On September 2, 2025, the Aisuru botnet launched a 29.7 terabits-per-second DDoS attack—shattering the previous 22.2 Tbps record set just three weeks earlier cybersecuritynewscloudflare. The attack lasted 69 seconds. It peaked at 14.1 billion packets per second and was one of 1,304 hyper-volumetric attacks Aisuru launched in Q3 2025 alone Bleeping Computer.

But here’s what should terrify you: Cloudflare blocked 8.3 million DDoS attacks in Q3 2025—a 40% increase year-over-year, bringing the 2025 year-to-date total to 36.2 million attacks, already 170% of all 2024 attacks cloudflare.

This isn’t an anomaly. It’s the new normal. šŸ“ˆ

šŸ“Š The Hockey Stick Is Here: Three Exponential Growth Curves Converging

⚔ Curve #1: Attack Volume Explosion

Between 2013 and 2024, DDoS attack volume increased 20x—from 309 Gbps to 5.6 Tbps cloudflare. Then in 2025, we shattered through 29.7 Tbps. That’s a 5.3x jump in a single year after a decade of steady 20x growth.

The math is terrifying:

  • Bits per second: 20x increase (2013-2024) cloudflare šŸ’„

  • Packets per second: 10x increase (2015-2024) cloudflare šŸ”„

  • Requests per second: 70x increase (2014-2024) cloudflare šŸš€

In Q1 2025 alone, Cloudflare blocked 20.5 million DDoS attacks—a 358% year-over-year increase cloudflare. The frequency curve is steepening faster than the volume curve.

🌐 Curve #2: IoT Device Proliferation

Over 19.8 billion IoT devices were online in 2025, with projections pushing past 29 billion by 2030 teltonika-networks. But security hasn’t kept pace:

  • One in five IoT devices still uses default passwords jumpcloud šŸ”“

  • More than 50% of IoT devices have critical vulnerabilities jumpcloud āš ļø

  • 60% of IoT breaches happen due to outdated firmware jumpcloud 🪲

  • 820,000 daily IoT attacks globally deepstrike šŸŽÆ

The Aisuru botnet alone comprises an estimated 1-4 million infected hosts worldwide gbhackers. These aren’t sophisticated targets—they’re your camera, my router, someone’s smart thermostat.

šŸ¤– Curve #3: AI-Powered Attack Automation

This is where it gets exponential.

AI enables real-time traffic analysis to identify weak points, adaptive attack patterns that change automatically to evade detection, and self-managing botnets that can recruit and coordinate compromised devices without human oversight sangfor.

In Q1 2025, DDoS incidents surged 358% compared to 2024, and the proportion of attacks causing actual production downtime rose 53% thehackernews. AI isn’t just making attacks bigger—it’s making them more effective. šŸŽÆ

The pattern is clear: Machine learning algorithms analyze normal traffic patterns, detect vulnerabilities automatically, and enable attacks to dynamically adjust, automatically reacting to defense mechanisms vscanner.

šŸŒŖļø Where AI Acceleration Creates the Perfect Storm

šŸ“ˆ The Acceleration Is Measurable

The largest botnet detected in 2024 consisted of 227,000 devices compared to 136,000 devices in 2023—a 67% year-over-year increase barracuda. Then in Q1 2025, a botnet of 1.33 million devices emerged—nearly six times larger than 2024’s record dailysecurityreview.

Q1 2025 saw a 110% increase in DDoS attacks compared to Q1 2024, and 2024 attack volumes were already 50% higher than 2023 dailysecurityreview. While direct measurements of AI-automated versus manual botnet recruitment speeds aren’t publicly available, the acceleration is evident: botnet sizes grew 6x while attack frequency doubled in a single year. šŸ“Š

Three AI-driven threats are compounding:

1. šŸ” Automated Vulnerability Discovery

According to Nozomi Networks’ July 2025 analysis, 7.36% of all detected attacks are brute force attempts, while 5.27% directly exploit default credentials deepstrike. AI doesn’t get tired scanning for ā€œadmin/adminā€ across millions of devices.

