Hasty Briefsbeta

Bilingual

Understanding the Recent DDoS Attack Against Read the Docs

20 days ago
  • Read the Docs experienced a major DDoS attack in June 2026, peaking at 5.5 million requests per minute, 100 times normal traffic.
  • The attack was globally distributed, used randomized headers/TLS, adapted to defenses, and targeted cache-bypassing URLs like 404s and 302 redirects.
  • Defense strategies included aggressive caching, Cloudflare edge services, targeted rate limiting, and client fingerprinting rather than simple IP blocking.
  • Key lessons: cache everything, protect cache-miss surfaces, use targeted challenges, and manage infrastructure as code.
  • The attack lasted nearly ten days, but the team maintained availability without resorting to universal JavaScript challenges.