惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

罗磊的独立博客
The GitHub Blog
The GitHub Blog
Hugging Face - Blog
Hugging Face - Blog
博客园 - 聂微东
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
小众软件
小众软件
博客园_首页
G
Google Developers Blog
Apple Machine Learning Research
Apple Machine Learning Research
MyScale Blog
MyScale Blog
Engineering at Meta
Engineering at Meta
Jina AI
Jina AI
酷 壳 – CoolShell
酷 壳 – CoolShell
人人都是产品经理
人人都是产品经理
B
Blog RSS Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
D
Docker
B
Blog
雷峰网
雷峰网
WordPress大学
WordPress大学
Stack Overflow Blog
Stack Overflow Blog
宝玉的分享
宝玉的分享

Help Net Security

Police arrest 10 suspected members of Black Axe cybercrime gang ShinyHunters claims it stole 1.4 million records from Udemy Sevii unveils Cyber Swarm Defense Mode to stop AI-driven attacks at scale Alleged Chinese hacker extradited to US over cyberattacks targeting COVID-19 research Cequence Agent Personas bring granular control and governance to enterprise AI agents NowSecure MARI gives enterprises evidence-based visibility into third-party mobile app risk The metrics killing your SOC, and what to use instead US state privacy fines reached $3.425 billion in 2025 Canada’s first SMS blaster case leads to three arrests Linux storage management tool Stratis 3.9.0 adds online encryption and cache-less pool startup TLS Connect gives SMBs a right-sized automated tool to manage TLS certificates Aptori expands its platform with autonomous offensive testing to reduce security bottlenecks Your IAM was built for humans, AI agents don’t care The AI criminal mastermind is already hiring on gig platforms 25 open-source cybersecurity tools that don’t care about your budget Product showcase: LuLu reveals unauthorized outbound connections from Mac apps Week in review: Claude Mythos finds 271 Firefox flaws, Vercel breach Users advised to drop passwords and make room for passkeys - Help Net Security Indirect prompt injection is taking hold in the wild - Help Net Security Compromised everyday devices power Chinese cyber espionage operations - Help Net Security New Cisco firewall malware can only be killed by pulling the plug - Help Net Security Meta is overhauling how you sign in, manage settings, and protect your accounts - Help Net Security Ubuntu 26.04 LTS delivers memory-safe system tools and live patching for Arm servers - Help Net Security OpenAI’s GPT-5.5 is out with expanded cybersecurity safeguards - Help Net Security AI is speeding up nation-state cyber programs - Help Net Security A study of 1,000 Android apps finds a privacy policy logging gap - Help Net Security IT spending to hit $6.31 trillion record, thanks to AI - Help Net Security Where AI in CI/CD is working for engineering teams - Help Net Security With AI's help, North Korean hackers stumbled into a near-undetectable attack - Help Net Security Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security
Bad bots make up 40% of internet traffic
Anamarija Po · 2026-04-30 · via Help Net Security

The normalization of AI and automation within internet infrastructure is changing how organizations interpret traffic. Activity that once appeared anomalous is now treated as expected behavior. AI agents have emerged as a third category of automated traffic alongside good and bad bots, according to the Thales 2026 Bad Bot Report: Bad Bots in the Agentic Age.

The distinction between legitimate and malicious automation is difficult to define because both operate through similar channels, workflows, and infrastructure.

AI-driven bot traffic

Bad bot vs good bot vs human traffic in 2025 (Source: Thales)

Bot traffic dominates the internet

Human traffic continues to decline as a share of overall activity. Automated traffic accounted for 53% of all observed internet traffic in 2025, with bad bots making up 40% and benign automation accounting for 13%.

General automation remains the most common attack type, accounting for 29% of activity. This includes brute-force attacks, vulnerability scanning, credential testing, and large-scale data scraping.

Business logic abuse and API violations also represent a significant share of attacks. These methods rely on manipulating legitimate application workflows or exploiting weaknesses in API design and authorization.

AI is increasing the effectiveness of these attacks. Bots now mutate fingerprints, adjust interaction timing, and adapt to mitigation controls. This enables persistent probing of applications until a viable path is identified. High-volume, low-complexity attacks create continuous background pressure, while more advanced bots target specific workflows.

“AI is transforming automation from something organizations try to block into something they must also manage,” said Tim Chang, Global VP and GM, Application Security at Thales. “The challenge is no longer identifying bots. It’s understanding what the bot, agent, or automation is doing, whether it aligns with business intent, and how it interacts with critical systems.”

The United States remains the most targeted country, accounting for 59% of bot attacks, followed by Australia, United Kingdom, and France.

AI-driven traffic blurs detection boundaries

AI-driven bot activity increased more than tenfold (12.5×) in 2025, with daily blocked requests rising from 2 million to 25 million.

AI agents retrieve data and perform tasks on behalf of users, operating through browsers, search platforms, and enterprise tools. Their behavior aligns with normal application usage, which makes them difficult to distinguish from legitimate traffic.

Current visibility is limited to detectable or declared AI clients, leaving a large portion of AI-driven automation unverified. This creates a gap between observed activity and the full scale of AI-enabled risk.

Attackers are also deploying self-hosted or modified LLMs that do not identify themselves as AI agents. These systems can be fine-tuned for malicious use, further reducing visibility.

A portion of AI-driven traffic already overlaps with malicious patterns. More than 10% of AI fetcher sessions and nearly 9% of AI crawler sessions trigger bad bot detection rules. Many of these sessions are blocked through customer-defined policies, reflecting decisions about which AI tools are allowed to access applications.

Access controls depend on application sensitivity. Public content may remain accessible, while authentication, transactional, and data-intensive endpoints are more tightly restricted.

Organizations move to control and monetize AI access

The rise of AI agents is driving new operational models, including verification and monetization of AI-generated traffic.

Verified AI bots use cryptographically signed headers, allowing organizations to authenticate and measure AI-driven access. This enables differentiation between approved AI agents and unverified automation and supports control over how these agents interact with applications and APIs.

Growing adoption is expected to drive the implementation of enforceable access models. AI traffic may be governed through policy, rate limiting, or commercial agreements, turning it into a managed and potentially billable channel.

APIs remain the primary attack surface

APIs continue to be a primary target, with 27% of bot attacks directed at API endpoints. As organizations rely more on APIs to power digital services, they have become a critical point of exposure.

The most common API threats include data leakage, business logic abuse, and remote code execution or file inclusion attacks. These attacks often rely on valid, well-formed requests executed at scale.

AI-driven tools are accelerating API interactions, increasing request volume and complexity. This trend is raising concerns among developers and security teams.

To evade detection, bots frequently disguise themselves as legitimate browsers. Google Chrome remains the most commonly impersonated browser, followed by Android Browser. This shows how mobile traffic is used to mask automated activity.

Financial services remains the top target

Financial services was the most targeted industry in 2025, accounting for 24% of all bot attacks. Bots increasingly interact directly with APIs, identity systems, and workflows that support customer transactions and digital banking operations.

While financial services leads in overall attack volume, telecoms, society (non-profit organizations), computing and IT, travel, and business sectors show the highest proportion of bad bot traffic. This reflects the extent to which automated threats are embedded across digital environments.

Webinar: The True State of Security 2026