July 29, 2026
Trends in hostile access situations seen from the NICTER report
The Other Side of AI Democratization

By KATATAN
3 min read
The Other Side of AI Democratization
Anthropic Mythos, Fable 5, and other high-performance AI models keep arriving one after another. Advanced problem-solving that once required specialist expertise is now available to anyone. Development, research, everyday productivity — AI's benefits reach nearly every domain.
But this shift has a flip side. The same models that boost developer productivity can just as easily become powerful tools in the hands of attackers. As AI makes vulnerability discovery and exploit generation faster, the barrier to launching a cyberattack keeps getting lower — a concern that's no longer far-fetched.
What a Decade of Darknet Observation Shows
This isn't just a feeling. Japan's National Institute of Information and Communications Technology (NICT) has run the NICTER*1 project, continuously observing "darknet"*2 traffic for over a decade, and recently published its findings in the "NICTER Observation Report 2025."
According to the report, the annual number of packets observed per IP address has trended as follows:
That's roughly a 4.7x increase in under ten years.
One important caveat: this isn't a count of successful attacks. A darknet consists of reachable but unused IP addresses, and most of the traffic that arrives there comes from indiscriminate scanning and probing. In fact, the NICTER report itself estimates that about 55.0% of observed packets are scans presumed to be for research/survey purposes.
In other words, this figure isn't a measure of "how many attacks succeeded" — it's a correlational signal of how much scanning and attack-related activity is occurring across the internet. We can't draw a direct causal line between the rise of accessible AI and this increase in observed traffic. But the fact that both trends are unfolding over the same period — the democratization of powerful AI and the intensification of internet-wide probing — is a signal developers shouldn't ignore.
More Sophisticated Attacks Demand More Sophisticated Governance
As attack techniques grow more sophisticated and automated, the bar for security governance expected of companies and dev teams inevitably rises with it. Security requirements from partners and customers, compliance obligations, accountability when incidents occur — these are no longer concerns reserved for large enterprises. They now touch development projects of every size.
Does your development project have security measures in place? Surprisingly few teams can answer that question without hesitation.
Introducing KATATAN's Vulnerability Check
That's why KATATAN is releasing the Vulnerability Check feature — a casual, low-friction way to check the health of your product.

It automatically runs 14 security checks — covering SSL/TLS, cookies, CORS, and security headers — against the URLs registered in your project. Findings are organized by severity (Critical / High / Medium / Low / Info), with bilingual (Japanese/English) explanations of the cause and recommended remediation for each. Reports can be exported as Markdown or CSV, and AI agents can access them directly via MCP tools.
Even if you haven't put any security measures in place yet, we'd encourage you to just run a scan — casually, without pressure. Like most approaches to getting in shape, the first step before changing anything is simply stepping on the scale. Vulnerability Check is available even on the free workspace plan, so give it a try.
What's Next
The checks KATATAN offers today are intentionally simple — a first step, not a complete picture. We'll keep researching the ever-expanding range of attack techniques and continue adding new checks over time.
About KATATAN
KATATAN is a test management and quality control SaaS in the era of AI-powered development. It is easy to write from AI, and it is easy for humans to review. And all test resources are centrally managed in one place, so quality control is transparent and helps improve the quality governance of the team. You can start using KATATAN for free. If you have any problems with testing management and quality control in AI-powered development, please try KATATAN.
Katatan - Quality Governance for AI-Driven Development Katatan is a quality governance platform built for the era of AI-driven development. AI agents create and update test…
— -
*1 NICTER: Short for Network Incident analysis Center for Tactical Emergency Response — a cybersecurity research organization within Japan's National Institute of Information and Communications Technology (NICT).
*2 Darknet: A block of IP addresses that are reachable on the internet but currently unused. Under normal internet usage, traffic destined for unused addresses should be rare — yet darknet observation reveals a substantial volume of incoming packets, most of which stem from cyberattack-related activity.
Source: National Institute of Information and Communications Technology (NICT), "NICTER Observation Report 2025," https://www.nicter.jp/