<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Alvin</title>
    <description>The latest articles on DEV Community by Alvin (@alviny).</description>
    <link>https://dev.to/alviny</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4011713%2Fe1bd01b2-7546-4914-8bc8-6ee352143221.png</url>
      <title>DEV Community: Alvin</title>
      <link>https://dev.to/alviny</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/alviny"/>
    <language>en</language>
    <item>
      <title>Cybersecurity in 2026: The Trends Reshaping Modern Applications</title>
      <dc:creator>Alvin</dc:creator>
      <pubDate>Fri, 24 Jul 2026 07:13:26 +0000</pubDate>
      <link>https://dev.to/alviny/building-for-2026-the-cybersecurity-trends-reshaping-modern-applications-27jb</link>
      <guid>https://dev.to/alviny/building-for-2026-the-cybersecurity-trends-reshaping-modern-applications-27jb</guid>
      <description>&lt;p&gt;Cybersecurity in 2026 feels different.&lt;/p&gt;

&lt;p&gt;It’s not simply because attacks are becoming more sophisticated or more frequent. What’s changing is where security problems begin. They’re no longer confined to isolated vulnerabilities or network boundaries—they’re increasingly emerging from the applications we build, the APIs we expose, the identities we manage, and the automated systems we rely on every day.&lt;/p&gt;

&lt;p&gt;Modern applications have become highly distributed. AI is accelerating development cycles, APIs are powering nearly every digital experience, and machine identities are beginning to outnumber human users. At the same time, attackers are becoming faster, more automated, and increasingly capable of blending malicious behaviors into legitimate traffic patterns.&lt;/p&gt;

&lt;p&gt;According to &lt;a href="https://www.statista.com/forecasts/1280009/cost-cybercrime-worldwide/" rel="noopener noreferrer"&gt;Statista&lt;/a&gt;, cybercrime cost businesses approximately $10.5 trillion in 2025 and is projected to reach $15.63 trillion by 2029. Ignoring these changes is becoming significantly more expensive than preparing for them.&lt;/p&gt;

&lt;p&gt;Looking ahead to 2026, five cybersecurity trends stand out—not because they’re entirely new, but because they’re fundamentally changing how modern applications need to think about security.&lt;/p&gt;




&lt;h2&gt;
  
  
  AI Is Industrializing Cyberattacks
&lt;/h2&gt;

&lt;p&gt;AI has become one of the most significant accelerators of cyberattacks. What makes AI particularly interesting isn’t simply its ability to automate existing attack techniques—it’s dramatically changing attacker economics by reducing both the cost and expertise required to launch sophisticated campaigns at scale.&lt;/p&gt;

&lt;p&gt;The numbers are beginning to reflect this shift:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf" rel="noopener noreferrer"&gt;FBI IC3&lt;/a&gt; recorded more than 22,000 AI-related complaints and over $893 million in adjusted losses during 2025.&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://reports.weforum.org/docs/WEF_Global_Cybersecurity_Outlook_2026.pdf" rel="noopener noreferrer"&gt;The World Economic Forum&lt;/a&gt; reported that 87% of respondents identified AI-related vulnerabilities as the fastest-growing cyber risk throughout 2025.&lt;/li&gt;
&lt;li&gt;
&lt;a href="https://qbeeurope.com/news-and-events/press-releases/ransomware-attacks-to-rise-by-40-by-2026-qbe-warns/" rel="noopener noreferrer"&gt;Deepfakes&lt;/a&gt; contributed to nearly 10% of cyberattacks during 2024, with fraud losses ranging from $250,000 to $20 million per incident.&lt;/li&gt;
&lt;/ul&gt;

&lt;h3&gt;
  
  
  Technical Insight
&lt;/h3&gt;

&lt;p&gt;We’re moving beyond scripted automation into adaptive attack operations. Large language models, agentic AI systems, browser automation frameworks, and proxy networks are enabling attackers to generate increasingly convincing phishing campaigns, automate vulnerability discovery, and launch context-aware social engineering attacks at unprecedented scale.&lt;/p&gt;