2. āš™ļø Botnet Orchestration at Machine Speed

AI-driven bots automatically recruit new devices, coordinate attacks without human control, and adapt traffic patterns in real-time securityboulevard. Since early 2025, Cloudflare mitigated 2,867 Aisuru attacks, with 45% being hyper-volumetric Bleeping Computer.

3. šŸŽ­ Evasion Through Pattern Mimicry

AI shapes attack traffic to look like legitimate users, making it harder for basic DDoS filters to distinguish malicious from normal traffic securityboulevard. The 29.7 Tbps attack used UDP carpet-bombing hitting 15,000 destination ports per second while randomizing packet attributes to evade defenses cloudflare.

āš–ļø The Regulatory Hammer Is Coming: EU Cyber Resilience Act

Here’s the compliance reality manufacturers can’t ignore:

The EU Cyber Resilience Act entered into force December 10, 2024, with reporting obligations starting September 11, 2026, and full enforcement December 11, 2027 europa.

Key requirements:

  • Manufacturers must report actively exploited vulnerabilities within 24 hours to national CSIRTs and ENISA certifycomply ā°

  • Companies violating the CRA face fines up to €15 million or 2.5% of worldwide annual turnover wsgr šŸ’°

  • Products that don’t comply cannot be sold in the EU after December 11, 2027 pillsburylaw 🚫

The clock is ticking: 27 months to full enforcement. ā³

āš ļø What You’re Building When You Skip Device Identity

Let me be direct: The 2016 Mirai botnet attack that took down CNN, Netflix, and Twitter exploited IoT devices by logging in using well-known default usernames and passwords cm-alliance. Nine years later, Mirai variants resurged between 2023-2025, still exploiting default credentials in millions of devices astrill.

We’re still making the same mistakes, just at 29.7 Tbps scale. 😱

Every device without:

  • āœ… Unique device identity

  • āœ… PKI-based authentication

  • āœ… Certificate lifecycle management

  • āœ… Secure credential provisioning

...is tomorrow’s botnet soldier. 🧟

Aisuru’s attack traffic caused ā€œwidespread collateral Internet disruption in the USā€ just from routing through ISPs cloudflare. Your unsecured device doesn’t just become a target—it becomes a weapon aimed at critical infrastructure. šŸŽÆ

šŸ›”ļø The Path Forward: Security That Scales With the Threat

The math is simple: Attacks are growing exponentially. Manual response doesn’t scale. Device identity must be automated.

āœ… What Actually Works:

1. šŸ” Certificate-Based Device Identity at Manufacturing

  • Every device gets a unique cryptographic identity before first boot

  • No default passwords, ever

  • Zero-trust authentication from day one

2. šŸ”„ Automated Certificate Lifecycle Management

  • Continuous rotation without manual intervention

  • Revocation mechanisms that actually work at IoT scale

  • Post-quantum crypto readiness

3. šŸ”— Supply Chain Security Visibility

  • Attestation of device identity through manufacturing

  • Secure boot and firmware signing

  • Tamper-evident credential provisioning

šŸ’° The Business Case: Prevention vs. Remediation

The financial case for proactive security is quantifiable:

Breach Costs:

  • Average single IoT security attack: $330,000 deepstrike

  • Breaches involving IoT devices: $5-10 million cumulative costs deepstrike

  • Industrial sector breaches: $5.56 million average deepstrike

  • Healthcare IoMT breaches: $10 million average—the costliest of any industry deepstrike šŸ„

  • Manufacturing sector data breaches: $4.97 million in 2024 deviceauthority šŸ­

Implementation vs. Remediation: While specific ROI calculations for device identity implementation vary by deployment scale and industry vertical, organizations achieving mature zero-trust deployment (which includes device identity) report average breach costs of $3.28 million—$1.76 million lower than organizations without mature programs startus-insights.

