Summary is AI-generated, newsdesk-reviewed
  • DigiCert's Q4 2025 RADAR report details rising internet demand and evolving cyber threats.
  • DDoS attacks now prolonged, increasing system strain and challenging short-term defence strategies.
  • Application-layer threats are quietly exploiting systems with sustained automated probing.

DigiCert has unveiled its Q4 2025 RADAR Threat Intelligence Brief, offering detailed insights into the intersection of worldwide internet demand and cybersecurity challenges during the final quarter of the year. Based on trillions of network activities observed via DigiCert’s expansive security platform—comprising UltraDNS, UltraDDoS Protect, and UltraWAF—this report presents a detailed examination of the contemporary threat environment.

The fourth-quarter analysis indicates ongoing, considerable pressure on internet infrastructure as the year concludes. There is a rise in online activities due to business cycles, consumer transactions, travel-related surges, and new device activations. These events coincide with increased malicious actions, underscoring the importance of robust, multi-layered security solutions.

Elevated online content demand

Data indicates consistently high internet traffic, with notable spikes around significant events. DigiCert’s DNS metrics reveal that what were previously short demand surges have transformed into prolonged periods of high load, extending across weeks. During these busy seasons, the notion of "off-peak" periods no longer applies.

Additionally, there was a persistent rise in certain DNS signals, including NXDOMAIN requests and automation tool queries, suggesting continual activity in:

  • Internet scanning
  • System misconfigurations causing repeated bad requests
  • Automated probing by bots and reconnaissance tools

Significance:

  • Peak demand has become the standard, eliminating reliance on brief recovery times.
  • Continuous DNS pressure exists, even when it appears otherwise.
  • Manual or reactive security strategies are ineffective against sustained demand.
  • Increased risks of outages and exploitation due to ongoing scanning and misconfigurations.

Evolution of DDoS activity

Throughout Q4, DDoS attacks grew in number, magnitude, and longevity. Instead of short disruptions, attacks now aim to apply prolonged pressure, indicating a strategic shift towards weakening infrastructure over time.

Implications:

  • Extended attacks necessitate prolonged defensive responses, rather than quick fixes.
  • There is a heightened risk of performance degradation, beyond complete outages.
  • Conventional defenses designed for brief spikes may be inadequate against enduring pressures.
  • Sustained attacks increase operational costs and affect customer experiences.

Focused application-layer threats

Web application threats remain predominantly automated, with attackers persistently testing application responses to various requests. Rather than loud, singular assaults, attackers are engaging in persistent probing using techniques like cookie manipulation to uncover weaknesses quietly over time. Despite fluctuating attack volumes, the approach remains unchanged: covert, continuous testing rather than overt disruption.

Consequences:

  • Applications face ongoing testing even when traffic appears normal.
  • Subtle attacks are difficult to detect and can persist longer.
  • Consistent probing can escalate minor misconfigurations into significant security issues.
  • Defenses must function continuously, not merely react to apparent spikes.

Enduring through constant demand and pressure

What Q4 reinforces is that resilience is no longer about absorbing isolated spikes in traffic and attacks,” stated Michael Smith, AppSec CTO at DigiCert.

With the ever-increasing scale of internet bandwidth and the creation of the Aisuru and Kimwolf botnets, organisations must be prepared to operate under prolonged demand and sustained attack pressure across DNS, network, and application layers simultaneously.

In case you missed it

Responsible AI adoption starts with governance
Responsible AI adoption starts with governance

The eagerness to adopt AI in physical security is increasing as teams want to implement technology solutions for faster, smarter operations. At the same time, the conversations sur...

How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence
How AI-enabled cameras are becoming operational sensors that power safety, automation, and business intelligence

The biggest return on investment from an AI-enabled camera might have nothing to do with security. Organisations are increasingly discovering that the same cameras installed to pro...

Solink's AI agents boost efficiency of existing infrastructure with automation
Solink's AI agents boost efficiency of existing infrastructure with automation

Deploying artificial intelligence (AI) tools should be seen as a business initiative rather than a technology initiative, says Martin Soukup, CTO of Solink, a cloud-based video sec...