The digital landscape is a battlefield where cybercriminals wage relentless attacks on vulnerable applications. Cloudflare’s 2024 Application Security Report paints a stark picture of this escalating threat, revealing a complex and evolving landscape that demands urgent attention.
Content delivery network provider Cloudflare has issued a warning about a dramatic surge in web threats. The company’s new report highlights a sharp increase in distributed denial-of-service (DDoS) attacks, bot traffic, and rapid exploitation of zero-day vulnerabilities.
Cloudflare’s State of Application Security 2024 report is based on a year’s worth of HTTP traffic data, collected between April 1, 2023, and March 31, 2024. Analysing over 57 million HTTP requests per second from its global network, which blocked 209 billion cyberthreats daily, the report offers a comprehensive snapshot of the current web threat landscape.
The 2024 report highlights key trends, including shifts in blocked web application and API traffic, the growth and increased complexity of DDoS attacks, the weaponisation of vulnerabilities, and the growing risk of shadow APIs.
Now in its fourth edition, the Application Security Report introduces a new section focused on client-side security within the context of web applications. This years report goes so far as to predict that a lack of API security focus at organisations will lead to increased complexity and loss of control, and increased access to generative AI will lead to more API risk.
The Malicious Tide: An Unrelenting Onslaught
A defining characteristic of the current threat environment is the unprecedented surge in malicious traffic targeting web applications.
Bot traffic was the second biggest challenge for Cloudflare, accounting for 31% of all mitigated traffic. A staggering 93% of these bots were identified as potentially malicious. Industries most targeted by bots included manufacturing, consumer goods, cybersecurity, and the US federal government.
The reports authors write “Enterprises often have a disjointed patchwork of legacy and point products for security that make it hard to connect and protect their SaaS apps, web apps and other IT infrastructure. The IT sprawl makes it easier for attackers to find and exploit vulnerabilities. The broad nature of web application and API threats requires specialised approaches to stop specialised attacks. However, a consolidated approach helps ensure better security, latency-free connectivity and business growth.”
Cybercriminals are employing a combination of automated tools and human ingenuity to launch sophisticated attacks.
- Botnets unleashed: The proliferation of botnets has amplified the scale and intensity of attacks. These networks of compromised devices can be harnessed to launch DDoS attacks, scrape data, spread malware, and conduct brute-force attacks against login credentials.
- Human-driven attacks persist: While automated attacks dominate headlines, human adversaries remain a constant threat. Organised crime syndicates, state-sponsored actors, and financially motivated attackers continue to target web applications for financial gain, espionage, or disruption.
- The evolving tactics: Attackers are constantly refining their methods, adopting new techniques like credential stuffing, account takeover, supply chain attacks, and business email compromise (BEC) to bypass defences.
The consequences of this relentless onslaught are far-reaching. Organisations face increased risks of data breaches, financial loss, reputational damage, operational disruption, and compliance failures.
Web Applications: The Vulnerable Heart of Digital Businesses
Web applications remain the primary battleground for cybercriminals due to their critical role in business operations. The report highlights a growing risk from third-party software dependencies.
Enterprise organisations typically use an average of 47 third-party scripts to enhance website functionality, along with 50 connections to JavaScript functions and 12 cookies. This reliance on external code, increasingly loaded directly into users’ browsers, exposes organisations to significant supply chain risks, legal liabilities, and compliance challenges.
Highlights from the report include a range of vulnerabilities that attackers exploit including:
- Injection flaws: SQL injection, command injection, and NoSQL injection continue to be prevalent, enabling attackers to manipulate databases, execute malicious code, and steal sensitive data.
- Cross-site scripting (XSS): This vulnerability allows attackers to inject malicious scripts into web pages, stealing user data, hijacking sessions, and executing unauthorised actions.
- Broken authentication and session management: Weak password policies, insecure authentication mechanisms, and improper session management create opportunities for unauthorised access and account takeover.
- Insecure direct object references (IDOR): Improper access control can allow attackers to manipulate data and perform unauthorised actions.
- Security misconfigurations: Incorrectly configured web applications, servers, and cloud services expose vulnerabilities to exploitation.
- Sensitive data exposure: Storing and transmitting sensitive data without proper encryption can lead to data breaches and unauthorised access.
- Missing function level access control: Inadequate access control can allow unauthorised users to access restricted functionality and data.
- Cross-site request forgery (CSRF): This vulnerability enables attackers to trick users into performing unintended actions, such as transferring funds or changing account settings.
- Using components with known vulnerabilities: Outdated or compromised third-party components can introduce vulnerabilities into applications.
- Insufficient logging and monitoring: Lack of visibility into application activity hinders threat detection, incident response, and forensic analysis.
Beyond the Web Application: A Widening Attack Surface
The report also highlights a concerning trend in API security. Many organisations are relying on outdated methods, such as traditional web application firewall rules, which assume most web traffic is harmless.
This negative security model is less effective than the positive security model, which strictly defines allowed traffic and blocks everything else. Another finding in this years report is that the threat landscape extends far beyond web applications, encompassing a broader attack surface.
- APIs under siege: Application Programming Interfaces (APIs) are increasingly targeted by attackers due to their critical role in data exchange. Insufficient authentication, authorisation, and error handling can lead to data breaches, system compromises, and unauthorised access.
