In mid-to-late June 2026, Read the Docs was subjected to its most significant distributed denial-of-service (DDoS) attack to date. The attack reached a peak of over 5.5 million requests per minute, which is approximately 100 times their typical baseline traffic. This incident persisted for nearly ten days, straining the platform's infrastructure, edge defenses, and incident response protocols.
Unlike previous, simpler traffic floods, this attack demonstrated a higher level of sophistication. It was highly distributed, originating from millions of unique IP addresses across hundreds of networks globally, including residential blocks and hosting providers. The attackers also rapidly adapted to defenses and specifically targeted areas that bypassed caching mechanisms.
The attack also featured header and TLS randomization, where HTTP request headers and TLS connection parameters were systematically altered to evade signature-based filters like JA3/JA4. This technique made it harder for traditional security measures to identify and block malicious traffic.
Read the Docs utilizes Cloudflare for protection, but even Cloudflare's automated DDoS mitigation, while effective against known botnets, allowed a significant portion of the attack traffic to bypass initial checks and reach Read the Docs' rate limiting and Web Application Firewall (WAF) rules. This indicates that automated CDN defenses may struggle against highly sophisticated and adaptive DDoS campaigns.
The attack also deliberately targeted URLs that resulted in cache misses, such as non-existent pages, further increasing the load on the origin servers and bypassing caching layers designed to absorb traffic spikes.
This event underscores a broader trend of increasing sophistication in DDoS attacks, particularly with the rise of AI crawlers and proxy networks making it easier to launch large-scale, distributed assaults. The experience of Read the Docs, a key documentation hosting platform, provides insights into the challenges faced by online services in maintaining availability against persistent and adaptive threats.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Read the Docs experienced its largest and most sophisticated distributed denial-of-service (DDoS) attack in mid-to-late June 2026, peaking at over 5.5 million requests per minute for nearly ten days. This incident highlights the evolving nature of DDoS attacks, which are becoming more distributed and adaptive, posing challenges even for established CDN defenses.