惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
V
V2EX
博客园 - 三生石上(FineUI控件)
Hugging Face - Blog
Hugging Face - Blog
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
罗磊的独立博客
博客园_首页
量子位
雷峰网
雷峰网
GbyAI
GbyAI
小众软件
小众软件
酷 壳 – CoolShell
酷 壳 – CoolShell
D
DataBreaches.Net
H
Hackread – Cybersecurity News, Data Breaches, AI and More
The Cloudflare Blog
IT之家
IT之家
WordPress大学
WordPress大学
人人都是产品经理
人人都是产品经理
Apple Machine Learning Research
Apple Machine Learning Research
P
Proofpoint News Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
博客园 - 聂微东

www.infosecurity-magazine.com

Just Three Ransomware Gangs Accounted for 40% of Attacks Last Month Google Chrome Rolls Out Protection Against Infostealers Targeting Session Cookies STX RAT Targets Finance Sector With Advanced Stealth Tactics Bitcoin Depot Reports $3.6m Crypto Theft After System Breach Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings Middle East Hack-for-Hire Operation Traced to South Asian Cyber Espionage Group Governance Gaps Emerge as AI Agents Drive 76% Increase in NHIs Google Warns of New Threat Group Targeting BPOs and Helpdesks Google API Keys Quietly Gain Access to Gemini on Android Devices Critical Vulnerability in Ninja Forms Exposes WordPress Sites Anthropic Launches Project Glasswing to Use AI to Find and Fix Critical Software Vulnerabilities US Thwarts DNS Hijacking Network Controlled by Russian APT28 Hackers Claude Discovers Apache ActiveMQ Bug Hidden for 13 Years Iran‑Backed Threat Actors Hit US CNI Providers via Internet‑Facing OT Assets Russian APT28 Hackers Hijack Routers to Steal Credentials, UK Security Agency Warns GPU Rowhammer Attack Enables Privilege Escalation and Full System Compromise GrafanaGhost Exploit Bypasses AI Guardrails for Silent Data Exfiltration Over $17bn Lost to Cyber Fraud in the Last Year, Warns FBI Storm-1175 Exploits Flaws in High-Velocity Medusa Attacks Fortinet Releases Emergency Patch After FortiClient EMS Bug Is Exploited New Phishing Platform Used in Credential Theft Campaigns Against C-Suite Execs New 'Storm' Infostealer Remotely Decrypts Stolen Credentials NCSC Issues Security Alert Over Hackers Targeting WhatsApp and Signal Accounts Apple Expands iOS 18 Security Updates Amid DarkSword Threat Researchers Observe Sub-One-Hour Ransomware Attacks GitHub Used as Covert Channel in Multi-Stage Malware Campaign Most CNI Firms Face Up to £5m in Downtime from OT Attacks Google Introduces Android Dev Verification Amid Openness Debate New Venom Stealer MaaS Platform Automates Continuous Data Theft Chinese Hackers Target European Governments in Espionage Campaigns
Average Number of Daily API Attacks Up 113% Annually
Phil Muncaster · 2026-03-17 · via www.infosecurity-magazine.com

Photo of Phil Muncaster

APIs now represent the “dominant” attack surface for global organizations, with 87% registering a related security incident last year, according to Akamai.

Now in its 12th year, the security vendor’s latest State of the Internet (SOTI) report was produced from analysis of its own data.

The average number of API attacks per organization in 2025 was 258, up 113% from 121 in 2024, it found. Some 61% of API attacks last year involved unauthorized workflows and abnormal activity, up from 30% in 2024. Akamai said this indicates a shift from traditional web-based to behavior-based attacks.

Of the OWASP Top API Security Risks, security misconfigurations (40%), broken object property level authorization (35%) and broken authentication (19%) were the most frequently exploited vulnerabilities.

Akamai also warned that the growth of agentic AI is amplifying the risk of sensitive data exposure. An average of 3000 APIs per customer contained sensitive data last year, with 12% showing security weaknesses and a quarter (24%) of those issues related to sensitive data exposure.

“Since AI depends on APIs for integration and data exchange, the volume of sensitive information traversing these interfaces has increased exponentially,” the report noted. “In today’s AI-driven environment, securing AI truly starts with securing APIs.”

Read more on API security: 99% of Organizations Report API-Related Security Issues.

More generally, AI is helping threat actors to automate and accelerate attacks, as well as creating new vulnerabilities (eg vibe coding) that attackers can exploit.

“Attackers increasingly focus on degrading performance, driving up infrastructure costs, and exploiting AI-driven automation at scale, rather than seeking headline-grabbing campaigns,” said Patrick Sullivan, CTO of security strategy at Akamai.

“Automation and AI are making these sophisticated campaigns cheap, repeatable, and fast. And as enterprises invest heavily in AI transformation, attackers are targeting the APIs that power that transformation.”

The Emergence of Blended Attacks

Akamai also pointed to a growth in the number of coordinated attacks that blend API abuse, web application attacks and Layer 7 DDoS activity. Web app attacks surged in volume by 73% between 2023 and 2025, while Layer 7 DDoS attacks increased 104% over the past three years.

The latter are being fuelled by easy access to DDoS-for-hire services/botnets and AI-enabled attack scripts that streamline targeting of APIs and web applications, Akamai claimed.

The vendor had the following recommendations for CISOs:

  • Gain visibility into the environment as a prerequisite for tackling DDoS, app and API attacks
  • Deploy an “integrated platform” of security controls that can be adjusted according to the risk tolerance of leadership
  • Invest in people and processes via training and validation exercises
  • Reference industry best practices when talking to the board or the infosec team – eg use OWASP to help prioritize training, deploy security controls, drive red and blue team pen testing, and analyze vulnerabilities
  • Use detailed industry reports to validate that current security controls are fit for purpose
  • Coordinate protection across DDoS mitigation, WAF, API security, bot and abuse prevention, and identity-aware controls – don’t treat these as isolated areas