&lt;p&gt;What’s changing isn’t simply attack volume—it’s attack velocity. AI is significantly shortening the time between discovering vulnerabilities and exploiting them while lowering the technical barriers required to execute sophisticated attacks.&lt;/p&gt;

&lt;h3&gt;
  
  
  Security Implications
&lt;/h3&gt;

&lt;p&gt;Modern applications will increasingly need to prioritize:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Behavioral-based threat detection over static rule matching.&lt;/li&gt;
&lt;li&gt;AI-assisted anomaly analysis and automated response capabilities.&lt;/li&gt;
&lt;li&gt;Continuous authentication mechanisms across user and machine identities.&lt;/li&gt;
&lt;li&gt;Adaptive security models capable of responding to evolving attack behaviors.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The question is no longer whether attackers will leverage AI—it’s how quickly defenders can adapt to AI-driven threats.&lt;/p&gt;




&lt;h2&gt;
  
  
  API Security Is Becoming Application Security
&lt;/h2&gt;

&lt;p&gt;Modern applications are increasingly API-first, which also means they’re increasingly API-dependent.&lt;/p&gt;

&lt;p&gt;Rapid AI adoption, microservices architectures, and multi-cloud deployments are continuously expanding the application attack surface. APIs that once existed only between internal services are increasingly exposed across partners, platforms, and AI integrations.&lt;/p&gt;

&lt;p&gt;According to &lt;a href="https://cybersecasia.net/tips/apac-cybersecurity-outlook-2026-quantum-risks-api-gaps-ai-sovereignty-and-cyber-resilience" rel="noopener noreferrer"&gt;CybersecAsia&lt;/a&gt;, the speed of AI deployment is already exceeding the pace of API security adoption, creating growing concerns around shadow and unmanaged APIs.&lt;/p&gt;

&lt;p&gt;According to &lt;a href="https://www.cdnetworks.com/reports/state-of-waap-2025/" rel="noopener noreferrer"&gt;API security observations published by CDNetworks&lt;/a&gt; throughout 2025, authentication bypass accounted for 18.8% of observed API attacks, while privilege escalation represented 12.5% of attack patterns. Low-frequency API attacks persisted for an average of 21.7 days, highlighting how difficult these attacks can be to detect using traditional security controls.&lt;/p&gt;

&lt;h3&gt;
  
  
  Technical Insight
&lt;/h3&gt;

&lt;p&gt;What’s changing about API attacks is their behavior. Attackers aren’t necessarily generating massive traffic spikes or exploiting well-known vulnerabilities. Increasingly, they’re targeting authorization logic, session management mechanisms, and business workflows themselves.&lt;/p&gt;

&lt;p&gt;Low-frequency attacks are particularly challenging because they often resemble legitimate user behaviors, allowing them to remain undetected for extended periods of time.&lt;/p&gt;

&lt;p&gt;This is one of the reasons &lt;a href="https://www.cdnetworks.com/products/cloud-security/" rel="noopener noreferrer"&gt;Web Application and API Protection (WAAP)&lt;/a&gt; is becoming increasingly strategic in 2026. Traditional WAF capabilities alone are no longer sufficient for protecting modern applications that depend heavily on APIs, automation, and distributed services.&lt;/p&gt;

&lt;h3&gt;
  
  
  Security Implications
&lt;/h3&gt;

&lt;p&gt;API security is gradually becoming application security. Building secure applications increasingly means understanding:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Who is accessing an API.&lt;/li&gt;
&lt;li&gt;Why they’re accessing it.&lt;/li&gt;
&lt;li&gt;Whether their behavior aligns with expected business logic.&lt;/li&gt;
&lt;li&gt;How APIs interact across distributed services and machine identities.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Continuous API discovery, behavioral baselining, and context-aware authorization will become increasingly important as API ecosystems continue expanding.&lt;/p&gt;




&lt;h2&gt;
  
  
  Availability Has Become an Architectural Concern
&lt;/h2&gt;

&lt;p&gt;We often discuss cybersecurity through the lens of confidentiality and data protection. Increasingly, however, availability deserves equal attention.&lt;/p&gt;

&lt;p&gt;Modern DDoS attacks aren’t necessarily becoming larger—they’re becoming more persistent.&lt;/p&gt;

