54% of attacks observed related to security misconfigurations (API8), while 27% related to broken object-level authorization (API1). In contrast, vulnerabilities such as broken user authentication (API2) and security monitoring and logging failures (API7) only relate to 1% of attacks.
| Publisher | Salt Security |
| Report | API Security Trends 2025 |
| Published | 1 February 2025 |
Published by Salt Security in API Security Trends 2025 , 1 February 2025. The figure is taken from the report as published; the full methodology is in the source.