
Contrast Security Releases Software Under Siege 2025, Exposing What Traditional Reports Miss About Application-Layer Threats
Recent reports from Verizon (DBIR 2025) and Google Mandiant (M-Trends 2025) confirm what many security leaders already suspect: components of the application layer are among the most targeted and least protected parts of the modern enterprise. This trend includes hackers' heightened focus on cloud environments, which heavily depend on application-layer services and interfaces, such as critical components like cloud-based single sign-on (SSO) web portals that store centralized authority.
But those reports raised an even bigger question:
What's actually happening inside the applications we build and run every day?
The Software Under Siege 2025 report from Contrast Security provides the missing context, offering a detailed, data-driven view into the vulnerabilities, exploit patterns, and attacker behaviors that SOC and AppSec teams need to understand now. Built on 1.6 trillion runtime observations per day, the report provides a uniquely accurate picture of how applications and APIs are being targeted, and how defenders can regain control.
'We're seeing a fundamental shift in how applications are being attacked,' said Jeff Williams, CTO and Founder of Contrast Security. 'AI is making it easier than ever for adversaries to launch targeted, viable attacks at scale, while traditional tools like WAFs, SAST, and EDR remain blind to what's happening inside the application while it's running. This report exposes that gap with hard data. It shows where the real threats are, how fast they're moving, and why organizations need a new model for defense: one that starts with runtime visibility.'
The report confirms that applications and APIs are the modern battleground of choice for attackers. Key findings include:
Why attackers are winning: On average, apps contain 30 serious vulnerabilities. AI-generated code is exacerbating the problem, and third-party libraries are accelerating the risk.
Why defenders can't keep up:
Applications face an average of 17 new vulnerabilities per month, with developer teams remediating 6 per month, on average.
Attackers exploit new vulnerabilities in just 5 days, but it takes 84 days on average to patch even the most critical flaws.
Application attacks are more prolific than ever before, with the average application targeted by attackers once every 3 minutes.
The average application is exposed to 81 confirmed, viable attacks each month that evade other defenses, primarily driven by untrusted deserialization, method tampering, OGNL injection, and similar attacks, which can vary by industry and technology stack.
A small number of attack techniques, harder to execute before AI, account for the lion's share of risk.
Why traditional tools fall short: WAFs and EDRs lack the runtime context to detect the growing threats. Many SOCs are flying blind.
The new 'best practice': A small number of attack techniques account for the majority of risk. Focusing on what's exploitable now enables teams to regain control.
To manage the growing risks, security teams are increasingly evolving their strategies to address the visibility gap at the application layer. That includes moving beyond traditional reactive defenses and adopting runtime protection models that can detect and stop attacks from within running applications.
The report also highlights how shared telemetry across SecOps, AppSec, and development teams helps organizations focus on the threats and vulnerabilities that pose the greatest real-world risk. This unified, contextual approach enables faster response, more targeted remediation, and reduced alert fatigue across security workflows.
Organizations adopting these practices are better positioned to improve their resilience against the rising tide of AI-assisted application-layer threats.
To download the full report, visit https://www.contrastsecurity.com/software-under-siege-2025-report.
Methodology
The report combines proprietary data from the Contrast Runtime Security Platform with additional data from trusted third parties to help security leaders understand the scope and nature of application-layer threats.
Contrast's data is collected from real-world running applications and application programming interfaces (APIs), using a lightweight sensor that allows full visibility into the complete runtime context. This 'inside-out' approach provides continuous visibility into how applications behave and are targeted in real-world production environments.
About Contrast Security
Contrast Security is the global leader in Application Detection and Response (ADR), empowering organizations to see and stop attacks on applications and APIs in real time. Contrast embeds patented threat sensors directly into the software, delivering unmatched visibility and protection. With continuous, real-time defense, Contrast uncovers hidden application-layer risks that traditional solutions miss. Contrast's powerful Runtime Security technology equips developers, AppSec teams and SecOps with one platform that proactively protects and defends applications and APIs against evolving threats.
