Recent research from Bugcrowd has revealed a dramatic increase in hardware, API, and network vulnerabilities, prompting cybersecurity professionals to reevaluate their defense strategies. The proliferation of Internet of Things (IoT) devices has contributed to an 88% rise in hardware vulnerabilities, as more organizations deploy connected sensors, appliances, and medical equipment. Security researchers have reported that 81% discovered new hardware flaws over the past year, highlighting the scale of the problem. Network vulnerabilities have doubled, and API bugs have increased by 10%, further expanding the attack surface for enterprises. Critical vulnerabilities, particularly those involving broken access control and sensitive data exposure, have seen significant growth, with payouts for these flaws rising by 32%. Broken access control alone has increased by 36%, while sensitive data exposure vulnerabilities have grown by 42%, underscoring persistent foundational security issues. The rapid adoption of AI-assisted software development is accelerating release cycles but also introducing new security gaps, especially in access control and data protection. As applications become more complex and agentic AI systems gain autonomy, managing access control becomes increasingly challenging. IoT security remains a major concern, as many devices are not designed to receive timely vulnerability patches or updates, leaving them exposed to attacks such as distributed denial-of-service (DDoS) and data theft. Attackers are exploiting the remote control capabilities of IoT devices, targeting everything from smart office lighting to advanced medical equipment and agricultural machinery. Efforts to improve IoT security include legislative initiatives and voluntary programs like the US Cyber Trust Mark, which aims to encourage device-makers to adopt better security practices. However, progress on these initiatives has been slow, and it remains uncertain when or if they will have a significant impact. The expanding use of nonhuman identities, such as API keys and machine accounts, further complicates the security landscape, as these digital identities often have broad access and are difficult to monitor. Security leaders are increasingly aware that agentic AI and the growing complexity of interconnected systems are likely to accelerate existing vulnerability trends. As a result, organizations are being urged to rethink their security strategies, focusing on foundational issues like access control, data protection, and the secure management of digital identities. The convergence of these trends signals a need for more robust, adaptive, and proactive security measures to address the evolving threat landscape.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Industry commentary accompanying the research said broken access control remains the top vulnerability category and warned that agentic AI, faster release cycles, and constrained budgets are making traditional defense approaches less effective. The analysis argues CISOs are being pushed toward more agile, business-aligned, and continuously offensive security strategies.
Bugcrowd research found an 88% increase in hardware vulnerabilities, network vulnerabilities roughly doubling, and API bugs rising 10% over the past year. The report links the expanding attack surface in part to growth in IoT and AI-assisted software development, and notes a 32% increase in payouts for critical issues.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.