&lt;p&gt;According to &lt;a href="https://www.cdnetworks.com/reports/state-of-waap-2025/" rel="noopener noreferrer"&gt;technical traffic observations published by CDNetworks&lt;/a&gt;, more than 227.37 million network-layer DDoS attack requests were mitigated throughout 2025, with attack volumes remaining elevated for much of the year. CDNetworks also reported that 86% of terabit-scale DDoS incidents observed during 2024 lasted longer than ten minutes, highlighting the growing prevalence of sustained, high-capacity attacks.&lt;/p&gt;

&lt;p&gt;Application-layer attacks continue presenting significant challenges as well. During 2025, 67.45% of Layer 7 DDoS attacks observed by CDNetworks were concentrated within the APAC region, reinforcing the importance of regional traffic visibility and application-layer protections.&lt;/p&gt;

&lt;p&gt;At the same time, CDNetworks observed that 74% of bot traffic throughout 2025 originated from malicious bots, underscoring the growing need for adaptive bot management capabilities.&lt;/p&gt;

&lt;h3&gt;
  
  
  Technical Insight
&lt;/h3&gt;

&lt;p&gt;What’s interesting here isn’t simply attack volume—it’s what the data suggests about attacker behavior. We’re increasingly seeing attackers optimize for sustained resource exhaustion rather than short-lived traffic bursts.&lt;/p&gt;

&lt;p&gt;Modern attacks frequently combine automated bot traffic, application-layer abuse, and prolonged attack durations to maximize operational impact. Availability challenges are gradually moving beyond networking concerns and becoming application-level challenges.&lt;/p&gt;

&lt;h3&gt;
  
  
  Why This Matters
&lt;/h3&gt;

&lt;ul&gt;
&lt;li&gt;Building resilient applications in 2026 increasingly means assuming malicious traffic will coexist alongside legitimate users from day one.&lt;/li&gt;
&lt;li&gt;Engineering teams should increasingly consider:&lt;/li&gt;
&lt;li&gt;Multi-layer DDoS mitigation strategies.&lt;/li&gt;
&lt;li&gt;Regional traffic visibility across globally distributed infrastructures.&lt;/li&gt;
&lt;li&gt;Adaptive bot management capabilities.&lt;/li&gt;
&lt;li&gt;Edge-based traffic filtering mechanisms.&lt;/li&gt;
&lt;li&gt;Application-layer protections designed for modern workloads.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Availability is becoming an architectural concern rather than simply an operational one.&lt;/p&gt;




&lt;h2&gt;
  
  
  Content Is Becoming a Security Asset
&lt;/h2&gt;

&lt;p&gt;AI crawlers represent one of the more interesting developments emerging across modern applications.&lt;/p&gt;

&lt;p&gt;Unlike traditional malicious bots, AI crawlers exist within a much larger gray area. Some provide legitimate value through indexing and retrieval capabilities, while others create significant concerns around content ownership, licensing, attribution, and proprietary data reuse.&lt;/p&gt;

&lt;p&gt;According to traffic intelligence published by CDNetworks throughout 2025, AI bot activity accounted for approximately 0.42% of total observed internet traffic, translating to roughly 1.64 million requests per day. &lt;br&gt;
More significantly, 72.67% of observed AI bot activity was associated with content retrieval and data scraping operations.&lt;/p&gt;

&lt;p&gt;CDNetworks also observed that OTT platforms accounted for 24% of application-layer DDoS attacks during 2025, followed by Broadcasting and Television at 23% and News and Publishing at 9%. Additionally, CDNetworks helped a licensed video and music content platform mitigate more than 10 million malicious crawler requests per day throughout 2025, highlighting how AI-driven scraping activities can directly affect copyrighted media assets.&lt;/p&gt;

&lt;h3&gt;
  
  
  Technical Insight
&lt;/h3&gt;

&lt;p&gt;Applications can no longer assume that every visitor is either a human user or a malicious bot. Increasingly, they’ll need to distinguish between search crawlers, AI assistants, retrieval systems, legitimate automation, and malicious scraping activities.&lt;/p&gt;

&lt;p&gt;The engineering challenge is no longer simply blocking malicious traffic—it’s making intelligent decisions about automated access.&lt;/p&gt;

