I'm curious if anybody could speculate who would be attacking a documentation silo, and to what end?
I run a similar service, and we get almost daily attacks like this. Sometimes it's a specific high-profile customer, other times it's broader.
I can't speak for RTD, but I think it's less "documentation site" and more just that we sit on the domains of high-profile products and the tools are just looking for any hole they can find?
Often it's even the company themselves, for whatever reason (security research, etc).
Could be testing in preparation for attacking something more critical?
Either testing for something bigger OR demonstrating their power to a 3rd party with minimal real disruption
Could have been a live-fire exercise by a nation state.
Edit: why the down vote? That is literally in the realm of possibility!
I'm the author of the blog. I don't know. Internally, we were half joking that we were going to get ransom notice, but we never did.
The only thing that sort of correlates with this attack is that before it started, we began rolling out some slightly more aggressive rate limits one by one. This was mostly because anytime any new "company" thinks they're going to catchup with Claude/OpenAI, they scrape us very aggressively (and they're not respectful about it). My guess is that the attackers behind this attack were already probing us (they were) and they thought the window of opportunity might be closing.