

Lights out for Lumma.
May 22, 2025
David Holmes, CTO for Application Security at Imperva, shares his expertise on the surge of AI in bot attacks. The conversation dives into the dismantling of Lumma's malicious infrastructure and the alarming rise in automated attacks. Holmes highlights critical vulnerabilities, like those affecting Lexmark printers, and discusses the evolving tactics of cybercriminals. He emphasizes the pressing need for enhanced security measures and the role of AI in combating these sophisticated threats. Tune in for insights that every cybersecurity enthusiast won't want to miss!
AI Snips
Chapters
Transcript
Episode notes
Automated Bots Surpass Humans
- In 2024, automated bot traffic exceeded human web traffic for the first time, with 51% of all traffic being automated.
- Among this, 37% of all traffic was malicious, meaning about 80% of automated traffic is harmful bots.
AI's Dual Role in Bot Attacks
- AI helps craft both very simple self-identified bots for beginners and highly sophisticated bots for advanced attackers.
- About 45% of malicious bots are simple and 45% are advanced, showing AI's dual role in bot development.
Bots Persist Through Constant Evasion
- Bots constantly change their attack patterns to evade detection, retooling as soon as defenders identify front markers.
- This persistence is driven by financial incentives motivating continuous evasion tactics.