Skip to content
September 11, 2026
  • Bluesky
  • Facebook
  • Linkedin
  • Mastodon
  • RSS
  • Twitter
  • Youtube

Daily CyberSecurity

Zero-hour alerts. Unmatched analysis.

Primary Menu
  • Home
  • CVE Data
    • CVE Watchtower
    • Top Exploited CVEs
    • CVE Stats by Vendor
    • Q2 2026 Report
    • CVE Alerts
    • CVE Alert Settings
    • Pricing
  • Cyber Criminals
  • Data Leak
  • Linux
  • Malware
  • Vulnerability
  • Submit Press Release
  • Weekly Recap
Light/Dark Button
  • Home
  • Technique
  • Top DDoS attack trends to watch out for in 2020
  • Technique

Top DDoS attack trends to watch out for in 2020

Do Son February 23, 2020 6 minutes read
DDoS attack trends

Image credit: Pixabay

Image credit: Pixabay

From growing to merging, here are some trends that businesses, security professionals, and application developers need to be aware of.

For some time, DDoS attacks were observed to be on a decline until they started going the upward trajectory again in the past year. Attacks reportedly doubled year-on-year in the fourth quarter of 2019. These cyber-threats may not entail the theft of information or assets, but they are just as damaging. They disrupt commercial activities organization operations as they shut down websites and online services with overwhelming volumes of fake traffic.

In 2020, it only makes sense to consider DDoS as a major threat and anticipate the different ways it will be used to harm websites and online services. Organizations should not downplay it, especially the rise in multi-vector attacks. It’s advisable to get acquainted with the trends and how these attacks are evolving.

Growing attack volumes

The success of Distributed Denial of Service attacks in derailing business activities as well as government operations appears to encourage cybercriminals to rely on this approach in harming their targets. Many companies tend to relegate DNS to a lower priority when it comes to establishing their security systems. Setting up DDoS protection is generally uncomplicated; unfortunately, many organizations still fail to have adequate defenses.

Security analysts expect more DDoS incidents in 2020–targeting not only large corporations and government offices but also small and midsize businesses. According to Kaspersky’s Q4 2019 DDoS report, the number of attacks detected in the fourth quarter of 2019 increased by around 79% compared to the number from the same period in 2018. It’s the highest year-on-year increase recorded by Kaspersky for 2019. In the last two quarters, the attack growth rates were at 32% and 18% respectively. This general growth pattern is expected to extend into the rest of the current year and even beyond.

Attackers launched numerous large-scale DDoS campaigns against financial institutions in Singapore, South Africa, and a number of countries in the Scandinavian region. The United Kingdom’s Labour party also suffered attacks aimed at disrupting the organization’s digital systems. Even the Minecraft server in the Vatican was not spared. Security experts believe that most of the attacks either have ideological motives or are driven by the possibility of financial gains.

Increased application layer attacks

In the past, the prevailing type of DDoS attack was volumetric, which means that the attacker employs massive false requests for every accessible port. These requests result in a UDP flood and ICMP flood. However, volumetric attacks tend to be less effective in the advent of cloud-based services. An infrastructure-oriented approach in DDoS is typically not as destructive as attacks that disrupt traffic on web applications. As such, cybercriminals are turning to application-layer attacks.

Also known as layer 7 DDoS, application-layer attacks are designed to target the web traffic of a user interacting application. They are network-based attacks that generally affect DNS, HTTP/HTTPS, and SMTP protocols. What makes them preferable (for attackers) is their efficiency. They can result in more damage with less total bandwidth compared to volumetric attacks.

Exploiting exposed servers

According to Akamai, there are around a hundred thousand memcached servers that are considered exposed or open to DDoS attacks. Memcached servers are database caching systems intended to speed up the loading of websites. They are not meant to be exposed on the public internet, but they respond to queries from anyone. These servers are set to be exploited by attackers if they remain unprotected.

On the other hand, the problem of exposed servers also emerges in the trend of companies shifting to UDP (User Datagram Protocol) so they can put backend web servers online. This setup is prone to creating backdoors that can be used by attackers. As enterprises try to create improved user experiences, they unwittingly open opportunities for successful DDoS attacks.

Hit-and-run DDoS

Also referred to as burst attacks, hit-and-run DDoS attacks are designed to create disruptions for a few seconds and recur after random intervals. As the term implies, it delivers bursts of denial-of-service that are then repeated over and over in an unpredictable pattern. The duration of the disruption as well as the interval of recurrence changes every so often, so it becomes difficult for organizations to deal with the problem.

This “innovative” attack will likely be employed by cybercriminals that fail are having a hard time defeating the defenses of their targets. Generally, security experts are only able to mitigate attacks if they are able to catch them in action. Hit-and-run DDoS creates short disruptions that don’t provide enough time for meaningful analysis. They then disappear and return again at unpredictable intervals and frequencies, throwing off security experts who are working on a solution.

