
On September 2, 2025, the Aisuru botnet launched a 29.7 terabits-per-second DDoS attackāshattering the previous 22.2 Tbps record set just three weeks earlier cybersecuritynewscloudflare. The attack lasted 69 seconds. It peaked at 14.1 billion packets per second and was one of 1,304 hyper-volumetric attacks Aisuru launched in Q3 2025 alone Bleeping Computer.
But hereās what should terrify you: Cloudflare blocked 8.3 million DDoS attacks in Q3 2025āa 40% increase year-over-year, bringing the 2025 year-to-date total to 36.2 million attacks, already 170% of all 2024 attacks cloudflare.
This isnāt an anomaly. Itās the new normal. š
š The Hockey Stick Is Here: Three Exponential Growth Curves Converging
ā” Curve #1: Attack Volume Explosion
Between 2013 and 2024, DDoS attack volume increased 20xāfrom 309 Gbps to 5.6 Tbps cloudflare. Then in 2025, we shattered through 29.7 Tbps. Thatās a 5.3x jump in a single year after a decade of steady 20x growth.
The math is terrifying:
Bits per second: 20x increase (2013-2024) cloudflare š„
Packets per second: 10x increase (2015-2024) cloudflare š„
Requests per second: 70x increase (2014-2024) cloudflare š
In Q1 2025 alone, Cloudflare blocked 20.5 million DDoS attacksāa 358% year-over-year increase cloudflare. The frequency curve is steepening faster than the volume curve.
š Curve #2: IoT Device Proliferation
Over 19.8 billion IoT devices were online in 2025, with projections pushing past 29 billion by 2030 teltonika-networks. But security hasnāt kept pace:
One in five IoT devices still uses default passwords jumpcloud š
More than 50% of IoT devices have critical vulnerabilities jumpcloud ā ļø
60% of IoT breaches happen due to outdated firmware jumpcloud šŖ²
820,000 daily IoT attacks globally deepstrike šÆ
The Aisuru botnet alone comprises an estimated 1-4 million infected hosts worldwide gbhackers. These arenāt sophisticated targetsātheyāre your camera, my router, someoneās smart thermostat.
š¤ Curve #3: AI-Powered Attack Automation
This is where it gets exponential.
AI enables real-time traffic analysis to identify weak points, adaptive attack patterns that change automatically to evade detection, and self-managing botnets that can recruit and coordinate compromised devices without human oversight sangfor.
In Q1 2025, DDoS incidents surged 358% compared to 2024, and the proportion of attacks causing actual production downtime rose 53% thehackernews. AI isnāt just making attacks biggerāitās making them more effective. šÆ
The pattern is clear: Machine learning algorithms analyze normal traffic patterns, detect vulnerabilities automatically, and enable attacks to dynamically adjust, automatically reacting to defense mechanisms vscanner.
šŖļø Where AI Acceleration Creates the Perfect Storm
š The Acceleration Is Measurable
The largest botnet detected in 2024 consisted of 227,000 devices compared to 136,000 devices in 2023āa 67% year-over-year increase barracuda. Then in Q1 2025, a botnet of 1.33 million devices emergedānearly six times larger than 2024ās record dailysecurityreview.
Q1 2025 saw a 110% increase in DDoS attacks compared to Q1 2024, and 2024 attack volumes were already 50% higher than 2023 dailysecurityreview. While direct measurements of AI-automated versus manual botnet recruitment speeds arenāt publicly available, the acceleration is evident: botnet sizes grew 6x while attack frequency doubled in a single year. š
Three AI-driven threats are compounding:
1. š Automated Vulnerability Discovery
According to Nozomi Networksā July 2025 analysis, 7.36% of all detected attacks are brute force attempts, while 5.27% directly exploit default credentials deepstrike. AI doesnāt get tired scanning for āadmin/adminā across millions of devices.
2. āļø Botnet Orchestration at Machine Speed
AI-driven bots automatically recruit new devices, coordinate attacks without human control, and adapt traffic patterns in real-time securityboulevard. Since early 2025, Cloudflare mitigated 2,867 Aisuru attacks, with 45% being hyper-volumetric Bleeping Computer.
3. š Evasion Through Pattern Mimicry
AI shapes attack traffic to look like legitimate users, making it harder for basic DDoS filters to distinguish malicious from normal traffic securityboulevard. The 29.7 Tbps attack used UDP carpet-bombing hitting 15,000 destination ports per second while randomizing packet attributes to evade defenses cloudflare.
āļø The Regulatory Hammer Is Coming: EU Cyber Resilience Act

Hereās the compliance reality manufacturers canāt ignore:
The EU Cyber Resilience Act entered into force December 10, 2024, with reporting obligations starting September 11, 2026, and full enforcement December 11, 2027 europa.