&lt;h3&gt;
  
  
  Security Implications
&lt;/h3&gt;

&lt;p&gt;Content protection is gradually becoming part of modern application security strategies.&lt;/p&gt;

&lt;p&gt;Engineering teams should increasingly evaluate:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Bot identity and access intent.&lt;/li&gt;
&lt;li&gt;Content sensitivity and business impact.&lt;/li&gt;
&lt;li&gt;Usage patterns across automated traffic.&lt;/li&gt;
&lt;li&gt;Granular access policies for AI crawlers and legitimate automation.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Modern applications will need to move beyond simple allow-or-block policies toward more intelligent approaches to automated access governance.&lt;/p&gt;




&lt;h2&gt;
  
  
  Identity Is Replacing the Traditional Perimeter
&lt;/h2&gt;

&lt;p&gt;Perhaps the most significant shift happening across cybersecurity is the growing importance of identity security.&lt;/p&gt;

&lt;p&gt;Traditional network perimeters are becoming increasingly difficult to define. Modern applications operate across cloud environments, remote workforces, APIs, and machine identities that extend far beyond conventional boundaries.&lt;/p&gt;

&lt;p&gt;Identity is gradually replacing the perimeter itself.&lt;/p&gt;

&lt;p&gt;According to &lt;a href="https://www.verizon.com/business/resources/reports/dbir" rel="noopener noreferrer"&gt;Verizon’s 2025 findings&lt;/a&gt;, credential abuse accounted for approximately 22% of initial access vectors throughout the year. Meanwhile, &lt;a href="https://docs.apwg.org/reports/apwg_trends_report_q1_2026.pdf" rel="noopener noreferrer"&gt;APWG&lt;/a&gt; recorded 971,181 phishing attacks during Q1 2026, representing a 13.8% increase compared with Q4 2025, while the number of known Phishing-as-a-Service kits doubled throughout 2025.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://services.google.com/fh/files/misc/cybersecurity-forecast-2026-en.pdf" rel="noopener noreferrer"&gt;Google&lt;/a&gt; has also highlighted the growing adoption of advanced MFA bypass techniques and increasingly sophisticated social engineering attacks, while deepfake technologies continue challenging traditional assumptions around identity verification.&lt;/p&gt;

&lt;h3&gt;
  
  
  Technical Insight
&lt;/h3&gt;

&lt;p&gt;Attackers are no longer attempting only to compromise systems—they’re increasingly attempting to impersonate trust itself.&lt;/p&gt;

&lt;p&gt;The implications extend far beyond user authentication. Machine identities are expanding rapidly across modern infrastructures, while compromised credentials can trigger automated actions across distributed environments with minimal friction.&lt;/p&gt;

&lt;p&gt;Zero Trust Network Access (ZTNA) adoption is accelerating partly because of these changes. As legacy VPN technologies continue reaching end-of-life, organizations are increasingly shifting toward identity-aware access models that provide users with access only to the resources they require while limiting opportunities for lateral movement.&lt;/p&gt;

&lt;h3&gt;
  
  
  Security Implications
&lt;/h3&gt;

&lt;p&gt;Identity protection in 2026 is becoming less about protecting credentials and more about continuously validating trust.&lt;/p&gt;

&lt;p&gt;Modern security architectures should increasingly prioritize:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Zero Trust principles.&lt;/li&gt;
&lt;li&gt;Adaptive authentication mechanisms.&lt;/li&gt;
&lt;li&gt;Identity threat detection capabilities.&lt;/li&gt;
&lt;li&gt;Machine identity governance.&lt;/li&gt;
&lt;li&gt;Risk-based access controls across distributed environments.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Identity is becoming as strategic as cloud and network security in modern application architectures.&lt;/p&gt;




&lt;h2&gt;
  
  
  What Modern Applications Are Teaching Us
&lt;/h2&gt;