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles
Yahoo
9 minutes ago
- Yahoo
Hexnode UEM Partners With Quokka to Double Down on Mobile App Security for Businesses
- Meet Hexnode at Black Hat USA 2025, Booth 1360, Las Vegas | August 6-7 - Tune in to Hexnode Live for further updates on the Hexnode – Quokka partnership | August 19, 2025 SAN FRANCISCO, July 29, 2025--(BUSINESS WIRE)--Hexnode, the enterprise software division of Mitsogo Inc., has announced a strategic integration with Quokka, a leader in mobile app risk intelligence. This collaboration, now available for Android and iOS devices, enables organizations to manage their mobile applications via Hexnode, while leveraging Quokka's capabilities to continuously assess mobile apps for malicious behavior, security vulnerabilities, and privacy risks. "Hexnode has built a powerful, intuitive platform for managing mobile devices at scale," said Vijay Pawar, Senior Vice President of Product at Quokka. "By integrating Quokka's mobile app risk intelligence, we're able to instantly deliver continuous app risk monitoring at scale. Together, we're giving customers an integrated solution that closes the mobile app security gap." The growing prevalence in sideloaded, unauthorized apps and the lack of centralized app vetting have contributed to a global surge in mobile malware infections. A 2024 report by Recorded Future highlighted how infostealer malware embedded in mobile apps was used to steal credentials and bypass enterprise security systems. Further, according to the Gartner® report, "Through 2030, mobile application security failures will be the biggest mobile threat for enterprises." Hexnode's integration with Quokka addresses these challenges by integrating Quokka's mobile app risk intelligence directly into the Hexnode environment, closing the mobile app security gap and delivering a comprehensive, end-to-end mobile security solution. Key Capabilities of the Integration App Behaviour Monitoring Detects data exfiltration, app collusion, and malicious activity within the app repository. Agentless, Zero-Disruption Deployment Full app risk monitoring without additional apps or agents on devices — fast rollout, no user friction. Compliance & Security Alignment Supports enforcement of mobile security and privacy requirements for GDPR, HIPAA, MASVS, and Zero Trust models. Building on app-specific threat intelligence, the integration will soon enable secure distribution of applications based on behavioral anomaly analysis. Additionally, upcoming enhancements will support automated policy enforcement, allowing Hexnode to trigger automated actions such as blocking or flagging high-risk apps identified by Quokka. "This integration is a major step forward in securing enterprise mobility," said Paul Hettesheimer, VP Enterprise Sales (US) at Hexnode. "By combining Hexnode's robust application management with Quokka's real-time app risk intelligence, we're enabling organizations to proactively defend against mobile threats, without adding complexity or disrupting the user experience." Upcoming Events To get an exclusive first look at how Quokka and Hexnode are joining forces to close mobile security gaps, register for Hexnode Live, taking place on August 19, 2025 >>> Additionally, with Black Hat US 2025 just a few days away, meet the Hexnode team at Booth 1360, on August 6-7 in Las Vegas. Gartner Attributions and Disclaimer Gartner, How to Avoid Common Cybersecurity Pitfalls in Mobile App Development, Dionisio Zumerle, 16 July 2025 Gartner is a registered trademark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved. About Quokka Quokka, a mobile security company, delivers Mobile Application Risk Intelligence trusted by the Fortune 500 and governments worldwide. Formerly known as Kryptowire, the company was founded in 2011 and is the first and longest-standing mobile security solution for the US Federal Government. Bringing visibility to one of the most overlooked and least understood areas of an organization's risk, Quokka helps security teams and developers uncover hidden risks in mobile apps. Utilizing ML-based behavioral analysis, Quokka reveals what apps actually do, going beyond surface scanning and static code analysis. From threat hunting and app vetting to compliance reviews and developer feedback, Quokka powers informed decisions across the mobile ecosystem. For more information, please visit About Hexnode Hexnode, an award-winning cloud-based Unified Endpoint Management (UEM) solution from Mitsogo Inc., is committed to helping businesses efficiently manage their device fleets. Recognizing the importance of corporate data and the rise of BYODs, COPEs, and COBOs, Hexnode strives to introduce intelligent technologies to safeguard devices against threats and theft. It offers comprehensive endpoint management solutions compatible with major platforms, including Android, Windows, Linux, iOS, macOS, ChromeOS, Fire OS, vision OS, and tvOS. The platform offers a free trial for those interested in exploring its capabilities. For more information, please visit View source version on Contacts Elizabeth Haleliz@ +1-415-510-2128 Sign in to access your portfolio


