Web Application Security Report 2025 Highlights Rise in Application Breaches
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
The Web Application Security Report 2025 indicates a troubling trend in application breaches, with 56% of surveyed organizations reporting a breach in the past year, up from 50% in 2024. This increase highlights the ongoing challenges in application security, particularly as organizations face evolving threats. A notable incident involved MGM Resorts, which experienced a breach that exploited application vulnerabilities, resulting in operational disruptions and the exposure of sensitive customer data.
Additionally, the report reveals that malware injection remains the most reported attack vector at 34%, followed closely by stolen credentials at 30%. These statistics reflect the growing sophistication of attacks, including credential stuffing and brute force methods targeting weak passwords. Software vulnerability exploits were reported by 29%, while application misconfigurations accounted for 26%, emphasizing the need for improved vulnerability management and secure configuration practices.
Another significant finding is the lack of confidence among organizations regarding their application and API visibility. Only 14% of respondents are very confident they know all applications and APIs in use, a decline from 21% last year. This uncertainty can lead to vulnerabilities, as demonstrated by the 2022 Optus API incident, where attackers exploited an unmonitored API endpoint to access sensitive customer data.
Organizations are also increasingly concerned about advanced threats, including human-like bots. The report shows that only 13% of respondents feel very prepared to defend against such bots, which are used for credential stuffing and data scraping. This lack of preparedness is concerning, especially given the rise in DDoS attacks, which have become the most common bot attack, with 49% of organizations expressing concern.
Implications for Cybersecurity
The findings from the report highlight the urgent need for organizations to bolster their application security measures. With the rise in breaches and sophisticated attack vectors, organizations must prioritize continuous monitoring and advanced threat detection capabilities. This includes implementing robust malware defenses and improving visibility into their application ecosystems to mitigate risks associated with shadow IT and undocumented APIs.
Furthermore, organizations should focus on educating employees about the risks of credential stuffing and the importance of using strong, unique passwords. Implementing multi-factor authentication can significantly reduce the risk of unauthorized access to accounts.
As AI-driven attacks become more prevalent, organizations must also adapt their defenses to counter these emerging threats. This includes investing in technologies that can detect AI-generated phishing attempts and other sophisticated attacks that exploit vulnerabilities in human behavior.
- MGM Resorts faced a significant breach due to application vulnerabilities, leading to operational disruptions and customer data exposure.
- Malware injection is the most reported attack vector at 34%, highlighting the need for robust defenses.
- Only 14% of organizations are very confident in knowing all applications and APIs in use, indicating visibility issues.
- In 2022, the Optus API incident demonstrated the risks of unmonitored API endpoints.
- Only 13% of organizations feel very prepared to defend against human-like bots, which are increasingly used for attacks.
Key Takeaways
- Implement continuous application monitoring to detect and respond to vulnerabilities promptly.
- Educate employees on the importance of using strong, unique passwords and enable multi-factor authentication.
- Regularly audit and document all applications and APIs in use to improve visibility and security.
- Invest in advanced threat detection tools to counter AI-driven attacks and sophisticated phishing attempts.
- Stay informed about the latest attack vectors and adjust security measures accordingly.
Key Terms & Concepts
- Malware Injection: In this article, malware injection refers to a type of attack where malicious code is inserted into an application to compromise its functionality.
- Credential Stuffing: Credential stuffing is a cyber attack where stolen login credentials are used to gain unauthorized access to user accounts.
- API: An API, or Application Programming Interface, allows different software applications to communicate and interact with each other.
- DDoS Attack: A DDoS attack, or Distributed Denial of Service attack, aims to overwhelm a service with traffic to disrupt its normal functioning.
- Human-Like Bots: Human-like bots are automated scripts designed to mimic legitimate user behavior, often used for malicious activities like data scraping.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.