&lt;p&gt;Looking across industries, several patterns are beginning to emerge.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;E-commerce and retail platforms accounted for 24% of observed bot attacks during 2025, according to CDNetworks’ technical observations. API attacks represented 32% of attacks targeting the industry during 2024, while approximately 22% of major DDoS incidents in late 2025 targeted online retail infrastructures.&lt;/li&gt;
&lt;li&gt;Gaming platforms remain particularly vulnerable to availability-related attacks. CDNetworks reported that gaming services experienced 57.38% of observed Layer 3 and Layer 4 attacks alongside 31.32% of Layer 7 attacks during 2024.&lt;/li&gt;
&lt;li&gt;Healthcare organizations continue facing substantial ransomware risks, with approximately 40% anticipated to experience attacks during 2026. The average cost of healthcare data breaches is projected to reach $12.6 million.&lt;/li&gt;
&lt;li&gt;Financial services remain heavily targeted by both API abuse and identity-related threats. According to CDNetworks, financial services accounted for 23.8% of observed API attacks throughout 2025, while Statista projects average breach costs within the sector will exceed $6.08 million during 2026. Deepfake attacks are accelerating as well, with Axios reporting that 55% of financial organizations experienced incidents during 2025, compared with 43% across other industries.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Although these industries face different challenges, they’re ultimately reinforcing similar lessons—security is moving closer to application architecture itself.&lt;/p&gt;




&lt;h2&gt;
  
  
  Final Thoughts
&lt;/h2&gt;

&lt;p&gt;Cybersecurity in 2026 isn’t simply about defending against the next vulnerability.&lt;/p&gt;

&lt;p&gt;Modern applications are changing faster than traditional security assumptions can keep pace. AI is reshaping attacker capabilities. APIs are continuously expanding application boundaries. Identity is replacing traditional perimeters, while availability and content protection are becoming architectural concerns rather than operational ones.&lt;/p&gt;

&lt;p&gt;Perhaps the biggest change isn’t happening within cybersecurity itself—it’s happening within the applications we’re building.&lt;/p&gt;

&lt;p&gt;Security is gradually moving closer to product architecture.&lt;/p&gt;

&lt;p&gt;Building secure applications in 2026 increasingly means assuming that automation, malicious traffic, machine identities, and adaptive threats are part of the environment from day one. The question is no longer whether modern applications will face these challenges, but whether they’re designed to continuously adapt when they do.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>cybersecurity</category>
      <category>cyberattack</category>
      <category>api</category>
    </item>
    <item>
      <title>5 Cybersecurity Trends Developers and Tech Leaders Should Watch in 2026</title>
      <dc:creator>Alvin</dc:creator>
      <pubDate>Thu, 16 Jul 2026 09:57:40 +0000</pubDate>
      <link>https://dev.to/alviny/5-cybersecurity-trends-developers-and-tech-leaders-should-watch-in-2026-33ja</link>
      <guid>https://dev.to/alviny/5-cybersecurity-trends-developers-and-tech-leaders-should-watch-in-2026-33ja</guid>
      <description>&lt;p&gt;Web applications and APIs sit at the center of modern digital services. They handle authentication, payments, search, content delivery, account management, and many of the workflows that developers build and maintain every day.&lt;/p&gt;

&lt;p&gt;That also makes them persistent targets.&lt;/p&gt;

&lt;p&gt;Each year, CDNetworks analyzes activity observed across our security platform to understand how threats involving web applications, APIs, bots, and digital services are changing.&lt;/p&gt;

&lt;p&gt;This article translates five findings from the &lt;a href="https://www.cdnetworks.com/reports/state-of-waap-2025/?utm_source=dev+to&amp;amp;utm_medium=3rd-party&amp;amp;utm_campaign=Download" rel="noopener noreferrer"&gt;&lt;strong&gt;CDNetworks 2025 State of WAAP Report&lt;/strong&gt;&lt;/a&gt; into practical considerations for developers, application security teams, platform engineers, and SREs.&lt;/p&gt;

&lt;p&gt;&lt;a href="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fjsgnr7hl8n4so81pm2of.png" class="article-body-image-wrapper"&gt;&lt;img src="https://media2.dev.to/dynamic/image/width=800%2Cheight=%2Cfit=scale-down%2Cgravity=auto%2Cformat=auto/https%3A%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Farticles%2Fjsgnr7hl8n4so81pm2of.png" alt="CDNetworks 2025 State of WAAP Report" width="800" height="453"&gt;&lt;/a&gt;&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;&lt;strong&gt;Methodology note:&lt;/strong&gt; The figures in this article reflect activity observed across the CDNetworks security platform during 2025. They describe activity within the scope of that platform telemetry and should not be interpreted as measurements of all global internet traffic.&lt;/p&gt;
&lt;/blockquote&gt;