Business Wire
10 minutes ago
- Business Wire
Avangrid, Tyba Complete Pilot to Advance Battery Energy Storage Systems
ORANGE, Conn.--(BUSINESS WIRE)--Avangrid, Inc., a leading energy company and member of the Iberdrola Group, today announced it has successfully completed a strategic pilot project with Tyba, an energy analytics and optimization platform, to enhance its battery energy storage system (BESS) modeling and identify potential locations for siting storage infrastructure across U.S. power markets. The initiative was designed to support Avangrid's evaluation of standalone and hybrid storage assets, improve revenue forecasting, and build internal expertise in the rapidly evolving U.S. storage landscape. 'As energy demand continues to surge across the country, battery storage will become increasingly critical for reliable energy supply,' said Avangrid CEO Jose Antonio Miranda. 'This pilot project with Tyba is just one example of Avangrid's approach to investing in innovative and forward-thinking solutions that enhance our own operations while helping the U.S. meet its energy needs.' 'It has been great to partner with Avangrid as they advance their efforts in the energy storage sector," said Tom Thunell, Tyba's Co-Founder and COO. "When honing an energy storage investment case, it is critical to understand how the battery will get its revenue. Tyba's platform simulates battery operations – informed by experience optimizing over 2GWh of operating storage – to demonstrate not only how much a project may return, but how it will operate to achieve those outcomes.' Throughout the pilot, Avangrid´s teams collaborated closely with Tyba through weekly working sessions and engagement. The project focused on leveraging Tyba's platform to simulate BESS operations across approximately 2,400 locations in seven U.S. regional grid operators and independent system operators. A key innovation in the pilot was the use of new pricing metrics to estimate battery energy storage systems revenue between the highest and lowest electricity prices each day. Tyba's platform enabled Avangrid analysts to screen for price volatility and identify the best locations for siting projects. This provided Avangrid with an enhanced understanding of where battery energy storage systems could provide the greatest return on investment. Tyba's software also allowed Avangrid to simulate BESS operations under different market conditions, using both past and projected electricity prices. It allowed Avangrid to fine-tune battery charging and discharging strategies in real-time, day-ahead, and ancillary services (back-up power) markets, and run hundreds of stimulations tailored to each regional grid operator. Avangrid is constantly evaluating opportunities to meet customer needs by incorporating energy storage into future projects as a key component of its comprehensive, cost-effective energy solutions. About Tyba: Tyba helps energy companies maximize the profitability of energy projects with a unified simulation and operations platform. Developers, owners, and operators use Tyba as their mission control center - to inform and automate energy storage operations, while maintaining the ability to make strategy adjustments with the click of a button. This approach helps their partners maximize project revenue and sustainably scale their portfolios. We believe that profitable renewable energy investments are essential to ensure the clean energy transition. With Tyba, profit maximization and grid decarbonization go hand-in-hand. About Avangrid: Avangrid, Inc. is a leading energy company in the United States working to meet the growing demand for energy for homes and businesses across the nation through service, innovation, and continued investments by expanding grid infrastructure and energy generation projects. Avangrid has offices in Connecticut, New York, Massachusetts, Maine, and Oregon, including operations in 23 states with approximately $48 billion in assets, and has two primary lines of business: networks and power. Through its networks business, Avangrid owns and operates eight electric and natural gas utilities, serving more than 3.4 million customers in New York and New England. Through its power generation business, Avangrid owns and operates more than 75 energy generation facilities across the United States producing 10.5 GW of power for over 3.1 million customers. Avangrid employs approximately 8,000 people and has been recognized by JUST Capital as one of the JUST 100 companies – a ranking of America's best corporate citizens in 2025 for the fifth consecutive year. The company was named among the World's Most Ethical Companies in 2025 for the seventh consecutive year by the Ethisphere Institute. Avangrid is a member of the group of companies controlled by Iberdrola, S.A. For more information, visit


Business Wire
10 minutes ago
- Business Wire
