-

APIs in peril: Wallarm's latest report exposes uptick in API attacks and highlights security predictions for 2024

Annual report analyzed 1.2 billion attacks, more than 22,000 vulnerabilities and over 146 bug bounty reports to predict 2024 API security trends

SAN FRANCISCO--(BUSINESS WIRE)--Wallarm, the leading end-to-end API and app security company, today announced the release of its Annual API ThreatStats™2024 Report. The annual report discloses the year's progress in identifying, understanding and combating API security threats, from the top exploited API vulnerabilities to emerging risks beyond the OWASP API Top 10. Wallarm executives will present top findings from the report during a webinar on Jan. 24 at 10 a.m. PT/1 p.m. ET.

Wallarm, which was recently named a leader in the GigaOm Radar report for API Security, exposed a rising trend in API security threats in the report, noting a noticeable increase in both the number and severity of API attacks and vulnerabilities. There was a 30% increase in API-related Common Vulnerabilities and Exposures (CVEs) and security bulletins in 2023 compared to 2022. Additionally, malicious requests involving APIs that Wallarm blocked rose significantly from 54% in 2022 to 70% in 2023.

These attacks aren’t going unnoticed by the public. Half of the top 20 most mentioned vulnerabilities in Google Searches are API-related, indicating growing public awareness and concern about API security.

“The growth in malicious API requests and rising public awareness of APIs in 2023 prove that API security is growing increasingly crucial for business leaders and cybersecurity professionals to prioritize in their digital security strategies,” said Ivan Novikov, CEO of Wallarm, which was recognized as one of the CyberTech 100 companies in 2023. “The key trends unearthed and actionable insights provided are a starting point for companies to strengthen their API security programs in 2024. Enterprises must act now, and Wallarm will continue to be at the forefront of the effort to mitigate these attacks.”

Other significant findings include:

Injections and API leaks dominate top API security risks

Injections, which involve malicious data or code being inserted into an API that leads to unauthorized access and data breaches, nabbed the first spot on the “Top 10 API Security Risks for 2023” list.

Although a newer entry on the list, API leaks ranked fourth due to their potential for unrestrained disclosure of sensitive data, often through negligent methods. API leaks are often overlooked, as evidenced by their absence from the OWASP Top 10 threat list.

API security bugs rule the bounty game with 62% of rewards

In 2023, most bug bounties — ethical hackers that test and challenge major companies’ security systems — were for API security: 62% of all bounty payments. Notably, API-related bounties are higher in value compared to other categories. The highest payout for an API bug was $15,000, three times larger than the highest non-API payout of $5,000.

Social media platform Snapchat had the highest bug bounty payout in 2023, signifying more major players see the importance of getting ahead of critical security flaws.

API security predictions for 2024 that demand immediate action

The report highlights several predictions and notes there’ll be an intensified focus on emerging API data leaks as a significant risk in 2024, emphasizing the prevention of sensitive information breaches that include API keys and JWT tokens.

There will also be a shift towards adopting novel metrics for vulnerability triaging and an increased focus on addressing broken access control and authorization (BOLA) issues in API security strategies.

To learn further insights from the Annual API ThreatStats™2024 Report, please register for the webinar.

About Wallarm

Wallarm, the integrated App and API Security company, provides robust protection for APIs, web applications, microservices, and serverless workloads running in cloud-native, hybrid cloud and on-premise environments. Wallarm is the preferred choice of hundreds of Security and DevOps teams for comprehensive discovery of web apps and API endpoints, protection against emerging threats throughout their API portfolio, and automated incident response to enhance risk management. Our platform supports modern tech stacks, offering dozens of deployment options in cloud and Kubernetes-based environments, and also provides a full cloud solution. Wallarm is headquartered in San Francisco, California, and is backed by Toba Capital, Y Сombinator, Partech, and other investors.

Contacts

Wallarm


Release Versions

Contacts

More News From Wallarm

Wallarm Releases World's First API Honeypot Report Highlighting API Attack Trends

SAN FRANCISCO--(BUSINESS WIRE)--Wallarm's API Security research team releases the first API honeypot report....

Wallarm Named to IT Harvest’s Cyber150 List of Top Cybersecurity Companies

SAN FRANCISCO--(BUSINESS WIRE)--Wallarm, a global leader in API security, is proud to announce its inclusion in IT Harvest's Cyber150 list, which highlights the top 150 cybersecurity companies driving innovation and excellence in the field. Curated by Richard Stiennon, noted industry analyst and founder of IT Harvest, the Cyber150 list recognizes organizations that have made a significant impact on the cybersecurity landscape. “We are excited to be included in the Cyber150 list. Protecting crit...

Wallarm Launches API Attack Surface Management (AASM)

SAN FRANCISCO--(BUSINESS WIRE)--Wallarm, a leader in API and application security, is proud to announce its latest innovation: API Attack Surface Management (AASM). This groundbreaking agentless technology revolutionizes how organizations identify, analyze, and secure their entire API attack surface. Designed for effortless deployment, Wallarm AASM empowers organizations to discover all of their externally-facing APIs and web applications, identify where they are missing critical web applicatio...
Back to Newsroom