&lt;h2&gt;
  
  
  TL;DR
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;AI is industrializing automated attacks.&lt;/strong&gt; AI-assisted tools are making attack campaigns more adaptive, scalable, and accessible.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;API abuse is becoming a primary path for business logic attacks.&lt;/strong&gt; Technically valid requests can still produce malicious business outcomes.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;AI bot traffic is creating a new governance challenge.&lt;/strong&gt; Teams need granular policies based on bot identity, purpose, access frequency, and content sensitivity.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Multi-layer DDoS attacks are raising the bar for resilience.&lt;/strong&gt; Campaigns can shift across network, transport, and application layers within the same attack.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;APAC is facing concentrated application-layer attack pressure.&lt;/strong&gt; APAC businesses are under greater pressure from attacks targeting their business-critical digital services.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Let’s take a closer look at each trend.&lt;/p&gt;




&lt;h2&gt;
  
  
  1. AI is industrializing automated attacks.
&lt;/h2&gt;

&lt;p&gt;Our latest research shows that AI is changing the economics of cyberattacks.&lt;/p&gt;

&lt;p&gt;Large language models, agentic AI tools, browser automation frameworks, and proxy networks are reducing the cost, time, and expertise required to run sophisticated campaigns.&lt;/p&gt;

&lt;p&gt;As a result, automated threats are moving beyond rigid scripts toward more adaptive, context-aware, and human-like attack patterns.&lt;/p&gt;

&lt;p&gt;This makes AI-driven automation a persistent and expanding threat to digital businesses.&lt;/p&gt;




&lt;h2&gt;
  
  
  2. API abuse is becoming a primary path for business logic attacks.
&lt;/h2&gt;

&lt;p&gt;APIs have become a primary route to business impact.&lt;/p&gt;

&lt;p&gt;In 2025, the CDNetworks security platform blocked more than &lt;strong&gt;15 billion malicious API requests per month on average&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Many attackers are now abusing legitimate functions such as login, registration, search, ordering, and payments, often through valid identities, sessions, and normal request paths.&lt;/p&gt;

&lt;p&gt;Because the activity can appear technically valid, business logic attacks are especially difficult to distinguish from genuine customer behavior.&lt;/p&gt;




&lt;h2&gt;
  
  
  3. AI bot traffic is creating a new governance challenge.
&lt;/h2&gt;

&lt;p&gt;AI bots are automated agents that crawl, retrieve, summarize, or act on online content for AI systems.&lt;/p&gt;

&lt;p&gt;In 2025, the CDNetworks security platform observed approximately &lt;strong&gt;1.64 million AI bot requests per day on average&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;Data scraping accounted for &lt;strong&gt;72.67%&lt;/strong&gt; of the observed AI bot activity.&lt;/p&gt;

&lt;p&gt;This volume shows that AI bots have become a meaningful part of enterprise internet traffic.&lt;/p&gt;

&lt;p&gt;But not all AI bots are harmful. Some support AI search, user-requested retrieval, or model improvement.&lt;/p&gt;

&lt;p&gt;Because similar technical behavior can serve very different purposes, simple allow-or-block decisions are often insufficient. Businesses need more granular governance based on bot identity, intent, context, access frequency, content sensitivity, and potential business impact.&lt;/p&gt;




&lt;h2&gt;
  
  
  4. Multi-layer DDoS attacks are raising the bar for resilience.
&lt;/h2&gt;

&lt;p&gt;Our research shows that DDoS campaigns are becoming more dynamic, with attackers shifting between Layers 3, 4, and 7 within the same campaign and adapting tactics in real time.&lt;/p&gt;

&lt;p&gt;A customer case from 2025 illustrates how this trend can play out in practice. &lt;/p&gt;

