-

Wallarm Releases World's First API Honeypot Report Highlighting API Attack Trends

SAN FRANCISCO--(BUSINESS WIRE)--Wallarm, the leader in real-time blocking of API attacks, today unveiled a comprehensive security research report based on data collected from the world's first globally distributed API honeypot network. The findings reveal critical insights into the growing threat landscape for APIs, showcasing their increasing vulnerability to rapid discovery and exploitation.

APIs have surpassed web applications as the primary targets of attackers, underscoring the urgency for businesses to implement robust API security measures. Organizations are plagued by uncontrolled API sprawl and lack of API governance, leading to significant breaches from exposed APIs. Wallarm’s study highlights several alarming trends that demand immediate attention from organizations deploying APIs.

Key Findings from the Report:

  • APIs Are the Prime Target: APIs now attract more attacks than traditional web applications.
  • Rapid Discovery: Newly deployed APIs are discovered by attackers in as little as 29 seconds.
  • Immediate Exploitation: Unprotected APIs are exploited within one minute of discovery.
  • High Velocity Data Theft: Attackers using batched API requests can exfiltrate millions of user records in seconds.
  • Targeting Well-Known Products: Recognizable and widely used API products face heightened targeting by attackers.

Wallarm’s globally distributed honeypot, spanning 14 locations, captures data from diverse geographies and providers, revealing critical trends. The honeypot provides targeted responses to API requests across multiple protocols, including REST, XML-RPC, GraphQL, and others. Over half (54%) of observed request types were API-specific, demonstrating that APIs are the preferred vector for attackers. Among these, 40% of requests targeted known vulnerabilities (CVEs). While port 80 emerged as the most commonly discovered entry point, interactions were distributed across many ports, demonstrating that protecting only common ports is insufficient.

“This report sheds light on a rapidly evolving attack surface and represents a groundbreaking effort in API security research,” said Ivan Novikov, CEO and founder at Wallarm. “APIs are the foundation of modern applications, but their widespread deployment and inadequate protection make them an attractive target for attackers. We hope this research helps organizations invest in strong protection for their APIs.”

Wallarm’s full report offers actionable insights and recommendations to safeguard APIs. To access the full research report and learn more about securing your APIs, visit http://www.wallarm.com/resources/api-honeypot-report.

About Wallarm:

Wallarm’s API security platform is the fastest, easiest, and most effective way to stop API security attacks. Customers choose Wallarm because it delivers a complete inventory of your APIs, patented AI/ML API abuse detection, real-time blocking on day zero, and an API SOC-as-a-service. Wallarm is headquartered in San Francisco, California, and is backed by Toba Capital, Y Сombinator, Partech, and other investors.

Contacts

Media Contact:
Michelle Yusupov
Hi-Touch PR
443-857-9468
yusupov@hi-touchpr.com

Wallarm


Release Summary
Wallarm's API Security research team releases the first API honeypot report.
Release Versions

Contacts

Media Contact:
Michelle Yusupov
Hi-Touch PR
443-857-9468
yusupov@hi-touchpr.com

More News From Wallarm

Wallarm Named to IT Harvest’s Cyber150 List of Top Cybersecurity Companies

SAN FRANCISCO--(BUSINESS WIRE)--Wallarm, a global leader in API security, is proud to announce its inclusion in IT Harvest's Cyber150 list, which highlights the top 150 cybersecurity companies driving innovation and excellence in the field. Curated by Richard Stiennon, noted industry analyst and founder of IT Harvest, the Cyber150 list recognizes organizations that have made a significant impact on the cybersecurity landscape. “We are excited to be included in the Cyber150 list. Protecting crit...

Wallarm Launches API Attack Surface Management (AASM)

SAN FRANCISCO--(BUSINESS WIRE)--Wallarm, a leader in API and application security, is proud to announce its latest innovation: API Attack Surface Management (AASM). This groundbreaking agentless technology revolutionizes how organizations identify, analyze, and secure their entire API attack surface. Designed for effortless deployment, Wallarm AASM empowers organizations to discover all of their externally-facing APIs and web applications, identify where they are missing critical web applicatio...

AI, Machine Learning Are the New Battleground for API Exploits, According to New Wallarm Report

SAN FRANCISCO--(BUSINESS WIRE)--Wallarm, the leading end-to-end API and app security company, today announced the release of its Q1 API ThreatStats™2024 Report. The quarterly report reveals a significant uptick in sophisticated cyber threats targeting APIs of AI infrastructure products including NVIDIA’s Triton Inference Server, ZenML and Hail. It also underscores notable API breaches among the world’s largest companies and the growing importance of advanced, proactive cybersecurity measures to...
Back to Newsroom