Take control of what reaches your stack: Cybersecurity Month at Gcore
- October 1, 2026
- 4 min read

Every service connected to the internet makes decisions about traffic all day, even when nobody is thinking about them. Customers open an app, crawlers index pages, APIs answer requests, and most of the time the infrastructure sorts it out quietly.
The trouble starts when the wrong traffic gets through, and the window to react can be extremely short. In the last quarter of 2025, Gcore Radar counted 1.3 million DDoS attacks, up from 512,000 a year earlier, while the largest attack reached 12 Tbps, compared with 2.2 Tbps the year before. Three in four network-layer attacks lasted less than a minute, often too quickly for anyone to respond by hand.
Those numbers come from the traffic Gcore sees on its own network, and protecting what sits behind that network is a large part of what we do. This October, for Cybersecurity Month, we want to share more of what we see and make it easier for you to act on it: understand what reaches your stack, decide what should get through, and try some of that protection yourself.
A month of product updates, sessions, and a trip to Germany
We’ve spent the past few months preparing for October. There are product updates, a practical DDoS webinar, a live security Q&A, a bot-spotting game on Discord, weekly comics, and guides you can use on your own infrastructure. At the end of the month, we’re also heading to Nuremberg for it-sa. Here is where to start.
Try WAAP with €25 in credit
The simplest place to begin is your own traffic. Gcore WAAP (Web Application and API Protection) protects websites, web applications, and APIs from malicious requests at the edge, including common web attacks, abusive bots, and application-layer DDoS traffic. During October, you can claim €25 in Gcore credit for WAAP. WAAP Start costs €25 a month and covers up to five domains, so the credit is enough to put real sites behind WAAP for a month, see what is reaching your applications, and start deciding what to allow, challenge, or block.
Claim your €25 credit and activate WAAP Start by October 31. Your free month then runs for a full month from the activation date.

Two ways to control what reaches you
TrafficGate is designed for traffic that may not be an attack but still costs you: AI crawlers collecting content, scrapers, or legitimate clients calling an expensive endpoint too often. It helps teams see what is using their resources and decide what should be served, limited, or stopped at the edge. We’re opening TrafficGate to early adopters, who will also help shape the product as it develops.
Edge Proxy brings DDoS protection to services that do not sit on a network you own, such as a rented game server or an application running in the cloud. You provide an origin IP, port, and protocol, and Gcore returns a protected address that filters attack traffic before it reaches your service, with no ASN, BGP, or GRE tunnel required. During Cybersecurity Month, we’ll take a closer look at the latest version of Edge Proxy.
Learn how to keep your service online
On October 15 from 17:00 to 18:00 CEST, we’ll host Gcore Security, Live: Ask the Product Managers in the Gcore Discord community. Gcore product managers and their representatives will answer questions about security, the products we’re building, and the challenges teams are dealing with in practice.
Then, on October 20 at 17:00 CEST, we’ll host A Practical Guide to DDoS Protection, a webinar about protecting cloud and hosted servers, choosing the right protection, and avoiding common setup mistakes that can leave services exposed.

The Gcore Discord is also where Bot or Not? runs through the first half of the month. Each day, we’ll share an anonymized traffic scenario and ask you to work out what is behind it: a person, a useful crawler, or something you would want to stop. The answer and practical lesson follow the next day, and the series ends with a live competition.
Security you can put into practice
Through the rest of the month, we’ll publish material you can use on your own infrastructure: a developer security checklist covering DNS, exposed origins, rate limits, APIs, bot policies, and incident visibility; a customer security story; and a technical breakdown of a major DDoS attack stopped by Gcore.
That DDoS article will look at how the attack unfolded, what traffic was involved, the mitigation decisions, and what the protected service saw. Every Friday, Security, Simplified will explain one related idea in comic form, from what a DDoS attack actually does to how edge filtering keeps real users connected while an attack is underway.
See you in Nuremberg
From October 27 to 29, we’ll be at it-sa Expo&Congress in Nuremberg, Europe’s largest trade fair for IT security. If you’re there, come and talk to us about DDoS protection, bots, application security, traffic control, or whatever is keeping your team busy.
There will also be cute stickers, which may or may not be the most compelling security feature we announce this month.
Deciding what gets through
“Attacks are becoming faster, more automated, and increasingly AI-driven—allowing adversaries to adapt techniques, identify weaknesses, and scale attacks at a speed traditional defenses were never designed for. Security teams need real-time visibility across applications, APIs, and infrastructure, combined with intelligent controls that can detect, understand, and mitigate threats before they turn into incidents.”
— Andre Reitenbach, Chief Executive Officer, Gcore
Three in four network-layer attacks in our data lasted less than a minute. What protects a service in that minute is what was decided before it.
If October gives you a reason to test those decisions before an attacker does, the month will have done its job.
Related articles
Subscribe to our newsletter
Get the latest industry trends, exclusive insights, and Gcore updates delivered straight to your inbox.