&lt;p&gt;The organization experienced a sustained, multi-day attack that targeted both its network and application layers. &lt;/p&gt;

&lt;p&gt;The campaign peaked at:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;1.4 Tbps&lt;/strong&gt; across Layers 3 and 4&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;770,000 requests per second&lt;/strong&gt; at Layer 7&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;CDNetworks mitigated the attack without business disruption.&lt;/p&gt;

&lt;p&gt;For business leaders, the implication is clear. &lt;/p&gt;

&lt;p&gt;DDoS risk now includes prolonged, multi-layered campaigns that can change tactics over time and pressure several parts of the digital environment at once. &lt;/p&gt;

&lt;p&gt;Maintaining availability under these conditions requires adaptive protection and expert mitigation across both network and application layers.&lt;/p&gt;




&lt;h2&gt;
  
  
  5. APAC is facing concentrated application-layer attack pressure.
&lt;/h2&gt;

&lt;p&gt;APAC accounted for &lt;strong&gt;67.45% of the Layer 7 DDoS activity observed on the CDNetworks security platform in 2025&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The region’s e-commerce, fintech, gaming, SaaS, mobile, entertainment, and digital content sectors depend on high-frequency paths such as login, search, checkout, verification, payments, content access, and API calls.&lt;/p&gt;

&lt;p&gt;Those revenue-critical workflows also make APAC businesses attractive targets for disruption, fraud, and abuse.&lt;/p&gt;




&lt;h2&gt;
  
  
  What Teams Should Prioritize in 2026
&lt;/h2&gt;

&lt;p&gt;Taken together, these trends show how attackers are combining legitimate identities, valid API traffic, automated tools, and business-critical workflows to create operational and security risks.&lt;/p&gt;

&lt;p&gt;For development, security, and platform teams, seven priorities stand out:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Protect revenue-critical API workflows&lt;/strong&gt;, including login, checkout, payments, verification, and account recovery.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Strengthen business continuity and API resilience in APAC markets&lt;/strong&gt;, where application-layer attack pressure is particularly concentrated.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Prepare for sudden spikes in automated traffic&lt;/strong&gt; before they affect application availability, backend services, and downstream dependencies.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Reduce exposure from compromised trusted identities&lt;/strong&gt;, including valid accounts, sessions, API keys, and service credentials.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Control the operational costs of AI-driven attacks&lt;/strong&gt;, especially when automated requests trigger expensive application or infrastructure processes.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Govern AI bot interactions based on business impact&lt;/strong&gt;, considering bot identity, purpose, access frequency, and content sensitivity.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Safeguard AI-enabled applications and agentic workflows&lt;/strong&gt; with scoped permissions, controlled tool access, and stronger oversight of high-impact actions.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;These priorities share a common goal: protecting critical digital services without creating unnecessary friction for legitimate users.&lt;/p&gt;




&lt;h2&gt;
  
  
  Final Thoughts
&lt;/h2&gt;

&lt;p&gt;The emerging security challenge is not limited to blocking requests that look obviously malicious. Teams also need to identify legitimate functionality being used with malicious intent.&lt;/p&gt;

&lt;p&gt;The &lt;strong&gt;CDNetworks 2025 State of WAAP Report&lt;/strong&gt; provides the supporting research and additional analysis behind these trends.&lt;/p&gt;

&lt;p&gt;👉 &lt;a href="https://www.cdnetworks.com/reports/state-of-waap-2025/?utm_source=dev+to&amp;amp;utm_medium=3rd-party&amp;amp;utm_campaign=Download" rel="noopener noreferrer"&gt;Read the full Report&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;If your team is assessing these risks and needs support from a specialist security provider, visit &lt;a href="https://www.cdnetworks.com/?utm_source=referral&amp;amp;utm_medium=dev+to&amp;amp;utm_campaign=0716" rel="noopener noreferrer"&gt;our website&lt;/a&gt; to learn how we help protect web applications, APIs, and digital services.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Disclosure: This article is based on security research and platform data from CDNetworks.&lt;/em&gt;&lt;/p&gt;

</description>
      <category>cybersecurity</category>
      <category>ai</category>
      <category>api</category>
      <category>security</category>
    </item>
  </channel>
</rss>
