Web apps and APIs were attacked more than ever last year

Red padlock open on electric circuits network dark red background
(Image credit: Shutterstock/Chor muang)

Web applications and APIs are popular targets for hackers, as they make use of flaws and misconfigurations to extract valuable data.

Verizon's Data Breach Investigation Report (DBIR) found that web apps were used in 80% of security incidents and 60% of breaches in 2023, and now a report from Barracuda claims to have dealt with 18 billion attacks on web apps last year, with over a billion in December alone.

It claims that many carry vulnerabilities or configuration errors, and since they often contain confidential information to businesses, such as personal and financial data, they make for prime attack targets.  

Barracuda also found that 40% of IT professionals believe attacks on web apps to be one of the most lucrative for cybercriminals, while 55% thought the same of attacks on APIs.

Web applications include popular productivity tools such as Google Workspace and Microsoft 365, which allow users to work and collaborate on documents from anywhere via their web browser alone.

Barracuda found that most attacks on web applications targeted security misconfigurations (30%). The second most popular attack type was code injections (21%). These include not just SQL injections, but also Log4Shell and LDAP injections. The latter is used in privilege management, such as supporting Single Sign-On (SSO) for applications.

Bot attacks on web apps were also popular last year, with most (53%) being used for volumetric Distributed Denial of Service (DDoS) attacks. These are attacks that make use of IoT devices, and "flood the target with data packets to use up bandwidth and resources." Barracuda points out that "such attacks can be used as a cover for a more serious and targeted attack against the network."

As for vulnerabilities in web apps, Barracuda believes that the ProxyShell flaws originating from 2021 are still being exploited frequently, leading to high-value breaches and even ransomware.

Barracuda claims that "attackers will often target old vulnerabilities that security teams have forgotten about," and that "multiple layers" of security are needed to secure web apps and APIs.

MORE FROM TECHRADAR PRO

Lewis Maddison
Reviews Writer

Lewis Maddison is a Reviews Writer for TechRadar. He previously worked as a Staff Writer for our business section, TechRadar Pro, where he had experience with productivity-enhancing hardware, ranging from keyboards to standing desks. His area of expertise lies in computer peripherals and audio hardware, having spent over a decade exploring the murky depths of both PC building and music production. He also revels in picking up on the finest details and niggles that ultimately make a big difference to the user experience.

Read more
API
Businesses are being plagued by API security risks - with nearly 99% affected
Best email services: image of email with one unread message alert
Over 400 million unwanted and malicious emails were received by businesses in 2024
Representational image of a hacker
The 10 worst software disasters of 2024: cyberattacks, malicious AI, and silent threats
Web DDoS attacks see major surge as AI allows more powerful attacks
Flags of Iran, China, Russia and North Korea on a wall. China North Korea Iran Russia alliance
Cybercrime is helping fund rogue nations across the world - and it's only going to get worse, Google warns
Fraude en ligne phishing
Phishing clicks nearly tripled in 2024 as criminals aim for smarter attacks
Latest in Security
Data Breach
Thousands of healthcare records exposed online, including private patient information
China
Juniper patches security flaws which could have let hackers take over your router
Representational image depecting cybersecurity protection
GitLab has patched a host of worrying security issues
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
AI agents can be hijacked to write and send phishing attacks
China
Volt Typhoon threat group had access to American utility networks for the best part of a year
Abstract image of cyber security in action.
MassJacker malware targets those looking for pirated software
Latest in News
Three iPhone 16 handsets on show
Apple could launch an iPhone 17 Ultra this year – but we've heard these rumors before
Super Mario Odyssey
ChatGPT is the ultimate gaming tool - here's 4 ways you can use AI to help with your next playthrough
Ray-Ban smart glasses with the Cpperni logo, an LED array, and a MacBook Air with M4 next to ecah other.
ICYMI: the week's 7 biggest tech stories from Twitter's massive outage to iRobot's impressive new Roombas
Brad Pitt looks over his right shoulder with 'F1' written behind him
Apple Original Films will take you behind-the-scenes of a racing cockpit in this new thrilling F1 movie trailer
AI writer
Coding AI tells developer to write it himself
Reacher looking down at another character from the Prime Video TV series Reacher
Reacher season 3 becomes Prime Video’s biggest returning show thanks to Hollywood’s biggest heavyweight