Katatan Logo
KATATAN
Blog
Introducing the Vulnerability Check Feature for Web Applications

Introducing the Vulnerability Check Feature for Web Applications

As high-performance AI models become mainstream, the same capabilities that boost developer productivity can just as easily arm attackers. KATATAN's new Vulnerability Check feature lets you casually check your product's security health — free to try today.

releasesecurityvulnerability-checkAI-driven development

The Other Side of AI Democratization

Anthropic Mythos, Fable 5, and other high-performance AI models keep arriving one after another. Advanced problem-solving that once required specialist expertise is now available to anyone. Development, research, everyday productivity — AI's benefits reach nearly every domain.

But this shift has a flip side. The same models that boost developer productivity can just as easily become powerful tools in the hands of attackers. As AI makes vulnerability discovery and exploit generation faster, the barrier to launching a cyberattack keeps getting lower — a concern that's no longer far-fetched.

What a Decade of Darknet Observation Shows

This isn't just a feeling. Japan's National Institute of Information and Communications Technology (NICT) has run the NICTER*1 project, continuously observing "darknet"*2 traffic for over a decade, and recently published its findings in the "NICTER Observation Report 2025."

According to the report, the annual number of packets observed per IP address has trended as follows:

YearPackets observed per IP address (annual)
2016~527,888
2018~806,877
2020~1,849,817
2022~1,833,012
2024~2,427,977
2025~2,504,680 (highest since observation began)

That's roughly a 4.7x increase in under ten years.

One important caveat: this isn't a count of successful attacks. A darknet consists of reachable but unused IP addresses, and most of the traffic that arrives there comes from indiscriminate scanning and probing. In fact, the NICTER report itself estimates that about 55.0% of observed packets are scans presumed to be for research/survey purposes.

In other words, this figure isn't a measure of "how many attacks succeeded" — it's a correlational signal of how much scanning and attack-related activity is occurring across the internet. We can't draw a direct causal line between the rise of accessible AI and this increase in observed traffic. But the fact that both trends are unfolding over the same period — the democratization of powerful AI and the intensification of internet-wide probing — is a signal developers shouldn't ignore.

More Sophisticated Attacks Demand More Sophisticated Governance

As attack techniques grow more sophisticated and automated, the bar for security governance expected of companies and dev teams inevitably rises with it. Security requirements from partners and customers, compliance obligations, accountability when incidents occur — these are no longer concerns reserved for large enterprises. They now touch development projects of every size.

Does your development project have security measures in place? Surprisingly few teams can answer that question without hesitation.

Introducing KATATAN's Vulnerability Check

That's why KATATAN is releasing the Vulnerability Check feature — a casual, low-friction way to check the health of your product.

Vulnerability Check report screen

It automatically runs 14 security checks — covering SSL/TLS, cookies, CORS, and security headers — against the URLs registered in your project. Findings are organized by severity (Critical / High / Medium / Low / Info), with bilingual (Japanese/English) explanations of the cause and recommended remediation for each. Reports can be exported as Markdown or CSV, and AI agents can access them directly via MCP tools.

Even if you haven't put any security measures in place yet, we'd encourage you to just run a scan — casually, without pressure. Like most approaches to getting in shape, the first step before changing anything is simply stepping on the scale. Vulnerability Check is available even on the free workspace plan, so give it a try.

What's Next

The checks KATATAN offers today are intentionally simple — a first step, not a complete picture. We'll keep researching the ever-expanding range of attack techniques and continue adding new checks over time.

Closing

We hope KATATAN can play some part in keeping your product safe from threats. If you have questions or feedback about Vulnerability Check, we'd love to hear from you.

Contact: contact@katatan.com


*1 NICTER: Short for Network Incident analysis Center for Tactical Emergency Response — a cybersecurity research organization within Japan's National Institute of Information and Communications Technology (NICT).

*2 Darknet: A block of IP addresses that are reachable on the internet but currently unused. Under normal internet usage, traffic destined for unused addresses should be rare — yet darknet observation reveals a substantial volume of incoming packets, most of which stem from cyberattack-related activity.

Source: National Institute of Information and Communications Technology (NICT), "NICTER Observation Report 2025," https://www.nicter.jp/