DigitalCIO
No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
DigitalCIO
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
No Result
View All Result
Digitalcio
No Result
View All Result
Home News

Bad bots use residential IPs to appear human and evade defenses: Barracuda

DigitalCIO Bureau by DigitalCIO Bureau
October 25, 2023
in News, Security
0
Bad bots use residential IPs to appear human and evade defenses: Barracuda
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

Barracuda has unveiled a new Threat Spotlight that shows how in the first six months of 2023, bad – or malicious – bots used residential IP addresses to launch attacks without being caught by the security blocks put on known malicious IPs. In many cases, the people who used or were later allocated those IPs ended up in “CAPTCHA hell,” unable to pass checks from Google or Cloudflare because their IP triggered a red flag as having been used for malicious activity.

Bots are software programs that move around the web performing automated tasks like search engine crawling. Barracuda researchers track the prevalence and behavior of good and bad bots from year to year.

Data for the first half of 2023 shows that nearly half (48%) of total global internet traffic was made up of bots, and most of this was down to bad bots. These complex computer programs are designed to cause mischief and harm, at speeds and volumes that human attackers couldn’t match.

And while in 2021, the bad bot landscape was dominated by swarms of “retail bots,” sent out to hunt for scarce and sought-after sneakers and toys to resell at a profit, in 2023, bad bots are often being used for more advanced attacks.

Armed with millions of common username and passwords, the bad bots are being sent out across the internet with the aim of compromising email accounts – particularly those they can reach through vulnerable application programming interfaces (APIs) – by bashing them with countless combinations of usernames/passwords until they get the one that works.

APIs are a growing target for cyberattack because they are relatively under-protected and used extensively for automated processes and communications. Examples of applications that use APIs to access emails and inboxes include email marketing applications that send and track bulk or personalized emails to potential or existing customers, as well as applications to manage, verify and automate emails.

“For the organizations targeted by these bots, a combination of under-secured APIs, weak authentication and access policies, and a lack of bot-specific security measures – such as limiting the volume and speed of inbound traffic leave them vulnerable to attack,” said Tushar Richabadas, Principal Product Marketing Manager, Applications and Cloud Security at Barracuda. “Organizations can be overwhelmed due to the sheer number of solutions required to stop bots, but the good news is that solutions are consolidating into Web Application and API Protection (WAAP) services that identifies and stops bad bots.”

The research also shows that in the first half of 2023, North America was the source of 72% of bad bot traffic. Roughly two-thirds (67%) of bad bot traffic came from hosting providers, including the two large public clouds: AWS and Azure, which skews the geographic data toward North America. The next most prevalent regions are the United Arab Emirates (12%), Saudi Arabia (6%), Qatar (5%), and India (5%).

Tags: BarracudaCAPTCHAThreat
Share30Tweet19
DigitalCIO Bureau

DigitalCIO Bureau

Recommended For You

Serious vulnerability in MongoDB makes cloud environments vulnerable

by DigitalCIO Bureau
December 29, 2025
0
Automated Breach And Attack Simulation – Can You Deny Its Relevance?

A serious security vulnerability in MongoDB, designated CVE-2025-14847 and nicknamed MongoBleed, allows attackers to extract sensitive data from the working memory of vulnerable systems without authentication. The vulnerability...

Read moreDetails

Cybercrime Will Become Increasingly Automated in 2026

by DigitalCIO Bureau
December 2, 2025
0
Trend Micro Named a Leader in Attack Surface Management in New Report

Trend Micro has released its annual Security Predictions Report for 2026, warning that the coming year will mark the true industrialization of cybercrime. Artificial intelligence (AI) and automation are now...

Read moreDetails

ESET Discovers Chinese PlushDaemon Group Compromises Network Devices

by DigitalCIO Bureau
November 24, 2025
0
ESET Discovers Chinese PlushDaemon Group Compromises Network Devices

ESET researchers discovered that China-aligned threat group PlushDaemon performs adversary-in-the-middle attacks using a previously undocumented implant for network devices (e.g., a router) that ESET named EdgeStepper, which redirects...

Read moreDetails

Salesforce Blocks Gainsight Apps After Detecting Suspicious Activity

by DigitalCIO Bureau
November 24, 2025
0
Salesforce Acquires AI Customer Service Startup Airkit.ai

CRM giant Salesforce has immediately blocked access to applications from software vendor Gainsight after detecting "unusual activity." The incident may have led to unauthorized access to customer data...

Read moreDetails

WatchGuard Introduces FireCloud Total Access

by DigitalCIO Bureau
September 29, 2025
0
Gartner: Adoption of GenAI To Collapse Cybersecurity Skills Gap

WatchGuard Technologies has announced FireCloud Total Access, the first hybrid secure access service edge (SASE) that breaks through the enterprise-only model and makes zero trust and cloud-delivered security practical...

Read moreDetails
Next Post
Lenovo Unveils ‘AI For All’ Strategy At Tech World Event

Lenovo Unveils ‘AI For All’ Strategy At Tech World Event

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

OurCrowd AI Fund to Collaborate with NVIDIA Inception

OurCrowd AI Fund to Collaborate with NVIDIA Inception

March 6, 2024

Microsoft to invest $75mn in creating 1,500 jobs in AI, Cloud

May 18, 2020
GajShield Infotech unleashes the power of AI to safeguard against dynamic cyber threat

GajShield Infotech unleashes the power of AI to safeguard against dynamic cyber threat

February 16, 2024

Browse by Category

  • Acquisition
  • Appointment
  • Archive
  • Artificial Intelligence
  • CIO Interviews
  • Cloud
  • Datacenter
  • Events and Conferences
  • Market Insights
  • News
  • Opinion and Analysis
  • Products
  • Resources
  • Security
  • Storage
  • Tech News
  • Telecom
Digitalcio

Welcome to DigitalCIO, your ultimate source for staying ahead in the ever-evolving world of technology and business.

BROWSE BY TAG

Acquisition AI Appointment artificial intelligence Artificial Intelligence and Machine Learning AWS Barracuda Big Data and Analytics Blockchain CISCO Cloud Computing Cloudflare Commvault CrowdStrike Cybersecurity Digital Transformation Dynatrace E-books Fortinet Gartner GenAI Generative AI Google Cloud IBM Infographics Internet of Things (IoT) Kaspersky Microsoft New Relic NTT DATA NVIDIA Palo Alto Networks Panel Discussion Qlik Salesforce ServiceNow Sophos Tenable Trend Micro Veeam Veeam Software Vertiv Webinars Whitepaper Zscaler

CATEGORIES

  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources
  • Archive

NAVIGATION

  • Home
  • About Us
  • Advertise with Us
  • Contact Us

© 2024 digitalcio.in - All rights reserved.

No Result
View All Result
  • Home
  • Tech News
  • Market Insights
  • CIO Interviews
  • Events and Conferences
  • Opinion and Analysis
  • Resources

© 2024 digitalcio.in - All rights reserved.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?