- Cloud security challenges: The rapid adoption of cloud computing has introduced new security risks, including misconfigurations, insecure APIs, unauthorised access, and data breaches.
- Internet of Things (IoT) vulnerabilities: The proliferation of IoT devices creates a vast attack surface, with potential for data breaches, DDoS attacks, network compromise, and physical harm.
- Supply chain attacks: The complexity of modern supply chains makes them attractive targets for cybercriminals. Compromised third-party vendors can provide entry points for attackers to infiltrate networks and steal data.
- Mobile applications: Mobile apps are increasingly targeted by attackers, with vulnerabilities in code, data storage, network communication, and insecure APIs posing risks.
- Industrial control systems (ICS): Critical infrastructure systems are facing growing threats, with potential for physical damage, disruption of services, and national security implications.
The Human Factor: A Persistent Challenge
The human element remains a persistent and critical vulnerability within the cybersecurity landscape. Despite advancements in technology, the susceptibility of individuals to social engineering tactics, phishing attacks, and inadvertent errors continues to pose a significant threat to organisations.
These vulnerabilities can lead to catastrophic data breaches, financial loss, and reputational damage. Consequently, a comprehensive security strategy must prioritise human factors, encompassing robust employee training, awareness programs, and the implementation of security controls designed to mitigate the risk of human error.
- Employee education: Raising employee awareness about cyber threats and best practices is crucial for preventing human-driven incidents.
- Security culture: Fostering a strong security culture where security is embedded into organisational processes is essential for long-term success.
Emerging Threats: The Future of Cybersecurity
The rapid evolution of technology is introducing new challenges and opportunities in cybersecurity.
- Artificial intelligence (AI): Both attackers and defenders are leveraging AI to gain an advantage. AI-powered attacks are becoming more sophisticated, while AI-driven security solutions are enhancing threat detection and response capabilities.
- Quantum computing: The potential impact of quantum computing on cryptography poses a long-term threat. Organisations must prepare for a post-quantum world.
- Biometric vulnerabilities: The increasing use of biometrics introduces new security challenges, as biometric data can be compromised or forged.
- Deepfakes: The creation of highly realistic synthetic media can be used for disinformation, fraud, and social engineering attacks.
Building Resilience: A Strategic Imperative
In order to effectively address the continually evolving threat landscape, organisations must implement a comprehensive and proactive security framework. This necessitates a multi-faceted approach that encompasses the identification, assessment, and mitigation of potential vulnerabilities.
By adopting a proactive stance and leveraging advanced technologies, organisations can enhance their resilience to cyber threats and safeguard their critical assets. To effectively address the evolving threat landscape, organisations must adopt a comprehensive and proactive approach to security. Key elements include:
- Risk assessment and management: Identifying, assessing, and prioritising risks is essential for allocating resources effectively.
- Incident response planning: Developing a robust incident response plan enables organisations to minimise the impact of security breaches.
- Continuous monitoring and improvement: Regular security assessments, audits, and vulnerability scanning are crucial for identifying and addressing weaknesses.
- Employee training and awareness: Investing in employee education and awareness programs is essential for building a security-conscious culture.
- Third-party risk management: Assessing and managing risks associated with third-party vendors is crucial for protecting the supply chain.
- Data protection: Implementing robust data protection measures, including encryption, access control, and data loss prevention, is essential for safeguarding sensitive information.
- Zero trust architecture: Adopting a zero-trust approach can help to strengthen security by verifying and authorising users and devices before granting access to resources.
- Threat intelligence: Leveraging threat intelligence to stay informed about emerging threats and attack trends is essential for proactive defence.
- Cybersecurity insurance: Considering cybersecurity insurance can help mitigate financial losses in the event of a breach.
The Role of Government and Industry Collaboration
The escalating sophistication and frequency of cyberattacks pose a formidable challenge to individuals, businesses, and governments alike. This growing digital threat landscape necessitates a robust and coordinated response. To effectively mitigate cyber risks and protect critical infrastructure, a unified approach is imperative.
Fostering strong partnerships between government agencies, the private sector, and academic institutions is essential to developing innovative solutions, sharing intelligence, and building a resilient cyber ecosystem. By combining the expertise of policymakers, industry leaders, and researchers, we can collectively enhance our ability to prevent, detect, and respond to cyber threats, safeguarding our digital future. Addressing the growing cyber threat requires collaboration between government, industry, and academia.
- Public-private partnerships: Sharing threat intelligence, best practices, and resources can enhance collective defence capabilities.
- Cybersecurity regulations: Clear and enforceable cybersecurity regulations can drive improvements in organisational security practices.
- Talent development: Investing in cybersecurity education and training is essential to develop a skilled workforce.
- International cooperation: Global collaboration is essential for addressing transnational cyber threats.
Summing Up
The application security landscape is a dynamic and complex environment, with new threats emerging constantly. The 2024 Application Security Report serves as a stark reminder of the challenges organisations face and the critical need for robust security measures.
By understanding the evolving threat landscape, adopting a proactive approach, and fostering a culture of security, organisations can build resilience, protect their assets, and maintain customer trust in the digital age.



