DigiCert has released its inaugural RADAR Threat Intelligence Brief, revealing a dramatic increase in distributed denial-of-service (DDoS) attacks and notable shifts in the worldwide cyber threat environment.
The report highlights unprecedented attack scales, evolving geopolitical attack origins, and rising automation, underscoring the need for enhanced cybersecurity resilience.
According to the Q3 2025 RADAR Brief, DigiCert’s telemetry recorded an “internet tsunami” of DDoS activity, with two incidents peaking at 2.4 terabits per second (Tbps) and 3.7 Tbps — among the largest attack sizes ever documented. These massive assaults demonstrate a fundamental shift in attack tactics, with cybercriminals deploying highly sophisticated and large-scale campaigns. DigiCert’s UltraDDoS Protect network successfully mitigated several multi-terabit attacks, preventing an estimated 3,000 hours of potential website downtime, highlighting the increasing scale and complexity of cyber threats.
The report also notes that the geopolitical landscape influences attack sources, with regions where digital infrastructure outpaces regulatory oversight emerging as new hotspots for malicious activity. Countries such as Vietnam, Russia, Colombia, and China are now among the top origins for attack traffic, complicating global cybersecurity efforts and attribution.
Higher education institutions saw a significant rise in DDoS activity, particularly during September, coinciding with the start of academic terms. The spike in attacks on universities and academic networks underscores their attractiveness as targets, possibly due to increased campus connectivity and perceived vulnerabilities, contrasting with other sectors like finance and IT that experienced relatively lower attack volumes during the same period.
Automation plays a growing role in cyber threats, with bot-driven attacks rising sharply—from 51% of recorded incidents in July to 73% by September. The report notes that September alone saw 32 million bot violations, emphasising the scale and velocity at which automated tools operate. Additionally, a 22,000% mid-quarter increase in DNS errors (FormErr) indicates how minor misconfigurations can cascade, amplifying risks across interconnected networks.
Michael Smith, DigiCert’s AppSec CTO, pointed out that attackers are mastering both precision and scale. The report reveals that during the quarter, targeted, high-impact attacks often targeted critical infrastructure and geopolitically sensitive regions. Notably, the United States accounted for 58% of global DDoS activity, with the UK and Saudi Arabia each comprising around 11%, underscoring the focus on vital infrastructure and regions with significant geopolitical influence.
DigiCert’s quarterly RADAR briefs leverage insights from its network monitoring tools—including UltraDNS, UltraDDoS Protect, and UltraWAF — to provide organisations with actionable intelligence. This ongoing analysis aims to help organisations anticipate cyber risks, strengthen their defenses, and respond more effectively to evolving threats.
As cyber threats continue to grow in scale and sophistication, the report emphasises the importance of comprehensive visibility across infrastructure, applications, and identity layers to maintain resilience in an increasingly hostile digital environment.










