Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Application attack rates are rising fast. What should security teams change?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 13010
Topic starter  

TL;DR: Application attack rates climbed from 55% in 2022 to 87% in 2026, with first hostile contact arriving 1 hour and 56 minutes after app store publication, according to Arxan Technologies' 2026 Application Security Threat Report. AI is shrinking the cost and skill barriers for app reverse engineering faster than most enterprise defence models are adapting.

NHIMG editorial — based on content published by Arxan Technologies: 2026 Application Security Threat Report

By the numbers:

Questions worth separating out

Q: How should security teams handle secrets found in application code?

A: Treat every secret in code as a governance issue, not just a coding mistake.

Q: Why do public applications create such a short attack window?

A: Because attackers can discover and probe public releases immediately, often with automation and AI-assisted analysis.

Q: What do security teams get wrong about mobile and application secrets?

A: They often treat embedded secrets as implementation details instead of reusable access.

Practitioner guidance

  • Shift secret discovery left of release Scan builds, client bundles, mobile packages, and CI artefacts for API keys, tokens, certificates, and backend credentials before publication.
  • Treat application-linked identities as governed assets Assign ownership, scope, rotation, and revocation rules to app-linked service accounts and tokens so they are managed like other non-human identities across their lifecycle.
  • Instrument post-release hostile-contact monitoring Watch for anomalous API probing, rapid reverse engineering signals, and suspicious authentication attempts in the first minutes and hours after app publication.

What's in the full report

Arxan Technologies' full report covers the operational detail this post intentionally leaves for the source:

  • Vertical-by-vertical attack rate breakdowns for mobile, banking, connected-vehicle, and medical device environments.
  • Telemetry methodology behind the first hostile contact timing and how the report measures early abuse patterns.
  • Additional trend data on regional shifts across EMEA, LATAM, APAC, and North America.
  • Context on how AI changes attacker workflow and the economics of reverse engineering.

👉 Read Arxan Technologies' 2026 Application Security Threat Report →

Application attack rates are rising fast. What should security teams change?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 12594
 

AI has collapsed the attacker preparation phase, which makes public application exposure a governance problem rather than only a testing problem. The report's core signal is that hostile contact now happens within hours, not days. That shortens the defender's useful response window and changes what counts as timely control verification. For practitioners, this means release governance must include identity-bearing assets, secret exposure checks, and runtime monitoring before publication, not after the first abuse event.

A question worth separating out:

Q: How can organisations limit damage when an app release is attacked quickly?

A: They should combine pre-release secret scanning, strict token scope, fast revocation, and runtime anomaly detection on exposed services. The goal is to shrink blast radius before attackers can chain reconnaissance into credential abuse. If release is already public, containment depends on rapid identity rotation and service-side control.

👉 Read our full editorial: Application attack rates surge as AI compresses the attacker cost curve



   
ReplyQuote
Share: