Habr•September 15, 2026•🇷🇺Translated from Russian

How Modern API Attacks Abuse Legitimate Functionality Instead of Exploiting Vulnerabilities

Just a few years ago, most API-related incidents followed a predictable pattern. When an application began behaving suspiciously, specialists looked for authorization errors, access control problems, signs of SQL injections, or attempts to exploit known vulnerabilities. The logic was straightforward: vulnerability exists, exploitation occurs, consequences follow.

Today, the NGENIX service support team increasingly encounters situations that do not fit this model. Services start responding more slowly, database load increases, users report errors during order placement, and certain operations take significantly longer than usual. WAF blocks nothing, and logs show neither breach indicators nor vulnerability exploitation attempts. At first glance the issue may appear internal, yet analysis reveals the system is operating exactly as instructed. The API is simply being used in ways developers never anticipated.

Most web traffic now flows through APIs, and attack volumes are rising accordingly. A substantial portion of current malicious activity does not involve exploiting vulnerabilities at all. Attackers often need only to invoke existing API functionality, pass legitimate authorization, and operate within normal business processes. The difference becomes visible only when analysts examine the client’s overall behavior rather than isolated requests.

Why WAF Often Fails to Stop Modern API Attacks

Attackers no longer need to locate a code flaw or bypass protection mechanisms. They can use the API exactly as the system permits, but at a scale or according to a scenario never envisioned by developers. Each request therefore looks correct: allowed methods, valid authorization, and proper parameters. No exploit signatures appear in the traffic.

WAF solutions analyze individual request content for known attack techniques such as injections or authorization bypasses. When a request matches the API specification and contains no malicious payload, the WAF has no reason to block it. Modern attacks are defined by behavior across sequences of calls, frequency patterns, and the ultimate goal of interaction with the system.

Burst Attacks: Overloading the Most Resource-Intensive Endpoints

Burst attacks consist of short, extremely intensive spikes aimed at specific, computationally expensive API methods. A single such request may trigger complex catalog searches, multiple database table accesses, internal service calls, and cache operations. Several hundred requests to a heavy endpoint can generate more load than thousands of simple queries. Unlike classic DDoS attacks, these campaigns do not require massive traffic volumes; they simply concentrate on the most expensive part of the application.

Fixed time-window rate limits often prove inadequate. Too lenient and they fail to stop the attack; too strict and they disrupt legitimate users during sales or marketing events. Modern systems therefore favor sliding-window mechanisms that evaluate activity across a continuous time range and handle short bursts more effectively.

Shortwave Attacks: Timed Requests Targeting Race Conditions

Shortwave attacks use brief pulses of requests separated by deliberate pauses. Traffic volume stays within normal limits and rate limits are not exceeded, so monitoring systems see nothing unusual. The objective is usually to trigger a race condition in business logic. Multiple simultaneous requests may each pass an availability check before any of them records the result, allowing the same limited resource, such as a promotional code, to be applied more than once.

The same technique can affect bonus accrual, inventory reservation, ticket booking, and any operation where concurrent requests modify a shared resource. Each individual request remains fully legitimate, making detection at the single-request level nearly impossible.

Carpet Bombing: Distributed Probing Across Many Endpoints

Carpet Bombing spreads activity across dozens or hundreds of API methods instead of concentrating on one endpoint. One portion of requests may query the product catalog, another the search function, a third inventory levels, and so on. No single endpoint shows anomalous load, yet the overall pattern reveals systematic reconnaissance of application structure and business logic.

Common examples include automated scraping of pricing and stock data and scalping of limited resources such as airline seats. On some airline booking sites, automated systems account for up to 45 percent of traffic, much of it undesirable. The result for users is an apparently overloaded service; for the business it means occupied resources without completed purchases.

Because modern bots use valid tokens, follow realistic user flows, and stay within obvious limits, distinguishing them from genuine users by request content alone is extremely difficult. Protection must therefore move from analyzing individual requests to evaluating the intent and behavioral similarity to real users.

Related articles

Hispasec•Vulnerabilities & Exploits

Critical CVE-2026-61500 in Rejetto HFS Allows Admin Session Forgery Leading to Remote Code Execution

A critical vulnerability tracked as CVE-2026-61500 is being actively exploited in Rejetto HTTP File Server (HFS), enabling unauthenticated attackers to forge administrator sessions and achieve remote code execution. The flaw impacts versions 3.0.0 through 3.2.0 and was addressed in release 3.2.1, making immediate updates essential for any internet-exposed instances. The root cause lies in the use of JavaScript Math.random() to generate the session cookie signing key instead of a cryptographically secure random number generator. Attackers can reconstruct the internal state of this weak PRNG from login responses, allowing them to create valid admin cookies. Once authenticated as an administrator, the attacker can abuse the server_code functionality to execute arbitrary JavaScript on the server. Exploitation activity was first observed on October 1, 2026, targeting U.S. systems and attributed to an unidentified actor based in China, following the public release of a Python proof-of-concept in late September.

BoletimSec•Vulnerabilities & Exploits

Dell Patches Six Critical Flaws in Container Storage Modules for Kubernetes

Dell has fixed six vulnerabilities in its Container Storage Modules that integrate storage systems with Kubernetes clusters. Two of the issues received the maximum CVSS score of 10.0, allowing remote unauthenticated attackers to obtain full administrative credentials for registered storage backends. Additional flaws enable privilege escalation to root on cluster nodes, exposure of hardcoded credentials, and leakage of Kubernetes secrets across the entire cluster. All versions prior to 1.17.0 are affected, with the fixes delivered in version 1.18.0. No workarounds exist, and Dell recommends rotating JWT signing keys after applying the update because the previous keys must be considered compromised.

Security NEXT•Vulnerabilities & Exploits

Critical Sandbox Bypass Flaw in GitLab AI Gateway Enables Remote Command Execution

GitLab has released patches for a critical vulnerability in its GitLab AI Gateway component that allows authenticated users to bypass sandbox restrictions and execute arbitrary commands. The flaw, tracked as CVE-2026-90970, resides in the custom flow prompt template processing of the Duo Agent Platform and carries a CVSS v3.1 base score of 9.9. Self-hosted deployments are affected, while GitLab’s own hosted AI Gateway service has already been updated. The company urges immediate upgrades to versions 19.4.1, 19.3.2, or 19.2.4. The vulnerability can be triggered under specific conditions by users with access to the Duo Agent Platform through crafted flow configurations.

Security NEXT•Vulnerabilities & Exploits

WebPros Releases Critical Patches for Three Vulnerabilities in cPanel & WHM

WebPros International has published security updates addressing three critical vulnerabilities in its cPanel & WHM hosting management platform. All three issues received the highest severity rating of Critical. The flaws include CVE-2026-93698, an input validation weakness in the Multilang adminbin component that could allow root-level operating system command execution. Two additional stored cross-site scripting vulnerabilities were also fixed, one of which is CVE-2026-93697 affecting the Mass Modify Accounts interface in WHM. Successful exploitation of the XSS flaws could let low-privileged accounts hijack administrator sessions. The updates were made available on September 29, 2026, and carry CVSS v3.0 base scores reaching 9.9.