Web applications and APIs sit at the center of modern digital services. They handle authentication, payments, search, content delivery, account management, and many of the workflows that developers build and maintain every day.
That also makes them persistent targets.
Each year, CDNetworks analyzes activity observed across our security platform to understand how threats involving web applications, APIs, bots, and digital services are changing.
This article translates five findings from the CDNetworks 2025 State of WAAP Report into practical considerations for developers, application security teams, platform engineers, and SREs.
Methodology note: The figures in this article reflect activity observed across the CDNetworks security platform during 2025. They describe activity within the scope of that platform telemetry and should not be interpreted as measurements of all global internet traffic.
TL;DR
- AI is industrializing automated attacks. AI-assisted tools are making attack campaigns more adaptive, scalable, and accessible.
- API abuse is becoming a primary path for business logic attacks. Technically valid requests can still produce malicious business outcomes.
- AI bot traffic is creating a new governance challenge. Teams need granular policies based on bot identity, purpose, access frequency, and content sensitivity.
- Multi-layer DDoS attacks are raising the bar for resilience. Campaigns can shift across network, transport, and application layers within the same attack.
- APAC is facing concentrated application-layer attack pressure. APAC businesses are under greater pressure from attacks targeting their business-critical digital services.
Let’s take a closer look at each trend.
1. AI is industrializing automated attacks.
Our latest research shows that AI is changing the economics of cyberattacks.
Large language models, agentic AI tools, browser automation frameworks, and proxy networks are reducing the cost, time, and expertise required to run sophisticated campaigns.
As a result, automated threats are moving beyond rigid scripts toward more adaptive, context-aware, and human-like attack patterns.
This makes AI-driven automation a persistent and expanding threat to digital businesses.
2. API abuse is becoming a primary path for business logic attacks.
APIs have become a primary route to business impact.
In 2025, the CDNetworks security platform blocked more than 15 billion malicious API requests per month on average.
Many attackers are now abusing legitimate functions such as login, registration, search, ordering, and payments, often through valid identities, sessions, and normal request paths.
Because the activity can appear technically valid, business logic attacks are especially difficult to distinguish from genuine customer behavior.
3. AI bot traffic is creating a new governance challenge.
AI bots are automated agents that crawl, retrieve, summarize, or act on online content for AI systems.
In 2025, the CDNetworks security platform observed approximately 1.64 million AI bot requests per day on average.
Data scraping accounted for 72.67% of the observed AI bot activity.
This volume shows that AI bots have become a meaningful part of enterprise internet traffic.
But not all AI bots are harmful. Some support AI search, user-requested retrieval, or model improvement.
Because similar technical behavior can serve very different purposes, simple allow-or-block decisions are often insufficient. Businesses need more granular governance based on bot identity, intent, context, access frequency, content sensitivity, and potential business impact.
4. Multi-layer DDoS attacks are raising the bar for resilience.
Our research shows that DDoS campaigns are becoming more dynamic, with attackers shifting between Layers 3, 4, and 7 within the same campaign and adapting tactics in real time.
A customer case from 2025 illustrates how this trend can play out in practice.
The organization experienced a sustained, multi-day attack that targeted both its network and application layers.
The campaign peaked at:
- 1.4 Tbps across Layers 3 and 4
- 770,000 requests per second at Layer 7
CDNetworks mitigated the attack without business disruption.
For business leaders, the implication is clear.
DDoS risk now includes prolonged, multi-layered campaigns that can change tactics over time and pressure several parts of the digital environment at once.
Maintaining availability under these conditions requires adaptive protection and expert mitigation across both network and application layers.
5. APAC is facing concentrated application-layer attack pressure.
APAC accounted for 67.45% of the Layer 7 DDoS activity observed on the CDNetworks security platform in 2025.
The region’s e-commerce, fintech, gaming, SaaS, mobile, entertainment, and digital content sectors depend on high-frequency paths such as login, search, checkout, verification, payments, content access, and API calls.
Those revenue-critical workflows also make APAC businesses attractive targets for disruption, fraud, and abuse.
What Teams Should Prioritize in 2026
Taken together, these trends show how attackers are combining legitimate identities, valid API traffic, automated tools, and business-critical workflows to create operational and security risks.
For development, security, and platform teams, seven priorities stand out:
- Protect revenue-critical API workflows, including login, checkout, payments, verification, and account recovery.
- Strengthen business continuity and API resilience in APAC markets, where application-layer attack pressure is particularly concentrated.
- Prepare for sudden spikes in automated traffic before they affect application availability, backend services, and downstream dependencies.
- Reduce exposure from compromised trusted identities, including valid accounts, sessions, API keys, and service credentials.
- Control the operational costs of AI-driven attacks, especially when automated requests trigger expensive application or infrastructure processes.
- Govern AI bot interactions based on business impact, considering bot identity, purpose, access frequency, and content sensitivity.
- Safeguard AI-enabled applications and agentic workflows with scoped permissions, controlled tool access, and stronger oversight of high-impact actions.
These priorities share a common goal: protecting critical digital services without creating unnecessary friction for legitimate users.
Final Thoughts
The emerging security challenge is not limited to blocking requests that look obviously malicious. Teams also need to identify legitimate functionality being used with malicious intent.
The CDNetworks 2025 State of WAAP Report provides the supporting research and additional analysis behind these trends.
If your team is assessing these risks and needs support from a specialist security provider, visit our website to learn how we help protect web applications, APIs, and digital services.
Disclosure: This article is based on security research and platform data from CDNetworks.

Top comments (1)
Good article!