Application Security & Development

Defending the AI-Generated Attack Surface: APIs, Botnets, and Vibe Coding

Defending the AI-Generated Attack Surface: APIs, Botnets, and Vibe Coding

Artificial intelligence is not just changing how organizations build software; it is acting as a massive force multiplier for existing vulnerabilities. As developers move faster with AI tools, the attack surface is expanding far beyond the capacity of human security teams to monitor manually.

This article explores:

  • The shift to behavior-based API attacks: Why traditional web defenses are failing against unauthorized workflows and AI agent interactions.
  • The hidden risks of “vibe coding”: How AI-assisted development tools are accelerating the introduction of legacy vulnerabilities into production environments.
  • The rise of super botnets: How commoditized Layer 7 DDoS attacks are overwhelming traditional infrastructure and what it means for your network architecture.

How Is Agentic AI Changing the API Attack Surface?

The fundamental challenge with autonomous AI agents is that they rely entirely on application programming interfaces (APIs) to perceive data and execute actions. According to recent threat research from Akamai, this dependence has drastically altered the threat landscape. The data reveals that approximately 61 percent of API attacks in 2025 involved unauthorized workflows and abnormal activity, a massive jump from just 30 percent in 2024. Attackers are moving away from traditional web exploits and focusing instead on behavioral manipulation.

This shift is exacerbated by sheer volume. According to Salt Security’s State of API Security Report, one quarter of enterprise respondents experienced over 100 percent growth in the number of APIs they manage over the past year. Traditional security tools that rely on static rules or rate limiting are blind to these new behavioral threats. To secure this expanding footprint, organizations must adopt continuous discovery mechanisms and behavioral analytics to understand exactly how APIs are being used by both human and machine identities.

%

of API attacks in 2025

involved unauthorized workflows and abnormal activity, a massive jump from just 30 percent in 2024.

What Are the Hidden Security Risks of AI-Assisted “Vibe Coding”?

The operational reality of modern software development is speed. Developers are increasingly relying on generative AI to scaffold code, a trend colloquially known as “vibe coding.” While this dramatically increases output, it introduces a severe operational impact for the security operations center. Akamai notes that AI is acting as a force multiplier for vulnerabilities, allowing developers to generate insecure code faster than security teams can manually review it.

Research from Checkmarx confirms that AI coding tools frequently reproduce insecure patterns from their training data. This means classic OWASP vulnerabilities, such as injection flaws and weak authentication mechanisms, are being coded into new applications automatically. Security leaders must intervene by embedding automated vulnerability scanning directly into the CI/CD pipeline. Without treating the OWASP Top 10 for Large Language Model Applications as a mandatory testing baseline, organizations risk deploying deeply flawed logic at an unprecedented scale.

How Are Super Botnets Transforming the DDoS Landscape?

While API vulnerabilities open the back door, brute-force attacks on the front door are becoming highly sophisticated. The commoditization of attack tools has given relatively unsophisticated threat actors access to massive resources. Akamai reports that Layer 7 Distributed Denial-of-Service (DDoS) attacks have surged by 104 percent over the last two years. This spike is largely driven by the emergence of new super botnets, such as Aisuru and Kimwolf, which weaponize compromised endpoints to overwhelm application layers.

Heading into 2027, CISOs must prepare for these volumetric attacks to become the baseline standard. A Layer 7 attack is particularly dangerous because it mimics legitimate user traffic, requiring advanced behavioral analysis to distinguish a botnet from a genuine customer surge. Organizations need to evaluate their infrastructure resilience and ensure their DDoS mitigation strategies are tightly integrated with their web application firewalls and API gateways.

Modernizing Your Defense Architecture

The speed of AI adoption means security teams can no longer rely on manual reviews or static defenses. If you are struggling to map your expanding API attack surface or defend against automated botnets, we can help. Defy works with organizations to build resilient, behavior-based security architectures that scale alongside your business.

Contact Defy to evaluate your current posture before the next wave of automated attacks hits.

Sources Cited

Partner Contribution

Thanks to our partner Akamai for their contributions to this article.

$

Contact Us