logo

Attackers Can Find New APIs in 29 Seconds: Wallarm

ID: 7085cf7a-d74f-505e-9fd2-d02e8a167816

STIX ID: report--7085cf7a-d74f-505e-9fd2-d02e8a167816

Feed Name: Security Boulevard

Date Published: 2024-12-17

Date Updated: 2026-04-22

Author: Jeffrey Burt

...
...

Wallarm’s API honeypot study reports that newly exposed APIs are typically discovered within ~29–34 seconds and can be probed or exploited in under a minute, with attackers heavily targeting port 80 and common endpoints like /status, /health, and /info. Captured activity was dominated by CVE exploitation attempts (40%), discovery/scanning (34%), and authentication checks (26%), and APIs slightly overtook web apps as primary targets (54.5% vs. 45.6%). The findings underline widespread, globally distributed scanning and advise organizations to harden and obfuscate public endpoints, prioritize API security, and assume immediate exposure upon deployment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.