Summary is AI-generated, newsdesk-reviewed
  • DigiCert's Q4 2025 RADAR Brief highlights increased cyber threats during peak internet demand.
  • Sustained DDoS attacks are evolving, demanding longer, more resilient security measures.
  • Automated application threats persist, necessitating continuous rather than reactive defenses.

DigiCert, a key player in the field of intelligent trust, has released its Q4 2025 RADAR Threat Intelligence Brief, showcasing critical insights into the interplay of global internet demand and cyber threats during the quarter. Leveraging data from trillions of network events handled by DigiCert's global security platform, which includes services like UltraDNS, UltraDDoS Protect, and UltraWAF, RADAR offers an extensive perspective on the current threat landscape.

The brief reveals the persistent pressure on internet infrastructure during year-end periods. Seasonal surges in online activity due to business cycles, consumer shopping, travel, and device activations have coincided with a noticeable rise in malicious activities, underscoring the importance of robust, multi-layered security solutions.

Continued Demand for Online Content

The fourth quarter saw sustained high levels of internet traffic, with brief spikes aligning with major events. DigiCert's DNS usage analysis indicates that previously brief periods of high demand have extended into longer, continuous periods, blurring the distinction between peak and off-peak times. Additionally, DNS signals such as elevated NXDOMAIN requests and queries from automation tools suggest ongoing:

  • Internet scanning
  • Misconfigured systems causing repeated bad requests
  • Automated probing by bots and tools

Significance:

  • Peak demand as a norm: Systems can no longer depend on short recovery breaks.
  • Continuous background load: DNS infrastructure faces constant pressure, even when there seems to be no apparent activity.
  • Scalability challenges: Reliance on manual or reactive approaches is ineffective due to the sustained nature of load.
  • Increased risk: Persistent scanning and misconfigurations heighten the chances of outages or security breaches.

Escalating and Evolving DDoS Activity

DDoS attacks intensified in both scale and duration throughout Q4. Attackers shifted tactics from brief disruptions to prolonged assaults designed to exert continuous pressure on system infrastructure and defenses. This trend indicates an evolution from transient attacks to sustained efforts to compromise systems.

Significance:

  • Longer attack durations: DDoS attacks are becoming extended events, requiring ongoing defense efforts.
  • Risk of performance issues: Longer attacks lead to degraded performance, beyond complete outages.
  • Need for improved defenses: Systems that focus solely on handling short bursts may be inadequate against prolonged pressure.
  • Cost and impact concerns: Extended attacks quietly increase operational costs and affect customer experiences.

Automated yet Focused Application-Layer Threats

Application-layer attacks predominantly utilized automated tools for consistently probing applications with various requests. The strategy involved subtle, continuous testing such as cookie manipulation to identify vulnerabilities over time, rather than launching overt and disruptive attacks.

Significance:

  • Constant application testing: Applications undergo ongoing tests, even when traffic appears normal.
  • Difficulty in detection: These quieter attacks are harder to identify and can persist longer.
  • Risk of misconfigurations: Continuous probing enhances the chances that minor misconfigurations become significant security threats.
  • Continuous defense requirement: Security measures must operate persistently, not just react to sudden increases in traffic.

Operating under demand and pressure

An emphasis on enduring through constant demand and pressure was highlighted. "What Q4 reinforces is that resilience is no longer about absorbing isolated spikes in traffic and attacks," said Michael Smith, AppSec CTO at DigiCert.

"With the ever-increasing scale of internet bandwidth and the creation of the Aisuru and Kimwolf botnets, organizations must be prepared to operate under prolonged demand and sustained attack pressure across DNS, network, and application layers simultaneously."

In case you missed it

How Is The Role Of Biometrics Changing In Physical Access Control?
How Is The Role Of Biometrics Changing In Physical Access Control?

Biometrics today provide better security and frictionless user experiences. Biometric identifiers like fingerprints, facial recognition, and iris scans are unique and difficult to...

Dormakaba Acquires Alliants: Hospitality Access Solutions
Dormakaba Acquires Alliants: Hospitality Access Solutions

dormakaba has signed a binding agreement to acquire Alliants Limited, the guest experience technology partner behind more than 100,000 hotel rooms for the world’s leading hos...

Allied Universal® Honored As Admired Workplace By Newsweek
Allied Universal® Honored As Admired Workplace By Newsweek

Allied Universal®, the world's pioneer security and facility services provider, has been named one of America's Most Admired Workplaces by Newsweek for the third consecutive ye...