
7/11/2024 · Michael Tremante, Sabina Zejnilovic, Catherine Newcomb
What this post added
This post provides a 2024 update on Cloudflare's Application Security Report, detailing a substantial increase in malicious traffic activity across the Internet. It highlights key trends including: WAF and Bot mitigations accounting for over half of all mitigated traffic, the rapid exploitation of CVEs (as fast as 22 minutes after proof-of-concept), DDoS attacks remaining the most common attack vector, a significant portion of observed traffic being automated and potentially malicious bots, and API traffic accounting for 60% of all traffic with a concerning quarter of API endpoints unaccounted for. It also introduces a new section on client-side security and the proliferation of third-party integrations, noting an average of 47 third-party endpoints integrated on enterprise sites. The report also quantifies network growth, with HTTP requests per second increasing by 23.9% YoY and DNS queries per second by 40% YoY, and a substantial 86.6% YoY increase in blocked cyber threats.