Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - API Security - APIs Under Siege: Wallarm Report Reveals How AI Is Supercharging Modern Cyberattacks
API Security Artificial Intelligence Latest News News & Analysis Security Study & Research Threat Intelligence Threats and Vulnerabilities

APIs Under Siege: Wallarm Report Reveals How AI Is Supercharging Modern Cyberattacks

Kirsten DoyleBy Kirsten DoyleFebruary 18, 20266 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
API AI Wallarm Report
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

APIs made up 17% of 67,058 published vulnerabilities in 2025, a total of 11,053 API-related flaws. The overlap between APIs and AI is even more notable. More than a third (36%) of AI vulnerabilities (786 out of 2,185) were API-related. 

Of the 245 vulnerabilities identified in the U.S. Cybersecurity and Infrastructure Security Agency’s 2025 Known Exploited Vulnerabilities list, 43% (106) were API-related. Unsurprisingly, 36% of AI-related exploits also corresponded to API vulnerabilities. 

These were some of the findings of Wallarm’s API ThreatStats Report 2026, which draws on vulnerability and breach data from 2025. 

The report describes AI as a risk multiplier that has been leveraging existing weaknesses in APIs and accelerating their exploitation. As companies continue to increase their dependence on APIs for their digital services, business logic, and AI, attackers are following the same trend. 

It is clear that APIs are not peripheral components. They are the connective tissue of digital business, and increasingly, the primary vector of attack. 

Identity Failures Drive Breaches 

Perhaps the most troubling aspect of this report is the consistency with which breaches have originated from identity issues rather than sophisticated exploitation attacks. 

Sixty-five percent of the breaches that were assessed originated from authentication issues. This included weak tokens, scope issues, reusing credentials, and a lack of runtime enforcement. Attackers are not necessarily finding new zero-day vulnerabilities; they are exploiting publicly accessible endpoints and poorly managed access controls. 

AI platforms are vulnerable, too. The report showed that 15% of breaches involved AI vendors, the same rate as for enterprise software vendors. As AI is increasingly integrated into customer-facing applications and backend automation, its reliance on APIs makes it a compelling target. 

Abuse over bugs: The 2025 API ThreatStats Top 10 

The evolution of the API ThreatStats Top 10 mirrors a broader shift in adversaries’ strategy. Rather than focusing solely on traditional software bugs, they increasingly prioritize logic flaws and cross-site exploitation. 

The top categories for 2025 were: 

  1. Cross-Site Issues (up from #5 in 2024) 
  1. Injections (down from #1) 
  1. Broken Access Control (down from #2) 
  1. Insecure Resource Consumption (up from #7) 
  1. Authentication Flaws (down from #3) 
  1. SSRF (up from #10) 
  1. Memory Corruption/Overflows (up from #9) 
  1. API Leaks (down from #4) 
  1. Authorization Issues (down from #6) 
  1. Weak Secrets/Cryptography (no change) 

The appearance of cross-site problems in the number one spot indicates a trend in exploit chain attacks that rely on browser contexts, session manipulation, and token abuse. At the same time, injections and access control issues continue to pose a threat, indicating that basic API security is still being poorly managed. The technical characteristics of API vulnerabilities amplify the risk: 

  • 97% were exploitable via a single request 
  • 98% were classified as easy or trivial to exploit 
  • 99% were remotely exploitable 
  • 59% required no authentication 

In practice, this means attacks can scale quickly, take minimal effort, and often bypass the need for compromised credentials. 

The Rise of Model Context Protocol (MCP) 

One of the most notable developments highlighted in the report is the rapid emergence of Model Context Protocol (MCP). Designed to enable agentic AI systems to interact with external tools and services, MCP-related vulnerabilities surged in 2025. 

The report identified 315 MCP-related vulnerabilities, representing 14% of all AI vulnerabilities analyzed. Growth was described as explosive, with one high-profile breach involving exposed agentic APIs that enabled attackers to take over AI agents. 

As AI systems increasingly operate autonomously (retrieving data, triggering workflows, and interacting with third-party services), the APIs underpinning these capabilities become mission-critical security boundaries. Poorly secured MCP servers, exposed endpoints, or overprivileged agents can turn automation into an attack amplifier. 

