Bad bots on the rise, targeting APIs

Share post:

Bad bots are getting cleverer, and as a result, more advanced attacks, such as account takeover and attacks against APIs, are increasing.

In June 2022, hackers launched an attack against Australia’s largest Chinese-language platform, Media Today, making over 20 million attempts to reset user passwords. The attackers weren’t humans, but bots—complex, automated programs that swarm around the internet carrying out instructions.

Bots can be benign or malicious. Benign bots, such as search engine crawlers, are used to harvest data for search engines. Malicious bots, on the other hand, are used to target digital systems, web applications, and application programming interfaces (APIs) for data theft, fraud, denial of service, and more.

Bad bots are evolving to become more sophisticated and are getting better at mimicking human behavior and bypassing traditional security controls. According to Imperva, bad bots accounted for just under half (48%) of all internet traffic in the first six months of 2023, up from 43% in the same period last year.

APIs are a growing target for bot attacks because they are relatively under-protected and used extensively for automated processes and communications. Attackers target applications that use APIs to access email accounts, such as marketing mailshot applications that send and track bulk- or personalized- emails to potential or existing customers.

The sources for this piece include an article in SecurityBrief.

SUBSCRIBE NOW

Related articles

North Korean hacker infiltrates US security vendor, loads malware

KnowBe4, a US-based security vendor, unknowingly hired a North Korean hacker who attempted to introduce malware into the...

CrowdStrike releases an update from initial Post Incident Review: Hashtag Trending Special Edition for Thursday July 25, 2024

Security vendor CrowdStrike released an update on from their initial Post Incident Review today. The first, and most surprising...

Security vendor CrowdStrike issues an update from their initial Post Incident Review

Security vendor CrowdStrike released an update from their initial Post Incident Review (PIR) today. The company's CEO has...

CrowdStrike CEO summoned by Homeland Security committee over software disaster

CrowdStrike CEO George Kurtz has been called to testify before the U.S. House Committee on Homeland Security following...

Become a member

New, Relevant Tech Stories. Our article selection is done by industry professionals. Our writers summarize them to give you the key takeaways