{"id":7916,"date":"2026-05-19T16:30:00","date_gmt":"2026-05-19T14:30:00","guid":{"rendered":"http:\/\/stocks-future.com\/?guid=d01ba09a1ec6c0f3f95c85a204a28920"},"modified":"2026-05-19T16:30:00","modified_gmt":"2026-05-19T14:30:00","slug":"agentic-ai-is-accelerating-how-software-gets-built-and-how-it-gets-attacked-most-enterprises-are-only-ready-for-one-according-to-digital-ais-2026-appsec-threat-report","status":"publish","type":"post","link":"https:\/\/stocks-future.com\/?p=7916","title":{"rendered":"Agentic AI Is Accelerating How Software Gets Built and How It Gets Attacked. Most Enterprises Are Only Ready for One, According to Digital.ai\u2019s 2026 AppSec Threat Report"},"content":{"rendered":"<p>\n<i>New data finds 87% of monitored client-facing apps faced attacks in 2026 \u2014 up from 55% in 2022 \u2014 as AI permanently collapses the cost and expertise required to exploit them<\/i><\/p><br\/><a href=\"https:\/\/mms.businesswire.com\/media\/20260519967565\/en\/1717137\/5\/Logo-Digital_ai-FC-RGB-3x.jpg\"><img src=\"https:\/\/mms.businesswire.com\/media\/20260519967565\/en\/1717137\/22\/Logo-Digital_ai-FC-RGB-3x.jpg\" \/><\/a><br\/><a href=\"https:\/\/mms.businesswire.com\/media\/20260519967565\/en\/1717137\/5\/Logo-Digital_ai-FC-RGB-3x.jpg\"><img src=\"https:\/\/mms.businesswire.com\/media\/20260519967565\/en\/1717137\/21\/Logo-Digital_ai-FC-RGB-3x.jpg\" \/><\/a><p>\n<i>iOS and Android attack rates have converged for the first time \u2014 closing a 21-point gap and invalidating a decade of platform-based security assumptions<\/i><\/p><p>RALEIGH, N.C.--(BUSINESS WIRE)--AI has created two simultaneous acceleration curves in enterprise software: one for building it and one for attacking it. For most software teams, publishing an app to the App Store or Google Play still feels like a product milestone. In 2026, it is a security exposure event.<\/p><p>\n<a  href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=http%3A%2F%2Fdigital.ai&amp;esheet=54537971&amp;newsitemid=20260519967565&amp;lan=en-US&amp;anchor=Digital.ai%26%238217%3Bs+2026+Application+Security+Threat+Report&amp;index=1&amp;md5=f9bbb33dc5ce022fced40d527a5a7eae\" rel=\"nofollow\" shape=\"rect\">Digital.ai\u2019s 2026 Application Security Threat Report<\/a> draws on real-time threat monitoring data from applications serving billions of consumers across financial services, healthcare, automotive, and telecommunications. The report finds that as AI tools accelerate application development and shipping, attackers are using the same capabilities to move faster, causing the window between app store publication and first hostile contact to disappear.<\/p><p>\nAnother key finding cuts to the root cause: agentic AI has reset the economics of software attacks. The skill, time, and cost barriers that once limited sophisticated attacks have collapsed. Activities that once required specialized security expertise, custom tooling, and days of manual effort can now be accomplished through AI-assisted code inspection, exploit generation, and malware adaptation in a fraction of the time.<\/p><p>\nThe five-year attack rate trajectory makes the correlation visible. The 55% \u2192 57% \u2192 65% \u2192 82.7% \u2192 87% climb \u2014 tracking closely alongside each major AI model release since 2022 \u2014 suggests the industry has crossed a threshold. The question now is not whether agentic AI-powered attacks will keep climbing; it is whether enterprises will invest in defending against them at the same pace.<\/p><p>\n<b>The Attack Surface Enterprises Left Exposed<\/b><\/p><p>\nOne enterprise customer monitoring their application in production observed hostile activity less than two hours after their app appeared in the store, a timeline consistent with what Digital.ai\u2019s broader threat telemetry shows. The window between app publication and first hostile contact is now measured in hours, not days.