International Peer-Reviewed JournalOpen AccessISSN 2456-8880
irejournals@gmail.com+91-7433024337

Home / Current Issue / Paper 1722336

1722336 Vol 10 · Issue 2 Download Paper

Evolution of Web Application Attacks: A Systematic Analysis of the Current Threat Landscape and Emerging Security Challenges

Irene I. Eda Jose Marcelito D. Brigoli Teodoro B. Comayas Jr. Bernie C. Empaces Jenel T. Tiad Serafin C. Palmares Kristine T. Soberano

Subject area: Science,Engineering and Technology  ·  Area of research: Cybersecurity – Web Application Security

Abstract

The rapid explosion of web application capabilities over the past ten years has fundamentally redesigned how applications are delivered, simultaneously introducing an intricate, multifaceted attack surface that continues to evolve. Standard vectors, long thought to be understood—such as SQL Injection (SQLi), Cross-Site Scripting (XSS), and Cross-Site Request Forgery (CSRF)—still exist as potent hazards, yet they are increasingly overshadowed. Emerging cloud-native architectures, serverless delivery mechanisms, microservices, and AI-driven automation introduce entirely new categories of subtle, deeply embedded vulnerabilities. This research evaluates how these threats have metastasized and traces the origins of modern security vectors to determine if established defensive protocols remain effective against increasingly complex modern exploitation tactics. We conducted a strict Systematic Literature Review (SLR) structured by PRISMA 2020 guidelines, filtering an extensive initial pool of 885 records down to 62 core sources published between 2015 and 2026. This foundational dataset synthesizes observations from 44 peer-reviewed empirical studies alongside analysis from 18 key cybersecurity frameworks and official threat intelligence reports, incorporating guidance from standards bodies including OWASP, NIST, and ISO/IEC. The synthesized evidence reveals a definitive and strategic maturation in adversarial approach: threat actors are abandoning isolated, single-vulnerability exploits. They are instead executing prolonged, multi-stage campaigns that specifically leverage the trust relationships found in interconnected software ecosystems. While SQLi, XSS, and authentication weaknesses remain critical and frequent (identified within our 12 primary attack categories), a steep rise in complex, multi-stage exploit chains, AI-assisted reconnaissance, API breaches, and software supply chain compromises represents the new operational normal for adversaries. Furthermore, our analysis indicates that traditional defensive frameworks like secure development lifecycles, Zero Trust Architecture, DevSecOps, and Web Application Firewalls (WAFs) are no longer sufficient in isolation. Their mitigation capacity works only when supported by continuous, real-time context-aware monitoring and truly dynamic risk management, establishing an empirical baseline for architecting resilient security posturing that can keep pace with accelerating innovation.

Keywords

Cybersecurity, Emerging Threats, Systematic Literature Review, Web Application Attacks, Web Application Security

How to cite this paper

Irene I. Eda, Jose Marcelito D. Brigoli, Teodoro B. Comayas Jr. , Bernie C. Empaces, Jenel T. Tiad; Serafin C. Palmares; Kristine T. Soberano "Evolution of Web Application Attacks: A Systematic Analysis of the Current Threat Landscape and Emerging Security Challenges" Iconic Research And Engineering Journals Volume 10 Issue 2 2026 Page 1378-1401
Irene I. Eda, Jose Marcelito D. Brigoli, Teodoro B. Comayas Jr. , Bernie C. Empaces, Jenel T. Tiad; Serafin C. Palmares; Kristine T. Soberano "Evolution of Web Application Attacks: A Systematic Analysis of the Current Threat Landscape and Emerging Security Challenges" Iconic Research And Engineering Journals, vol. 10, no. 2, Aug. 2026
Irene I. Eda, Jose Marcelito D. Brigoli, Teodoro B. Comayas Jr. , Bernie C. Empaces, Jenel T. Tiad; Serafin C. Palmares; Kristine T. Soberano (2026). Evolution of Web Application Attacks: A Systematic Analysis of the Current Threat Landscape and Emerging Security Challenges. Iconic Research And Engineering Journals, 10(2).
Irene I. Eda, Jose Marcelito D. Brigoli, Teodoro B. Comayas Jr. , Bernie C. Empaces, Jenel T. Tiad; Serafin C. Palmares; Kristine T. Soberano "Evolution of Web Application Attacks: A Systematic Analysis of the Current Threat Landscape and Emerging Security Challenges" Iconic Research And Engineering Journals, vol. 10, no. 2, Aug. 2026.
@article{1722336,
      author = {Irene I. Eda, Jose Marcelito D. Brigoli, Teodoro B. Comayas Jr. , Bernie C. Empaces, Jenel T. Tiad; Serafin C. Palmares; Kristine T. Soberano},
      title = {Evolution of Web Application Attacks: A Systematic Analysis of the Current Threat Landscape and Emerging Security Challenges},
      journal = {Iconic Research And Engineering Journals},
      year = {2026},
      volume = {10},
      number = {2},
      pages = {1378-1401},
      issn = {2456-8880},
      url = {https://www.irejournals.com/formatedpaper/1722336.pdf},
      abstract = {The rapid explosion of web application capabilities over the past ten years has fundamentally redesigned how applications are delivered, simultaneously introducing an intricate, multifaceted attack surface that continues to evolve. Standard vectors, long thought to be understood—such as SQL Injection (SQLi), Cross-Site Scripting (XSS), and Cross-Site Request Forgery (CSRF)—still exist as potent hazards, yet they are increasingly overshadowed. Emerging cloud-native architectures, serverless delivery mechanisms, microservices, and AI-driven automation introduce entirely new categories of subtle, deeply embedded vulnerabilities. This research evaluates how these threats have metastasized and traces the origins of modern security vectors to determine if established defensive protocols remain effective against increasingly complex modern exploitation tactics. We conducted a strict Systematic Literature Review (SLR) structured by PRISMA 2020 guidelines, filtering an extensive initial pool of 885 records down to 62 core sources published between 2015 and 2026. This foundational dataset synthesizes observations from 44 peer-reviewed empirical studies alongside analysis from 18 key cybersecurity frameworks and official threat intelligence reports, incorporating guidance from standards bodies including OWASP, NIST, and ISO/IEC. The synthesized evidence reveals a definitive and strategic maturation in adversarial approach: threat actors are abandoning isolated, single-vulnerability exploits. They are instead executing prolonged, multi-stage campaigns that specifically leverage the trust relationships found in interconnected software ecosystems. While SQLi, XSS, and authentication weaknesses remain critical and frequent (identified within our 12 primary attack categories), a steep rise in complex, multi-stage exploit chains, AI-assisted reconnaissance, API breaches, and software supply chain compromises represents the new operational normal for adversaries. Furthermore, our analysis indicates that traditional defensive frameworks like secure development lifecycles, Zero Trust Architecture, DevSecOps, and Web Application Firewalls (WAFs) are no longer sufficient in isolation. Their mitigation capacity works only when supported by continuous, real-time context-aware monitoring and truly dynamic risk management, establishing an empirical baseline for architecting resilient security posturing that can keep pace with accelerating innovation.},
      keywords = {Cybersecurity, Emerging Threats, Systematic Literature Review, Web Application Attacks, Web Application Security},
      month = {August},
  }