As organizations accelerate AI adoption, attackers have repositioned to exploit the infrastructure powering that transformation. APIs, the connective tissue of modern AI systems, have become the primary attack surface, according to Akamai's 2026 Apps, APIs, and DDoS State of the Internet report released today.
The data is stark: daily API attacks rose 113 percent year over year. Layer 7 DDoS attacks surged 104 percent over the past two years. Web application attacks climbed 73 percent between 2023 and 2025. Eighty-seven percent of surveyed organizations reported an API-related security incident in 2025.
The pattern Akamai researchers identify is not opportunistic but structural. Attackers are industrializing their methods, blending API abuse, web application attacks, and Layer 7 DDoS activity into coordinated campaigns designed for scale. The shift is away from headline-grabbing breaches toward sustained campaigns that degrade performance, inflate infrastructure costs, and exploit automation.
"Attackers increasingly focus on degrading performance, driving up infrastructure costs, and exploiting AI-driven automation at scale, rather than seeking headline-grabbing campaigns," said Patrick Sullivan, CTO of Security Strategy at Akamai. "Automation and AI are making these sophisticated campaigns cheap, repeatable, and fast."
Several structural factors are accelerating the problem. "Vibe coding" -- AI-assisted code generation without adequate security review -- is introducing misconfigurations that reach production unsanitized. Hacktivist-driven DDoS activity is rising alongside politically motivated actors who now have access to DDoS-for-hire services powered by AI-generated attack scripts. "Super botnets" such as Aisuru and Kimwolf, built on the Mirai architecture, have grown sophisticated enough to target APIs and web applications at scale.
The report also identifies a governance gap: application and API security are still frequently managed as separate disciplines, even as attackers exploit them as a single attack vector. Treating them separately creates visibility gaps that attackers need to move from initial compromise to full exploitation.
The agentic AI layer adds a compounding risk. As enterprises deploy autonomous agents that call APIs to execute tasks, the attack surface expands beyond what static inventory and perimeter controls were designed to protect. An agent with broad API access becomes a force multiplier for any attacker who can influence its inputs -- a dynamic the report describes as central to the next phase of the threat landscape.
The Akamai findings arrive as a wave of vendors are repositioning for the agentic security market. XM Cyber this week added MCP server inventory and cloud AI exposure mapping to its Continuous Exposure Management Platform, specifically to address the blind spots created by rapid AI tool deployment. The convergence of these launches reflects a market that has moved from awareness to active product investment in the span of one reporting cycle.
Sources: Akamai, Help Net Security
--
By the Control Plane Editorial Team