The cost differential is clear: invest in device identity at manufacturing, or pay multi-million dollar breach remediation costs later. šŸ’ø

šŸš€ The DigiCert Advantage: Built for 30 Billion Devices

Here’s where theory meets execution. DigiCert Device Trust solutions deliver:

  • šŸ”’ PKI at IoT scale: Managing millions of device certificates with the same rigor as web PKI

  • šŸ›”ļø Post-quantum readiness: Hybrid certificate algorithms protecting against both current and quantum threats

  • šŸ“‹ Compliance automation: Built for EU Cyber Resilience Act, FDA 524B, Radio Equipment Directive

  • ⚔ Zero-touch provisioning: Devices ship with identity baked in at manufacturing

Contact DigiCert for a customized ROI analysis based on your device volume, vertical market, and compliance requirements.

šŸŽÆ The Question That Matters

Are you building the next generation of connected products with security as a foundation—or are you building the next Aisuru?

The 29.7 Tbps attack wasn’t the ceiling. It was the warning shot. 🚨

With 29 billion IoT devices projected by 2030 teltonika-networks, AI-powered attack automation, and regulatory enforcement beginning in 27 months, the window for ā€œwe’ll fix security laterā€ has closed.

The puck isn’t just moving—it’s accelerating exponentially. šŸ’āš”


šŸ“ž Call to Action

For Device Manufacturers: Is your current approach to device identity ready for:

  • āœ… EU CRA compliance by December 2027?

  • āœ… FDA Section 524B requirements for medical devices?

  • āœ… The reality of AI-powered vulnerability scanning?

šŸŽÆ Schedule a Device Trust assessment: Contact DigiCert’s IoT Security Team

For Security Teams: Download our compliance roadmap: ā€œEU Cyber Resilience Act: 24-Month Implementation Guide for Device Manufacturersā€ šŸ“„

The question isn’t whether to implement device identity and PKI-based authentication.

The question is whether you do it before December 11, 2027—or after your devices become part of the next record-breaking botnet. ā°

#IoTSecurity #Cybersecurity #DDoS #DeviceTrust #PKI #AIThreats #Botnets #CyberResilienceAct #EUCompliance #ZeroTrust #DeviceIdentity #CriticalInfrastructure #IoTVulnerabilities #PostQuantumCrypto #SupplyChainSecurity #IndustrialIoT #SmartDevices #CyberAttacks #SecurityByDesign #DigiCert #DeviceManufacturers #CISO #InfoSec #ThreatIntelligence #DDoSProtection #CyberDefense #ConnectedDevices #IoTCompliance #MedicalDevices #FDA524B #SecureManufacturing


šŸ“š Sources & Further Reading

Primary Attack Data:

  1. Cloudflare Q3 2025 DDoS Threat Report: https://blog.cloudflare.com/ddos-threat-report-2025-q3/

  2. BleepingComputer - Aisuru botnet analysis: https://www.bleepingcomputer.com/news/security/aisuru-botnet-behind-new-record-breaking-297-tbps-ddos-attack/

  3. Cybersecurity News - 29.7 Tbps attack details: https://cybersecuritynews.com/29-7-tbps-ddos-attack/

  4. GBHackers - Aisuru Botnet Record: https://gbhackers.com/29-7-tbps-ddos-attack-by-aisuru-botnet/

Historical Growth Analysis:

  1. Cloudflare - DDoS Attack Size Evolution (2013-2024): https://blog.cloudflare.com/bigger-and-badder-how-ddos-attack-sizes-have-evolved-over-the-last-decade/

  2. Cloudflare Q1 2025 DDoS Threat Report: https://blog.cloudflare.com/ddos-threat-report-for-2025-q1/

  3. Cloudflare Q2 2025 DDoS Threat Report: https://blog.cloudflare.com/ddos-threat-report-for-2025-q2/

IoT Security Statistics:

  1. JumpCloud - IoT Security Risks 2025: https://jumpcloud.com/blog/iot-security-risks-stats-and-trends-to-know-in-2025

  2. DeepStrike - IoT Hacking Statistics: https://deepstrike.io/blog/iot-hacking-statistics

  3. Teltonika Networks - IoT Security Risks 2025: https://www.teltonika-networks.com/newsroom/top-iot-security-risks-in-2025-and-how-to-defend-against-them

  4. Fortinet - IoT Device Vulnerabilities: https://www.fortinet.com/resources/cyberglossary/iot-device-vulnerabilities

AI & DDoS Evolution:

  1. Sangfor - AI DDoS Attacks: https://www.sangfor.com/blog/cybersecurity/ai-ddos-attacks

  2. The Hacker News - AI’s Impact on DDoS: https://thehackernews.com/expert-insights/2025/08/the-new-face-of-ddos-is-impacted-by-ai.html

  3. MazeBolt/VScanner - DDoS Attack Trends 2025: https://vscanner.ai/blog/ddos-attack-trends-for-2025-and-the-impact-of-artificial-intelligence

  4. A10 Networks - AI in DDoS Attacks: https://www.a10networks.com/blog/the-machine-war-has-begun-cybercriminals-leveraging-ai-in-ddos-attacks/

EU Cyber Resilience Act:

  1. European Commission - Official CRA Page: https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act

  2. Pillsbury Law - CRA Requirements Timeline: https://www.pillsburylaw.com/en/news-and-insights/eu-cyber-resilience-act-requirements-products-software.html

  3. Wilson Sonsini - CRA Compliance Guide: https://www.wsgr.com/en/insights/new-eu-cybersecurity-obligations-for-connected-devices-what-you-need-to-know.html

  4. Cyber Resilience Act Official Resource:

https://www.cyberresilienceact.eu/

  1. NCSC Finland - CRA Implementation: https://www.kyberturvallisuuskeskus.fi/en/toimintamme/saantely-ja-valvonta/kyberkestavyyssaados-cyber-resilience-act-cra

Botnet Growth & Scale Data:

  1. Barracuda Networks - 2024 Botnet Landscape: https://blog.barracuda.com/2025/03/21/top-threats-of-the-2024-botnet-landscape

  2. Daily Security Review - Q1 2025 Botnet Report: https://dailysecurityreview.com/security-spotlight/massive-1-33-million-device-botnet-drives-unprecedented-ddos-attacks-surge-in-q1-2025/

  3. XLab Research - Aisuru Deep Dive: https://blog.xlab.qianxin.com/super-large-scale-botnet-aisuru-en/

Cost & ROI Analysis:

  1. DeepStrike - IoT Security Breach Costs: https://deepstrike.io/blog/iot-hacking-statistics

  2. StartUs Insights - Emerging Cybersecurity Technologies: https://www.startus-insights.com/innovators-guide/emerging-cybersecurity-technologies/

  3. Device Authority - Industrial IoT Security Threats: https://deviceauthority.com/industrial-iot-security-threats-top-risks-and-mitigation-strategies-2025/

  4. Device Authority - Healthcare IoT Breach: https://deviceauthority.com/healthcare-iot-security-breach-2025-why-over-1-million-devices-were-exposed/

Additional Context:

  1. Gcore Radar - Q1-Q2 2025 DDoS Report: https://gcore.com/press-releases/gcore-radar-ddos-attack-trends-q1-q2-2025

  2. eSecurity Planet - Aisuru Analysis: https://www.esecurityplanet.com/threats/aisuru-botnet-shatters-records-with-29-7-tbps-ddos-attack/

  3. Cybersecurity Dive - Q3 DDoS Trends: https://www.cybersecuritydive.com/news/ddos-rises-q3-aisuru-botnet-record-attack/806922/