Hexnode UEM Partners With Quokka to Double Down on Mobile App Security for Businesses
SAN FRANCISCO--(BUSINESS WIRE)-- Hexnode, the enterprise software division of Mitsogo Inc., has announced a strategic integration with Quokka, a leader in mobile app risk intelligence. This collaboration, now available for Android and iOS devices, enables organizations to manage their mobile applications via Hexnode, while leveraging Quokka's capabilities to continuously assess mobile apps for malicious behavior, security vulnerabilities, and privacy risks. Join Hexnode at Booth 1360 during Black Hat USA 2025 in Las Vegas on August 6–7, and stay informed with Hexnode Live on August 19 for key updates on the strategic Hexnode–Quokka partnership. "Hexnode has built a powerful, intuitive platform for managing mobile devices at scale," said Vijay Pawar, Senior Vice President of Product at Quokka. "By integrating Quokka's mobile app risk intelligence, we're able to instantly deliver continuous app risk monitoring at scale. Together, we're giving customers an integrated solution that closes the mobile app security gap." The growing prevalence in sideloaded, unauthorized apps and the lack of centralized app vetting have contributed to a global surge in mobile malware infections. A 2024 report by Recorded Future highlighted how infostealer malware embedded in mobile apps was used to steal credentials and bypass enterprise security systems. Further, according to the Gartner® report, 'Through 2030, mobile application security failures will be the biggest mobile threat for enterprises.' Hexnode's integration with Quokka addresses these challenges by integrating Quokka's mobile app risk intelligence directly into the Hexnode environment, closing the mobile app security gap and delivering a comprehensive, end-to-end mobile security solution. Key Capabilities of the Integration App Behaviour Monitoring Detects data exfiltration, app collusion, and malicious activity within the app repository. Agentless, Zero-Disruption Deployment Full app risk monitoring without additional apps or agents on devices — fast rollout, no user friction. Compliance & Security Alignment Supports enforcement of mobile security and privacy requirements for GDPR, HIPAA, MASVS, and Zero Trust models. Building on app-specific threat intelligence, the integration will soon enable secure distribution of applications based on behavioral anomaly analysis. Additionally, upcoming enhancements will support automated policy enforcement, allowing Hexnode to trigger automated actions such as blocking or flagging high-risk apps identified by Quokka. 'This integration is a major step forward in securing enterprise mobility,' said Paul Hettesheimer, VP Enterprise Sales (US) at Hexnode. 'By combining Hexnode's robust application management with Quokka's real-time app risk intelligence, we're enabling organizations to proactively defend against mobile threats, without adding complexity or disrupting the user experience.' Upcoming Events To get an exclusive first look at how Quokka and Hexnode are joining forces to close mobile security gaps, register for Hexnode Live, taking place on August 19, 2025 >>> Additionally, with Black Hat US 2025 just a few days away, meet the Hexnode team at Booth 1360, on August 6-7 in Las Vegas. Gartner Attributions and Disclaimer Gartner, How to Avoid Common Cybersecurity Pitfalls in Mobile App Development, Dionisio Zumerle, 16 July 2025 Gartner is a registered trademark of Gartner, Inc. and/or its affiliates and is used herein with permission. All rights reserved. About Quokka Quokka, a mobile security company, delivers Mobile Application Risk Intelligence trusted by the Fortune 500 and governments worldwide. Formerly known as Kryptowire, the company was founded in 2011 and is the first and longest-standing mobile security solution for the US Federal Government. Bringing visibility to one of the most overlooked and least understood areas of an organization's risk, Quokka helps security teams and developers uncover hidden risks in mobile apps. Utilizing ML-based behavioral analysis, Quokka reveals what apps actually do, going beyond surface scanning and static code analysis. From threat hunting and app vetting to compliance reviews and developer feedback, Quokka powers informed decisions across the mobile ecosystem. For more information, please visit About Hexnode Hexnode, an award-winning cloud-based Unified Endpoint Management (UEM) solution from Mitsogo Inc., is committed to helping businesses efficiently manage their device fleets. Recognizing the importance of corporate data and the rise of BYODs, COPEs, and COBOs, Hexnode strives to introduce intelligent technologies to safeguard devices against threats and theft. It offers comprehensive endpoint management solutions compatible with major platforms, including Android, Windows, Linux, iOS, macOS, ChromeOS, Fire OS, vision OS, and tvOS. The platform offers a free trial for those interested in exploring its capabilities. For more information, please visit