<\/p><p>\nMobile applications have become a primary attack surface in the enterprise portfolio \u2014 and the most exposed to the new attacker capabilities that AI has unlocked. The applications that enterprises distribute directly into the hands of billions of customers exist outside the enterprise firewall. They live on devices the security team does not control, in public marketplaces on the open internet. When an attacker compromises a mobile app, the app is not the destination; it is the entry point. Reverse engineering a mobile application gives an attacker a blueprint to the backend APIs, authentication logic, and server infrastructure that power it \u2014 the same infrastructure protecting customer data, transactions, and core business operations.<\/p><p>\nA companion finding puts a finer point on where the underinvestment is showing up.<\/p><p>\n<b>The iOS Budget Assumption Has Expired<\/b><\/p><p>\nIn 2023, iOS apps faced roughly half the attack rate of Android apps, a gap that justified significantly lower security investment on Apple\u2019s platform. In 2026, iOS apps were attacked at an 86% rate, compared to 89% for Android. This gap, which once stood at 21 percentage points, has now effectively closed. iOS instrumentation attacks alone jumped 10 percentage points in a single year, as AI-assisted dynamic analysis tooling matured into a mainstream attacker capability.<\/p><p>\niOS has always been harder to attack but is no longer the deciding factor in target selection. AI-assisted reverse engineering absorbs what complexity remains. Enterprise AppSec budget allocations that still reflect a 2-to-1 Android-to-iOS threat assumption are now misaligned with the data.<\/p><p>\n<b>The Number That Matter<\/b><\/p><ul class=\"bwlistdisc\">\n<li>\n87% of monitored mobile applications faced attacks in 2026, up from 55% in 2022 \u2014 a 58% climb that maps closely alongside every major AI model release since ChatGPT launched in November 2022<\/li>\n<li>\nThe reason: agentic AI has collapsed the cost and skill floor of attacking software. What once required a specialist team and weeks of work now takes an afternoon and an LLM subscription<\/li>\n<li>\nFinancial services apps hit a 2026 attack rate of 91% \u2014 the highest ever recorded for any vertical in the report's history<\/li>\n<li>\nAutomotive apps reached 91% \u2014 statistically identical to financial services \u2014 as connected vehicle apps became primary control surfaces for assets worth tens of thousands of dollars<\/li>\n<li>\nMedical device apps recorded the largest single-year jump of any named vertical \u2014 8 percentage points, from 78% to 86%. A compromised medical device app raises possible consequences far beyond a typical data breach. It is a potential pathway to patient harm.<\/li>\n<li>\niOS apps were attacked at an 86% rate in 2026, compared to 89% for Android \u2014 closing a gap that once stood at 21 percentage points and invalidating the budget assumptions that gap justified<\/li>\n<li>\niOS instrumentation attacks jumped 10 percentage points in a single year. This is the sharpest single-year move recorded for any attack type on either platform and a direct signal that AppSec budgets still favoring Android over iOS are misaligned with the data<\/li>\n<\/ul><p>\n\"The same AI your developers used to build your app this morning is being used to attack it this afternoon. That forces a question every AppSec team needs to answer: is the application built to defend itself from the moment it hits the store? Or is it waiting for the security team to notice it is being used as the entry point? In an environment where 87% of monitored apps are under attack, waiting is not a strategy,\" said Derek Holt, CEO, Digital.ai. \"The gap between where the attacks are and where the security investment is, is no longer acceptable.\"<\/p><p>\nTo read the full report, visit <a  href=\"https:\/\/cts.businesswire.com\/ct\/CT?id=smartlink&amp;url=https%3A%2F%2Fdigital.ai%2Fresource-center%2Fwhitepapers%2F2026-application-security-threat-report%2F%3Futm_source%3Dpress%26utm_medium%3Dreferral%26utm_campaign%3DWC-AS-2026_05_19-WW-WP-%255B2026%2520App%2520Threat%2520Report%255D&amp;esheet=54537971&amp;newsitemid=20260519967565&amp;lan=en-US&amp;anchor=Digital.ai&amp;index=2&amp;md5=2ffcf9f0a58a2a92cf481d8baf2d3b38\" rel=\"nofollow\" shape=\"rect\">Digital.ai<\/a>.