High-profile Breaches Highlight the Risks 

Major incidents in 2025 also stressed the importance of APIs in real-world attacks. Qantas was affected by the leak of 6 million records due to inadequate authentication mechanisms, while SwissBorg was targeted in a $41 million heist involving stolen credentials and API misuse. 

In one of the Top 10 incidents, thousands of MCP servers were compromised due to a path-traversal vulnerability that allowed malefactors to access live production AI workflows. They didn’t employ any exotic AI-related attack methodologies, just good old API vulnerabilities such as weak authentication and insecure backend interactions.  

The problem was that these APIs were doing more than just serving data; they were executing actions on behalf of AI agents. 

Analysis of the industry showed that enterprise software and AI infrastructure were the most affected, each contributing 15% to the incidents. Cybersecurity companies accounted for 13% of the incidents, indicating that no industry is safe. 

Exposure, Not Novelty, Drives Risk 

One of the themes that runs through the report is that most API breaches are not the result of new vulnerabilities. Rather, they are the result of exposure: unknown endpoints, shadow APIs, weak tokens, too much privilege, and a lack of runtime controls. 

The report indicates that businesses need to change their mindset about API security. Prevention is no longer enough. Discovery, inventory, and runtime enforcement are essential. 

The recommendations of the report are based on three priorities: 

  • Secure identity controls: Protect token management, implement least privilege access, and verify authentication at runtime. 
  • Enforce at runtime: Identify and prevent abuse patterns in real time, not just during testing. 
  • Inventory all APIs: Uncover shadow and deprecated APIs before attackers do. 

For AI-driven systems, the stakes are even higher. Agentic architectures, MCP integrations, and external tool connections all depend on secure API boundaries. Without them, AI can magnify operational risk at machine speed. 

A Defining Year for API Security 

There’s one inescapable finding in the report: APIs are now the primary front in the war on cyber threats. As digital transformation continues to accelerate and the adoption of AI increases, APIs are the entry points to valuable data, business logic, and AI-driven decision-making. 

The reality facing security professionals is that bad actors are already taking advantage of this new normal on a massive scale. 

To see how the new reality of API vulnerability is changing the cyber threat landscape and what security professionals can do next, download the full report. 

Kirsten Doyle
Kirsten Doyle
Information Security Buzz News Editor

Kirsten Doyle has been in the technology journalism and editing space for nearly 24 years, during which time she has developed a great love for all aspects of technology, as well as words themselves. Her experience spans B2B tech, with a lot of focus on cybersecurity, cloud, enterprise, digital transformation, and data centre. Her specialties are in news, thought leadership, features, white papers, and PR writing, and she is an experienced editor for both print and online publications.

  • Kirsten Doyle
    SIG report: AI-generated code is linked to twice the security risk and rising technical debt
  • Kirsten Doyle
    Miasma worm spreads from Red Hat packages to Microsoft repositories
  • Kirsten Doyle
    Dutch police, NCSC take down major botnet
  • Kirsten Doyle
    Palo Alto warns of active exploitation of GlobalProtect authentication bypass flaw

The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

Share. Facebook Twitter LinkedIn Email Copy Link

Related Posts

UK Solicitor Investigated After Uploading Client Files to ChatGPT

February 27, 20263 Mins Read

AI Theater, Real Risk: What Moltbook Reveals About API Security

February 27, 20265 Mins Read

Zimperium Warns Mobile Apps Are the New API Battleground

September 22, 20256 Mins Read
ISB-Bora-Side-Bar

No se ha podido establecer conexión. Error 429

 
ISB-Bora-Side-Bar
Black ISB Logo

Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

X (Twitter) LinkedIn Facebook RSS

Working With Us

  • About Us
  • Advertise With Us
  • Contact Us

Write For Us

  • How To Contribute

The Pages

  • Privacy Policy
  • Cookie Policy
  • AI Policy
  • Terms & Conditions
  • Copyright Notice

Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

Type above and press Enter to search. Press Esc to cancel.

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}