Merging DDoS with other attacks

To maximize the impact of attacks, security analysts see the possibility of attackers merging DDoS with previous attempts to disrupt or breach a network. This combination of network incidents can maximize the potential gains of attacks. It muddles the ability to identify attacks and apply the necessary solutions. By incorporating DDoS with other attacks, it becomes easier to achieve the desired outcomes.

Merging of attacks is not exactly a new idea, but it will probably gain traction in the year ahead. Back in 2016, security analysts documented combinations of ransomware and DDoS attacks. This resulted in a more efficient, two-pronged approach in pursuing moneymaking cybercrimes. Under this scheme, ransomware-infected computers whose users refused to pay were converted to rentable DDoS botnets, creating another felonious revenue stream.

In summary

DDoS continues to become a serious threat for enterprises and businesses worldwide. As security firms develop advanced methods to deal with these attacks, cybercriminals likewise tweak or augment their attacks. They also take advantage of various vulnerabilities that have been neglected or that emerge because of changes in the way systems are created.

Not many pay attention to the DDoS threat, especially after reports in previous years claimed that they were becoming less prevalent. This shouldn’t be the case, though, as threat factors are growing, DDoS attacks are increasing, and attackers are merging them with other security incidents to maximize the damage.

SHARE
Share on FacebookShare on XShare on LinkedInShare on TelegramShare on BlueskyShare on Mastodon
Tags: DDoS attack trends

Search

Translation

CVE ALERTS
📧

Email Delivery
Get threat intel straight to your inbox.

♾️

Unlimited Vendors
Track every technology in your stack.

🚨

All New CVE Alerts
Be the first to know about new flaws.

⚙️

Custom EPSS Threshold
Filter noise, focus on real risks.

💬

Slack & Teams Webhook
Integrate directly into your SecOps.

🚫

100% Ad-Free
Enjoy an uninterrupted reading experience.

$7/mo
Subscribe Now

🚨 Active Exploits in the Wild

  • CVE-2026-42016CVSS 8.1
    JFrog Artifactory (Self Hosted) versions before 7.133.11 are vulnerable to a privilege escalation attack due to a validation...
    Admin intel📅 Updated: Sep 11, 2026
  • CVE-2026-42018CVSS 7.5
    JFrog Artifactory could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially...
    Admin intel📅 Updated: Sep 11, 2026
  • CVE-2026-20079CVSS 10.0
    A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated,...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2025-25249CVSS 8.1
    A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2026-87491
    Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute...
    Admin intelCISA KEV📅 Added to KEV: Sep 9, 2026📅 Updated: Sep 9, 2026
  • CVE-2026-19490
    Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1...
    CISA KEV📅 Added to KEV: Sep 9, 2026
  • CVE-2026-75650CVSS 10.0
    Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that...
    Admin intelCISA KEV📅 Added to KEV: Sep 8, 2026📅 Updated: Sep 8, 2026
  • CVE-2026-81963CVSS 7.8
    Improper link resolution before file access ('link following') in Windows Update Stack allows an authorized attacker to elevate...
    CISA KEV📅 Added to KEV: Sep 8, 2026
Powered by CVE Watchtower

🔴 Live Critical Threats

  • CVE-2026-82107CVSS 9.6
    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote...
  • CVE-2026-82100CVSS 9.6
    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote...
  • CVE-2026-81204CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to...
  • CVE-2026-80424CVSS 9.1
    IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote...
  • CVE-2026-79724CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to...
  • CVE-2026-78573CVSS 9.8
    IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote attacker...
  • CVE-2026-45764CVSS 9.1
    Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network...
  • CVE-2026-19646CVSS 9.1
    IBM Common Licensing Agent 9.0, Agent 9.0.0.1, Agent 9.0.0.2, ART 9.0, ART...
  • CVE-2026-89094CVSS 9.9
    Forgejo before 16.0.4 allows remote code execution via a crafted template repository...
  • CVE-2026-85025CVSS 9.8
    IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker...
Powered by CVE WATCHTOWER

Our Websites
  • Penetration Testing Tools
  • The Daily Information Technology
  • Top Exploited CVEs
  • Daily CyberSecurity

    • About SecurityOnline.info
    • Advertise with us
    • Announcement
    • Contact
    • Contributor Register
    • Login
    • Disclaimer
    • DCMA
    • Privacy Policy
    • About SecurityOnline.info
    • Advertise on SecurityOnline.info
    • Contact Us

    When you purchase through links on our site, we may earn an affiliate commission. Here’s how it works

    • CVE Watchtower
    • CVE Statistics by Vendor 2026
    • Q2 2026 Report
    • Top Exploited CVEs
    • Bluesky
    • Facebook
    • Linkedin
    • Mastodon
    • RSS
    • Twitter
    • Youtube
    © 2017 - 2026 Daily CyberSecurity. All Rights Reserved.