Site navigation

AI-driven APIs Are Lacking in Security

Elizabeth Greenberg

,

AI APIs
“AI is transforming web and API security, enhancing threat detection but also creating new challenges,” said Rupesh Chokshi, senior vice president and general manager of Akamai’s Application Security Portfolio.

Web attacks were up by a third year-on-year, cyber firm Akamai Technologies found, largely driven by AI which is increasingly used to develop APIs.

The report from Akamai found that APIs have emerged as primary targets for cyber-attacks, with 150 billion API attacks from January 2023 through December 2024 tracked by Akamai.

The AI API market is growing rapidly and the integration of AI-driven tools with core platforms via APIs has substantially expanded this attack surface.

The majority of AI-powered APIs are externally accessible and many rely on inadequate authentication mechanisms, a vulnerability compounded by the growing array of AI-driven attacks targeting them.

Akamai notes that AI-powered APIs are even more vulnerable than their counterparts as AI fuels technical advancements for threat actors.

In addition, Akamai documents a dramatic rise in Layer 7 (application-layer) distributed denial of service (DDoS) attacks against web applications and APIs. Quarterly attack volumes increased 94% year-over-year between Q1 2023 and Q4 2024.

In early 2023, they observed monthly numbers of 500 billion, which rose to 1.1 trillion in one month by December 2024. This growth is due to the growing sophistication of bot-driven attacks, the persistence of HTTPS flooding as a primary attack vector, and the prevalence of Layer 7 DDoS attacks targeting the high technology industry.

The report also found that there were more than 230 billion web attacks targeting commerce organisations, making it the most impacted industry. This is nearly triple the number of attacks experienced by high technology, which was the second most attacked sector.

Further, there were 7 trillion Layer 7 DDoS attacks targeting the high technology sector from January 2023 through December 2024, making it the most affected industry.


Recommended reading


Authentication and authorisation flaws are continually exposing sensitive data and functionality, as OWASP API Security Top-10 related incidents increased by 32%.

Akamai also found that growth in security alerts related to the MITRE security framework are up 30% as attackers are using advanced techniques such as automation and AI to exploit APIs.

Alarmingly, shadow and zombie APIs are presenting as particularly vulnerable attack vectors within increasingly complex API ecosystems.

“AI is transforming web and API security, enhancing threat detection but also creating new challenges,” said Rupesh Chokshi, senior vice president and general manager of Akamai’s Application Security Portfolio.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data