Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

App attacks hit 83% in January 2025: what should teams change?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12795
Topic starter  

TL;DR: App attacks surged to 83% in January 2025, up from 65% in 2024, as AI-assisted malware, attack profitability, and attack democratization widened the risk surface beyond corporate firewalls, according to Arxan Technologies' 2025 Application Security Threat Report. The security model is shifting from perimeter protection to continuous application hardening across web, mobile, and desktop estates.

NHIMG editorial — based on content published by Arxan Technologies: 2025 Application Security Threat Report

By the numbers:

Questions worth separating out

Q: What breaks when application secrets are not governed like identities?

A: Application secrets become durable access paths instead of controlled credentials.

Q: Why do AI-assisted attacks increase application risk so quickly?

A: AI-assisted tooling reduces the effort required to find exposed endpoints, vary payloads, and test credentials at scale.

Q: How do security teams know if application hardening is keeping pace with attackers?

A: Measure the time from publication to hostile contact, the percentage of apps with embedded secrets, and the speed of revocation after exposure.

Practitioner guidance

  • Map application secrets to named owners Inventory API keys, tokens, certificates, and service accounts used by applications, then assign each one an accountable owner and expiry or rotation policy.
  • Reduce credential persistence windows Replace long-lived application secrets with shorter-lived credentials where possible, and rotate or revoke any secret that is embedded in code, build pipelines, or deployment templates.
  • Add runtime detection around app-to-app trust Monitor for abnormal token use, unusual service account activity, and unexpected backend access from application workloads.

What's in the full report

Arxan Technologies' full report covers the operational detail this post intentionally leaves for the source:

  • Attack frequency breakdowns across Android, iOS, web, and desktop application targets
  • The report's breakdown of how AI-assisted malware is changing attacker economics
  • Industry-specific risk patterns that help teams prioritise application hardening work
  • Proactive strategies for securing applications beyond the corporate firewall

👉 Read Arxan Technologies' 2025 Application Security Threat Report →

App attacks hit 83% in January 2025: what should teams change?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12338
 

Application attack frequency is becoming a governance problem, not only a tooling problem. When attacks rise as development accelerates, teams cannot rely on perimeter-era assumptions about where risk lives. The operational question becomes whether application identities, embedded secrets, and release pipelines are governed as part of the same control plane. That is where NHI governance intersects with app security: service credentials that live inside software behave like identities, not static code artefacts. Practitioner conclusion: treat application trust as an identity lifecycle issue.

A question worth separating out:

Q: Who is accountable when an application credential is exposed and reused?

A: Accountability should sit with both the application owner and the team responsible for credential governance, because the failure spans software design and identity control. If the organisation cannot name an owner for each secret, it cannot reliably rotate, revoke, or offboard it. That gap becomes a governance issue, not just a security incident.

👉 Read our full editorial: App attacks surged to 83% as AI-assisted malware expands



   
ReplyQuote
Share: