Amazon, Google, and Cloudflare say a DDoS attack hit 398M RPS in August, ~8x larger than the previous record, due to a new bug; Google was able to mitigate it
Amazon, Google and Cloudflare said they detected the largest distributed denial-of-service (DDoS) attacks on record in August due to a newly discovered vulnerability.
Context & Ripple Effects
This event marks a sharp step up from Google Cloud's earlier 46M requests-per-second attack mitigation and Cloudflare's reports of hyper-volumetric attacks exceeding 71M RPS.
The significance is not merely a new peak: Amazon, Google, and Cloudflare tie the surge to a newly discovered vulnerability, making protocol remediation as important as raw network capacity.
First-order effects
- Amazon, Google, and Cloudflare must deploy and maintain mitigations for the newly identified flaw; Google says it successfully absorbed the reported attack.
- Customers behind these providers face an immediate need to ensure affected systems and DDoS controls are remediated, since the vulnerability enabled unusually high request volumes.
Second-order effects
- Other cloud and edge providers will need to validate that their own infrastructure can withstand the same attack pattern, increasing pressure to improve detection, rate limiting, and mitigation capacity.
- For buyers of security and hosting services, a record attack linked to a software flaw makes provider response capability and patch cadence more consequential in vendor selection.
Third-order effects
- If vulnerability-driven amplification continues to produce step-function increases in attack scale, DDoS resilience will depend less on historical traffic benchmarks and more on rapid, coordinated protocol remediation.
- The pattern favors large distributed platforms that can observe attacks across broad networks and deploy protections quickly, though the corpus does not establish how durable that advantage will be.
The trend: DDoS defense is shifting from capacity planning against steadily larger floods toward rapid mitigation of vulnerabilities that can abruptly multiply request volume.