Q3 2025 DDoS review: botnets and entry-point management

Changing attack devices make service inventory and origin access controls more important.

Contents of this article

Distinguish the quarter from the publication date

Cloudflare published its Q3 report on December 3, 2025, focusing on Aisuru botnet activity. The quarter identifies the observation period, not the publication date.

Maintain an inventory of every public entry point

A service may expose a website, APIs, game ports and test domains. Protecting only the main hostname leaves other paths to the same backend. Maintain one inventory of addresses, protocols, ports and owners, including retired entry points.

A network address is not a user identity

Mobile and enterprise users can share an egress address. Aggressive IP-only limits may block legitimate sign-ins. For HTTP services, assess endpoint cost, sessions and failure behavior at the application layer alongside network mitigation.

Close unintended bypass paths

Review unprotected A/AAAA records, old IPs, direct ports and management endpoints. Retain required health checks and controlled administration paths, with rollback instructions, so closing bypasses does not remove recovery access.

References

Cloudflare Q3 2025 DDoS report

Related products and onboarding

View products and onboarding information

Back to industry insights Contact technical support