Exchange Commission (SEC) from time to time.

Forward-looking statements speak only as of the date on which they are made, and, except as required by applicable law, Radware undertakes no obligation to update or revise any forward-looking statements to reflect events or circumstances after the date of such statements. Radware’s public filings are available from the SEC’s website at www.sec.gov or on Radware’s website at www.radware.com.

About Radware 

Radware® (NASDAQ: RDWR) is a global leader in application security and delivery solutions for multi-cloud environments. The company’s cloud application, infrastructure, API, and AI security solutions use AI-driven algorithms for precise, behavior-based, real-time protection against sophisticated web, application, and DDoS attacks, API abuse, business logic threats, and malicious bots. Radware delivers end-to-end API security, including discovery, posture management, testing, and runtime protection, along with advanced protection for AI agents and models. Enterprises and carriers worldwide rely on Radware to address evolving cyberthreats, protect their brands and business operations, and reduce costs. For more information, please visit the Radware website.

Radware encourages you to join our community and follow us on: Facebook, LinkedIn, Radware Blog, X, and YouTube. 

©2026 Radware Ltd. All rights reserved. Any Radware products and solutions mentioned in this press release are protected by trademarks, patents, and pending patent applications of Radware in the U.S. and other countries. For more details, please see: https://www.radware.com/LegalNotice/. All other trademarks and names are property of their respective owners. 

Radware believes the information in this document is accurate in all material respects as of its publication date. However, the information is provided without any express, statutory, or implied warranties and is subject to change without notice. 

The contents of any website or hyperlinks mentioned in this press release are for informational purposes and the contents thereof are not part of this press release.

Media Contact:
Gina Sorice
GinaSo@radware.com

Investor Contact:
Yisca Erez
YiscaE@radware.com

A photo accompanying this announcement is available at https://www.globenewswire.com/NewsRoom/AttachmentNg/674f6eef-72b1-4fa8-9f89-5566c52e6a2e


Risks

  • Rapidly shortening window between vulnerability disclosure and exploitation increases risk for software development and IT security sectors.
  • Increased use of AI agents and internally developed APIs without sufficient visibility and documentation heightens organizational cyber risk exposure.
  • Geopolitical conflicts driving hacktivist attacks introduce regional and industry-specific volatility in cybersecurity threats, impacting government and defense sectors.

More from Press Releases

MannKind and Rose Pharma Inc Enter Licensing and Collaboration Agreement to Develop an Inhaled Rapid-Acting, Short-Duration GLP-1 for Weight Management Sep 9, 2026 Einride Expands Defense Offering With Mission Planning and Operational Decision-Making for Autonomous Logistics Sep 9, 2026 Telix to Present at the Morgan Stanley 24th Annual Global Healthcare Conference and H.C. Wainwright 28th Annual Global Investment Conference Sep 9, 2026 Sysco Reaffirming Fiscal 2027 Guidance; Introducing $500 Million Multi-Year AI Powered Efficiency Program; Raising Mid-Term Financial Algorithm Targets Sep 9, 2026 Kilbourne Graphite Project Advances Through Key Permitting Milestones Sep 9, 2026