Key requirements:
Manufacturers must report actively exploited vulnerabilities within 24 hours to national CSIRTs and ENISA certifycomply ā°
Companies violating the CRA face fines up to ā¬15 million or 2.5% of worldwide annual turnover wsgr š°
Products that donāt comply cannot be sold in the EU after December 11, 2027 pillsburylaw š«
The clock is ticking: 27 months to full enforcement. ā³
ā ļø What Youāre Building When You Skip Device Identity
Let me be direct: The 2016 Mirai botnet attack that took down CNN, Netflix, and Twitter exploited IoT devices by logging in using well-known default usernames and passwords cm-alliance. Nine years later, Mirai variants resurged between 2023-2025, still exploiting default credentials in millions of devices astrill.
Weāre still making the same mistakes, just at 29.7 Tbps scale. š±
Every device without:
ā Unique device identity
ā PKI-based authentication
ā Certificate lifecycle management
ā Secure credential provisioning
...is tomorrowās botnet soldier. š§
Aisuruās attack traffic caused āwidespread collateral Internet disruption in the USā just from routing through ISPs cloudflare. Your unsecured device doesnāt just become a targetāit becomes a weapon aimed at critical infrastructure. šÆ
š”ļø The Path Forward: Security That Scales With the Threat
The math is simple: Attacks are growing exponentially. Manual response doesnāt scale. Device identity must be automated.
ā What Actually Works:
1. š Certificate-Based Device Identity at Manufacturing
Every device gets a unique cryptographic identity before first boot
No default passwords, ever
Zero-trust authentication from day one
2. š Automated Certificate Lifecycle Management
Continuous rotation without manual intervention
Revocation mechanisms that actually work at IoT scale
Post-quantum crypto readiness
3. š Supply Chain Security Visibility
Attestation of device identity through manufacturing
Secure boot and firmware signing
Tamper-evident credential provisioning
š° The Business Case: Prevention vs. Remediation
The financial case for proactive security is quantifiable:
Breach Costs:
Average single IoT security attack: $330,000 deepstrike
Breaches involving IoT devices: $5-10 million cumulative costs deepstrike
Industrial sector breaches: $5.56 million average deepstrike
Healthcare IoMT breaches: $10 million averageāthe costliest of any industry deepstrike š„
Manufacturing sector data breaches: $4.97 million in 2024 deviceauthority š
Implementation vs. Remediation: While specific ROI calculations for device identity implementation vary by deployment scale and industry vertical, organizations achieving mature zero-trust deployment (which includes device identity) report average breach costs of $3.28 millionā$1.76 million lower than organizations without mature programs startus-insights.
The cost differential is clear: invest in device identity at manufacturing, or pay multi-million dollar breach remediation costs later. šø
š The DigiCert Advantage: Built for 30 Billion Devices
Hereās where theory meets execution. DigiCert Device Trust solutions deliver:
š PKI at IoT scale: Managing millions of device certificates with the same rigor as web PKI
š”ļø Post-quantum readiness: Hybrid certificate algorithms protecting against both current and quantum threats
š Compliance automation: Built for EU Cyber Resilience Act, FDA 524B, Radio Equipment Directive
ā” Zero-touch provisioning: Devices ship with identity baked in at manufacturing
Contact DigiCert for a customized ROI analysis based on your device volume, vertical market, and compliance requirements.
šÆ The Question That Matters
Are you building the next generation of connected products with security as a foundationāor are you building the next Aisuru?
The 29.7 Tbps attack wasnāt the ceiling. It was the warning shot. šØ
With 29 billion IoT devices projected by 2030 teltonika-networks, AI-powered attack automation, and regulatory enforcement beginning in 27 months, the window for āweāll fix security laterā has closed.
The puck isnāt just movingāitās accelerating exponentially. šā”
š Call to Action
For Device Manufacturers: Is your current approach to device identity ready for:
ā EU CRA compliance by December 2027?
ā FDA Section 524B requirements for medical devices?
ā The reality of AI-powered vulnerability scanning?
šÆ Schedule a Device Trust assessment: Contact DigiCertās IoT Security Team
For Security Teams: Download our compliance roadmap: āEU Cyber Resilience Act: 24-Month Implementation Guide for Device Manufacturersā š„
The question isnāt whether to implement device identity and PKI-based authentication.
