Proof of concept (PoC) exploits are being rapidly weaponised by threat actors, even as soon as 22 minutes after they are made available to the public, new research from Cloudflare reveals.
The cybersecurity firm’s Application Security report which covers from April 2023 to March 2024, which delves into the threat landscape.
The report found that the speed at which these vulnerabilities are exploited outpaces defence and patch development, leaving organisations in the lurch as weaknesses are identified and proliferate across the public sphere.
For Cloudflare, this pushed the company to integrate their human written signatures of defence with a machine-learning approach to increase the speed of their response and reduce false positives.
The firm also said the speed of exploiting attack vectors has been enhanced by the specialisation of threat actors in certain vulnerabilities and attack types, meaning they can efficiently use weaknesses to their advantage.
Internet traffic was also studied in the report, with a shocking finding that 6.8% of all daily internet traffic is caused by distributed denial of service (DDoS) traffic, which is a common form of attack aiming to make online platforms inaccessible to users due to an oversaturation of traffic.
This is a marked increase from the 6% seen in the year prior, showing that DDoS attacks are on the rise. In total, DDoS comprised 37.1% of all mitigated application traffic, and HTTP DDoS attacks increased by 93% year on year.
Recommended reading
- Report: Vulnerability Exploitation Surge Endangers Cybersecurity
- IT Leaders Split on Generative AI’s Role in Cybersecurity
- Cyber Leaders Reveal Compliance and Boardroom Struggles
But this is still only the average – according the Cloudflare, malicious traffic can double, reaching 12% during global attack incidents.
This also suggests that bots are becoming increasingly common, and more effective in launching DDoS attacks. DDoS was found to be the number one attack type taken against web apps.
The report found that 93% of bots are potentially malicious, with one third (31.2%) of all traffic stemming from bots, 93% of which are unverified.





