🔧 AI Nachrichten Evernote 11.30.6(24.08.2026 um 17:14 Uhr)
🔧 AI Nachrichten Speed Limiters, Short Cables, and Other EV Road Trip Revelations(26.08.2026 um 21:51 Uhr)
🔧 AI Nachrichten Hands-On with ChatGPT Work’s New Cloud Browser Feature(26.08.2026 um 17:06 Uhr)
🔧 AI Nachrichten Anthropic Introduces an In-App Browser for Claude Cowork(27.08.2026 um 16:18 Uhr)
🔧 AI Nachrichten Monthly Log: August 2026(31.08.2026 um 16:24 Uhr)
🔧 AI Nachrichten Inside OpenAI’s Codex with Andrew Ambrosino(31.08.2026 um 17:26 Uhr)
🎥 PodcastsDesigned in California Makes Its Official Debut(03.09.2026 um 17:59 Uhr)
🔧 AI Nachrichten Evernote 11.30.6(24.08.2026 um 17:14 Uhr)
🔧 AI Nachrichten Speed Limiters, Short Cables, and Other EV Road Trip Revelations(26.08.2026 um 21:51 Uhr)
🔧 AI Nachrichten Hands-On with ChatGPT Work’s New Cloud Browser Feature(26.08.2026 um 17:06 Uhr)
🔧 AI Nachrichten Anthropic Introduces an In-App Browser for Claude Cowork(27.08.2026 um 16:18 Uhr)
🔧 AI Nachrichten Monthly Log: August 2026(31.08.2026 um 16:24 Uhr)
🔧 AI Nachrichten Inside OpenAI’s Codex with Andrew Ambrosino(31.08.2026 um 17:26 Uhr)
🎥 PodcastsDesigned in California Makes Its Official Debut(03.09.2026 um 17:59 Uhr)

26 🕛 kürzlich 3 Min Lesezeit CVE-RADAR
0

When Analytics Said Nothing, Bots Were 90% of the Traffic

↗ Quelle (dev.to)
🗣️ Stimme:

For months, ChinaGlobalSouth was under constant attack.



The site was already protected by several well-known WordPress security tools: Wordfence, Sucuri, All In One Security. But the attacks kept coming. Cloudflare’s Under Attack Mode was being triggered almost every day, and the team could not understand why.



The problem was not simply that the site was “slow.”

The real question was: why was a news site constantly behaving like it was under siege?



At first, we looked at the usual sources: Google Analytics, Plausible, server logs, Cloudflare signals. Nothing looked obviously abnormal. Human traffic seemed normal. The site would stabilize for a while, then suddenly fall back into Cloudflare UAM again.



We installed Shield ( .



And the picture changed completely.



More than 60% of the traffic was automated bot activity, including SEO spam attempts, fake browser user agents, scraping clients, and abnormal request patterns designed to overload, pollute, or manipulate the site.



Example attack patterns we found:




  1. SEO spam injection through WordPress search



Bots were injecting spam keywords into the ?s= search parameter, trying to get those terms indexed through the site’s own search result pages.



Examples included spam signatures like:



cleantalkorg2.ru

batmanapollo

Stock Market breaking news english

Психолог Онлайн

encoded external URLs

This was not normal search traffic. It was an attempt to use the site’s HTML as an SEO spam surface.




  1. Fake browser user agents



One repeated user agent looked like a browser, but it was not a real one:



Mozilla/5.0 AppleWebKit/605.1.15 (KHTML, like Gecko) Chrome/139.0.0.0 Safari/605.1.15

The problem: AppleWebKit/605 belongs to Safari-like traffic. Real Chrome usually reports AppleWebKit/537.36, and the platform block was missing. This was a scraper pretending to be a browser, badly.



The volume was also increasing hour by hour.




  1. Non-browser HTTP clients



We also saw clients that should almost never appear as normal reader traffic on a news website:



Embarcadero URI Client/1.0

Go-http-client/2.0

These are automation clients, not typical human visitors.



Once Radar exposed the real traffic, we could train Shield’s AI with the correct signals. Instead of guessing, we could build rules based on actual attacker behavior.



The result: the attacks were identified, classified, and blocked much more effectively.



The lesson was simple:



You cannot protect what you cannot see.



Performance, security, and observability are no longer separate problems. On modern WordPress sites, especially publishers and high-traffic content sites, bot traffic can look like a hosting issue, an SEO issue, or a Cloudflare issue.



But sometimes the real problem is hidden in plain sight: thousands of requests pretending to be normal traffic.



Radar gave us visibility.

Together, they turned a confusing performance problem into a clear security response.

Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf dev.to.
↗ Original-Artikel auf dev.to lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 49%
🟡 In Evaluierung 29%
🟢 Keine Auswirkung 10%
Spannende Innovation 12%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
2 Quellen
Hands-On with ChatGPT Work’s New Cloud Browser Feature
1 Quelle
Evernote 11.30.6
1 Quelle
Speed Limiters, Short Cables, and Other EV Road Trip Revelations
Ähnliche Beiträge
🔍 Verwandte News

Auch interessante Nachrichten When Analytics Said Nothing, Bots Were 90% of the Traffic

Thematisch verwandte Begriffe: When, Analytics, Said, Nothing · 6 Treffer

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...

Laden...

Beiträge werden geladen ...

Laden...

Videos werden geladen ...