State of Web Application and API Protection Report 2025

Report
State of WAAP Report 2025
State_of_WAAP_Report_2025.jpg

AI is changing the economics of attacks against web applications and APIs.

By reducing the cost, skill, and time required to launch automated campaigns, AI is enabling attackers to scale attacks faster, adapt tactics more easily, and target business-critical workflows with greater precision.

This shift is fueling a new wave of WAAP risks, including multi-layer DDoS campaigns, AI-driven bot activity, API abuse, and business logic attacks. Together, these trends are reshaping how organizations need to protect modern web applications and APIs.

Based on data from the CDNetworks security platform, our latest State of WAAP Report examines how DDoS attacks, web application threats, bot activity, and API attacks evolved throughout 2025.

Key findings include:

  • 329 L3/4 DDoS attacks exceeded 1 Tbps, with the largest peaking at 1.55 Tbps
  • 67% of L7 DDoS attacks were concentrated in APAC
  • 43.5% of AI-driven bot activity was linked to API-related attacks
  • 74% of observed bot traffic came from bad bots
  • Financial Services was the most targeted sector for API attacks

Download the report to explore the full findings and learn practical strategies to strengthen protection across your web applications and APIs.

Download The Report

Fields with an * are required.