The question is whether you do it before December 11, 2027āor after your devices become part of the next record-breaking botnet. ā°
#IoTSecurity #Cybersecurity #DDoS #DeviceTrust #PKI #AIThreats #Botnets #CyberResilienceAct #EUCompliance #ZeroTrust #DeviceIdentity #CriticalInfrastructure #IoTVulnerabilities #PostQuantumCrypto #SupplyChainSecurity #IndustrialIoT #SmartDevices #CyberAttacks #SecurityByDesign #DigiCert #DeviceManufacturers #CISO #InfoSec #ThreatIntelligence #DDoSProtection #CyberDefense #ConnectedDevices #IoTCompliance #MedicalDevices #FDA524B #SecureManufacturing
š Sources & Further Reading
Primary Attack Data:
Cloudflare Q3 2025 DDoS Threat Report: https://blog.cloudflare.com/ddos-threat-report-2025-q3/
BleepingComputer - Aisuru botnet analysis: https://www.bleepingcomputer.com/news/security/aisuru-botnet-behind-new-record-breaking-297-tbps-ddos-attack/
Cybersecurity News - 29.7 Tbps attack details: https://cybersecuritynews.com/29-7-tbps-ddos-attack/
GBHackers - Aisuru Botnet Record: https://gbhackers.com/29-7-tbps-ddos-attack-by-aisuru-botnet/
Historical Growth Analysis:
Cloudflare - DDoS Attack Size Evolution (2013-2024): https://blog.cloudflare.com/bigger-and-badder-how-ddos-attack-sizes-have-evolved-over-the-last-decade/
Cloudflare Q1 2025 DDoS Threat Report: https://blog.cloudflare.com/ddos-threat-report-for-2025-q1/
Cloudflare Q2 2025 DDoS Threat Report: https://blog.cloudflare.com/ddos-threat-report-for-2025-q2/
IoT Security Statistics:
JumpCloud - IoT Security Risks 2025: https://jumpcloud.com/blog/iot-security-risks-stats-and-trends-to-know-in-2025
DeepStrike - IoT Hacking Statistics: https://deepstrike.io/blog/iot-hacking-statistics
Teltonika Networks - IoT Security Risks 2025: https://www.teltonika-networks.com/newsroom/top-iot-security-risks-in-2025-and-how-to-defend-against-them
Fortinet - IoT Device Vulnerabilities: https://www.fortinet.com/resources/cyberglossary/iot-device-vulnerabilities
AI & DDoS Evolution:
Sangfor - AI DDoS Attacks: https://www.sangfor.com/blog/cybersecurity/ai-ddos-attacks
The Hacker News - AIās Impact on DDoS: https://thehackernews.com/expert-insights/2025/08/the-new-face-of-ddos-is-impacted-by-ai.html
MazeBolt/VScanner - DDoS Attack Trends 2025: https://vscanner.ai/blog/ddos-attack-trends-for-2025-and-the-impact-of-artificial-intelligence
A10 Networks - AI in DDoS Attacks: https://www.a10networks.com/blog/the-machine-war-has-begun-cybercriminals-leveraging-ai-in-ddos-attacks/
EU Cyber Resilience Act:
European Commission - Official CRA Page: https://digital-strategy.ec.europa.eu/en/policies/cyber-resilience-act
Pillsbury Law - CRA Requirements Timeline: https://www.pillsburylaw.com/en/news-and-insights/eu-cyber-resilience-act-requirements-products-software.html
Wilson Sonsini - CRA Compliance Guide: https://www.wsgr.com/en/insights/new-eu-cybersecurity-obligations-for-connected-devices-what-you-need-to-know.html
Cyber Resilience Act Official Resource:
https://www.cyberresilienceact.eu/
NCSC Finland - CRA Implementation: https://www.kyberturvallisuuskeskus.fi/en/toimintamme/saantely-ja-valvonta/kyberkestavyyssaados-cyber-resilience-act-cra
Botnet Growth & Scale Data:
Barracuda Networks - 2024 Botnet Landscape: https://blog.barracuda.com/2025/03/21/top-threats-of-the-2024-botnet-landscape
Daily Security Review - Q1 2025 Botnet Report: https://dailysecurityreview.com/security-spotlight/massive-1-33-million-device-botnet-drives-unprecedented-ddos-attacks-surge-in-q1-2025/
XLab Research - Aisuru Deep Dive: https://blog.xlab.qianxin.com/super-large-scale-botnet-aisuru-en/
Cost & ROI Analysis:
DeepStrike - IoT Security Breach Costs: https://deepstrike.io/blog/iot-hacking-statistics
StartUs Insights - Emerging Cybersecurity Technologies: https://www.startus-insights.com/innovators-guide/emerging-cybersecurity-technologies/
Device Authority - Industrial IoT Security Threats: https://deviceauthority.com/industrial-iot-security-threats-top-risks-and-mitigation-strategies-2025/
Device Authority - Healthcare IoT Breach: https://deviceauthority.com/healthcare-iot-security-breach-2025-why-over-1-million-devices-were-exposed/
Additional Context:
Gcore Radar - Q1-Q2 2025 DDoS Report: https://gcore.com/press-releases/gcore-radar-ddos-attack-trends-q1-q2-2025
eSecurity Planet - Aisuru Analysis: https://www.esecurityplanet.com/threats/aisuru-botnet-shatters-records-with-29-7-tbps-ddos-attack/
Cybersecurity Dive - Q3 DDoS Trends: https://www.cybersecuritydive.com/news/ddos-rises-q3-aisuru-botnet-record-attack/806922/