<\/p><p>\n<b>About the Report<\/b><\/p><p>\nThe Digital.ai 2026 Application Security Threat Report is based on real-time threat telemetry collected from monitored applications serving billions of end users across financial services, healthcare, automotive, telecommunications, and other regulated industries globally. The data was collected across billions of application instances during Q4 2025.<\/p><p>\nMost published threat intelligence in application security describes server-side attacks, network activity, or post-incident forensics. This report describes something different \u2014 client-side and runtime attacks observed against applications running in production, in the wild, on devices and networks outside enterprise control. Digital.ai operates the largest application hardening telemetry footprint in the industry, with roots tracing to the original commercial application of anti-tampering technology developed at Purdue University in 2001. The dataset behind this report is not derivable from public sources, vendor surveys, or threat intelligence feeds.<\/p><p>\n<b>About Digital.ai<\/b><\/p><p>\nDigital.ai enables the world\u2019s most complex organizations to deliver trusted software at AI speed. By applying agentic AI across the critical stages of software delivery \u2014 from planning through security, testing, and delivery \u2014 Digital.ai helps enterprises remove bottlenecks, reduce risk, and improve the flow of software value to production. Its solutions integrate into existing environments, allowing organizations to transform to AI-first without disruption. Today, 53% of the Fortune 100 trust Digital.ai to make that happen.<\/p><p>\n<b><i>Forward-Looking Statements<\/i><\/b><\/p><p>\n<i>This release contains forward-looking statements about the application security threat environment, Digital.ai's products and capabilities, and the actions enterprises may take in response. These statements reflect Digital.ai's current expectations and are subject to risks and uncertainties that could cause actual results to differ materially. Digital.ai undertakes no obligation to update any forward-looking statement. Figures cited in this release reflect threat telemetry collected during Q4 2025 and reported in the 2026 edition of the Threat Report; see the Methodology section of the full Report for details on dataset scope and year-over-year comparability. Third-party names and marks referenced are the property of their respective owners.<\/i><\/p><br\/> <b>Contacts<\/b> <br\/><p>\n<b>Media:<\/b><br\/><b>Colleen Martin<\/b><br\/><b>Zer0 to 5ive, for Digital.ai<\/b><br\/><b><a  href=\"mailto:colleen@0to5.com\" rel=\"nofollow\" shape=\"rect\">colleen@0to5.com<\/a><\/b><\/p>","protected":false},"excerpt":{"rendered":"<p>New data finds 87% of monitored client-facing apps faced attacks in 2026 \u2014 up from 55% in 2022 \u2014 as AI permanently collapses the cost and expertise required to exploit them<br \/>\niOS and Android attack rates have converged for the first time \u2014 closing a 21-&#8230;<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-7916","post","type-post","status-publish","format-standard","hentry","category-infos-businesswire"],"_links":{"self":[{"href":"https:\/\/stocks-future.com\/index.php?rest_route=\/wp\/v2\/posts\/7916","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/stocks-future.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/stocks-future.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/stocks-future.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/stocks-future.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=7916"}],"version-history":[{"count":1,"href":"https:\/\/stocks-future.com\/index.php?rest_route=\/wp\/v2\/posts\/7916\/revisions"}],"predecessor-version":[{"id":7917,"href":"https:\/\/stocks-future.com\/index.php?rest_route=\/wp\/v2\/posts\/7916\/revisions\/7917"}],"wp:attachment":[{"href":"https:\/\/stocks-future.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=7916"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/stocks-future.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=7916"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/stocks-future.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=7916"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}