1. APIs have seen huge growth in usage, with over 25% of all internet traffic now consisting of API calls, largely driven by mobile apps and the growing IoT ecosystem.
2. Attackers have shifted focus to targeting APIs due to their simplicity and accessibility, exploiting common vulnerabilities like credential stuffing and application layer attacks against APIs developed with modern lightweight frameworks.
3. One campaign analyzed by Akamai showed attackers attempting 4 times as many stolen credentials through APIs compared to standard web logins, using over 4 times as many unique IP addresses per API-based campaign.
4. The rise of IoT devices has introduced new attack vectors, with credential abuse campaigns now exploiting vulnerable IoT devices like routers
Related topics: