Table of Contents
It’s undeniable that AI is changing the security equation for modern applications.
Attack techniques that once depended on manual effort can now be automated, adapted, and executed at far greater scale.
Speed is only part of the problem. AI also gives attackers more ways to test defenses, refine behavior, and blend malicious activity into normal traffic patterns.
This shift is reshaping web application and API security. As AI lowers the barrier for more dynamic attack activity, organizations are facing a threat environment that moves faster than traditional security assumptions were designed to handle.
Our latest State of WAAP Report is now available. Based on observations from the CDNetworks security platform, the report examines how AI is influencing web application security, API protection, bot management, and DDoS defense. It also explores what these trends mean for organizations that need to maintain resilience as the threat landscape continues to evolve.

Key Findings from the Report
The report highlights several trends shaping today’s WAAP landscape:
-
DDoS attacks tested both capacity and resilience. In 2025, 329 DDoS attacks exceeded 1 Tbps, with the largest attack peaking at 1.55 Tbps.
-
L7 DDoS attacks concentrated in APAC. The region accounted for 67% of observed L7 DDoS attacks.
-
APIs became a major target for AI-driven automation. CDNetworks observed that 43.5% of AI-driven bot activity directly targeted APIs.
-
Bad bots dominated automated traffic. They accounted for 74% of observed bot traffic.
-
Financial services remained a high-value target for API attacks. The sector accounted for 23.8% of API attacks observed by the CDNetworks security platform.
Trends Reshaping the WAAP Landscape
1. AI is industrializing automated attacks.
AI is reducing the time, cost, and expertise required to execute sophisticated campaigns. Automated threats are becoming more adaptive, context-aware, and difficult to distinguish from legitimate activity.
2. API abuse is becoming a primary path for business logic attacks.
APIs are now central to digital business, making them a high-value target. In 2025, the CDNetworks security platform blocked more than 15 billion malicious API requests per month on average. Many attacks no longer rely on obvious exploits. Instead, they abuse legitimate workflows such as login, checkout, search, registration, and payment.
3. AI bot traffic is creating new governance challenges.
CDNetworks observed an average of 1.64 million AI bot requests per day in 2025. As AI bots become a more visible part of enterprise internet traffic, organizations need more granular controls based on intent and context rather than simple allow-or-block decisions.
4. Multi-layer DDoS attacks are raising the bar for defense resilience.
Attackers are combining network-layer, transport-layer, and application-layer techniques to increase disruption. In one 2025 customer case observed by CDNetworks, a sustained multi-day, multi-layer DDoS campaign, with L3/L4 attack traffic peaking at 1.4 Tbps and Layer 7 traffic reaching 770,000 qps. This makes resilience a broader WAAP priority, not just a capacity issue.
5. APAC enterprises face concentrated application-layer attack pressure.
In 2025, Application-layer attacks continue to place concentrated pressure on enterprises in APAC, where digital services, mobile applications, and API-driven business models are widely adopted. CDNetworks platform data shows that APAC accounted for 67.45% of observed Layer 7 DDoS activity in 2025.
What Security Teams Should Consider Next
The report also outlines where security leaders may need to rethink WAAP priorities as attacks become more automated, adaptive, and closely tied to business outcomes.
Key priorities include:
- Protect revenue-critical API workflows
- Manage business continuity and API resilience in APAC markets
- Prepare for automated traffic spikes to protect operations
- Reduce exposure from trusted identity compromise
- Control operational costs from AI-driven attacks
- Govern AI bot interactions with business impact in mind
- Safeguard AI-enabled applications and agentic workflows
Download the Full State of WAAP Report 2025
The CDNetworks State of WAAP Report 2025 provides a detailed analysis of the trends affecting web applications, APIs, bots, and DDoS attacks, together with practical recommendations for strengthening modern WAAP strategies.
Download the full report to explore the full findings and understand how the threat landscape continues to evolve.

Frequently Asked Questions
1. What is the CDNetworks State of WAAP Report?
CDNetworks State of WAAP Report analyzes the evolving threat landscape around web applications, APIs, bots, and DDoS attacks, based on data and observations from the CDNetworks security platform.
2. What changed in the 2025 web application and API threat landscape?
Attackers became more automated and adaptive in 2025, using legitimate-looking traffic, trusted identities, and API workflows to create disruption, fraud, data exposure, and service degradation.
3. Why are AI-driven bots becoming a concern for enterprises?
AI-driven bots create enterprise risk by scraping valuable content, increasing infrastructure costs, and automating access to digital assets at a scale that traditional controls may struggle to manage.
4. How is AI changing cyberattacks against web applications and APIs?
AI reduces the time, cost, and expertise needed to build adaptive campaigns, vary attack patterns, probe defenses, and mimic legitimate digital behavior.
5. Who should read the CDNetworks State of WAAP Report 2025?
Security leaders, CISOs, IT teams, and business decision-makers should read the report to understand how web, API, bot, and DDoS threats are evolving in the age of AI.
