Tag: api
-
220 million traveler records exposed in Vietnam-linked APIS leak
Exclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026. Researchers accessed the Vietnam-linked system through a cloud-based path using default credentials. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/220-million-traveler-records-exposed-in-vietnam-linked-apis-leak/
-
Authentication Challenges in AI-Powered Applications and How to Solve Them
AI-powered applications are no longer simple request-response tools. They orchestrate long-running agents, call external APIs on a user’s behalf, retain conversational memory, and increasingly act autonomously across systems. That shift changes what “authentication” even means. Verifying a human at login… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/authentication-challenges-in-ai-powered-applications-and-how-to-solve-them/
-
APIs Are the Attack Surface That Matters in AI-Powered Apps FireTail Blog
Sep 07, 2026 – Jeremy Snyder – Recently, I had the opportunity to speak on the main stage at the combined API:World, AI TechWorld and CloudX event in Santa Clara. I wanted to share my thoughts on what I presented,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/apis-are-the-attack-surface-that-matters-in-ai-powered-apps-firetail-blog/
-
Sichtbarkeit und Kontrolle für KI, APIs und Anwendungen – Mehr Cyberresilienz in Hybrid- und MultiUmgebungen
First seen on security-insider.de Jump to article: www.security-insider.de/cyberresilienz-hybrid-multi-cloud-a-92b4ab465d4faf9a39538119fbbfc5f5/
-
What Are the Main Types of AI Gateways? LLM, MCP, and Agent Gateways Explained
Gateways have long marked important boundaries in computing.Network gateways connected systems that used different protocols. Secure web gateways inspected traffic moving between employees and the internet.And API gateways gave organizations a central point for routing service requests, authenticating clients, applying… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/what-are-the-main-types-of-ai-gateways-llm-mcp-and-agent-gateways-explained/
-
SSOJet API Error Codes: A Developer Reference (and What Not to Retry)
Tags: apiEvery SSOJet API error returns the same three fields, a stable error string, a human-readable error_description, and a numeric error_code, and there are 148 documented codes across seven domains. This is the reference for handling them in code:… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/ssojet-api-error-codes-a-developer-reference-and-what-not-to-retry/
-
AI safety organization METR reports API key theft and credit misuse
First seen on scworld.com Jump to article: www.scworld.com/brief/ai-safety-organization-metr-reports-api-key-theft-and-credit-misuse
-
Hackers Steal Metr API Key, Burn $600K in AI Credits
Separate Database Flaw Could Have Exposed Sensitive Model Data. Attackers in March stole a Metr API key and used it for three weeks to consume about $600,000 worth of AI model credits. In a separate May campaign, hackers probed a public Metr service with a bug that could have exposed unpublished and sensitive model data.…
-
API-first DCIM: Reduce Integration Friction and Keep Control Across Tools
Disconnected tools slow your operations down more than missing data ever could. Every day, teams waste hours stitching together systems that don’t naturally talk to each other. API-first DCIM cuts through that drag, turning scattered signals into one clear operational… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/api-first-dcim-reduce-integration-friction-and-keep-control-across-tools/
-
What a 14-Day Federal Patch Clock Costs a Team That Isn’t a Federal Agency
(MLflow, CVE-2026-64849, August 2026)By Pablo Bleck, Engineering Manager & Software Engineer, ActiveStateMLflow shipped its webhook API open by default across a platform with more than 30 million monthly downloads, and a CISA listing turned that unauthenticated endpoint into a 14-day… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/what-a-14-day-federal-patch-clock-costs-a-team-that-isnt-a-federal-agency/
-
Claude AI Develops Working RCE Exploit Against WAGO PLC With Researcher Assistance
Researchers have demonstrated that Anthropic’s Claude AI can assist in porting a remote code execution exploit between vulnerable models of WAGO programmable logic controllers (PLCs). However, this process requires significant human guidance, lengthy analysis sessions, and more than $500 in API usage. The experiment focused on CVE-2021-31886, a pre-authentication buffer overflow flaw in the Nucleus…
-
Hackers Exploit LiteLLM Admin API Flaw to Turn Read-Only Access Into Full Server Takeover
Attackers are actively exploiting a critical authorization flaw in LiteLLM’s administrative API. This vulnerability allows low-privileged, read-only users to modify proxy configurations, expose sensitive secrets, and potentially gain full administrator control over affected servers. Researchers at Zenity Labs tracked approximately 3,900 requests targeting LiteLLM’s administration endpoints from February to June 2026, originating from 73 different…
-
Hackers Hide Reverse Shell Traffic Behind Signed Apps and AWS API Gateway
Threat actors are using a layered fake IT-support campaign to obtain remote access, deploy a malicious MSI package and conceal hands-on-keyboard activity behind legitimate signed applications and AWS API Gateway infrastructure. The operation demonstrates how attackers can divide execution, command-and-control and interactive shell functions across multiple processes to frustrate conventional endpoint and network detections. Once…
-
9 Enterprise Identity Trends That Will Define 2026 and Beyond
Trend 1: Agentic Identity Becomes a First-Class Citizen in IAM AI agents are already operating in production environments. They read emails, write code, query databases, post to Slack, file tickets, and call APIs across dozens of enterprise systems. Their identity… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/9-enterprise-identity-trends-that-will-define-2026-and-beyond-2/
-
Open-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and Jira
Sift is a free, open-source command line tool that searches for passwords, API keys, and other sensitive data across the places a company keeps its work: local disks, Windows … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/02/sift-open-source-secret-scanning/
-
How to Evaluate API Security and Abuse Detection Platforms
First seen on scworld.com Jump to article: www.scworld.com/buyers-guide/how-to-evaluate-api-security-and-abuse-detection-platforms
-
AI Model Evaluator METR Hit by Credential Theft, Probing
In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit. First seen on darkreading.com Jump to article: www.darkreading.com/identity-access-management-security/ai-model-evaluator-metr-credential-theft-probing
-
Attackers Steal METR API Key and Burn $600,000 in AI Credits
Attackers used a stolen METR API key for three weeks, consuming model credits worth $600,000 First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/attackers-steal-metr-api-key/
-
Agents Without Guardrails: Why Agentic AI Governance Must Focus on Behavior, Not Just Identity
Enterprises have spent decades building security around a familiar question:”¯Who are you? Identity and access management (IAM), authentication, service accounts, OAuth tokens, and role-based access controls all start there. Establish identity, assign permissions, and control access. Agentic AI changes the equation. AI agents do not simply access systems. They reason, select tools, call APIs, retrieve……
-
External input cannot be trusted: input validation and encoding strategies
External data should be treated as hostile until it has been checked, constrained, and transformed for the specific place it will be used. That applies whether the data comes from a browser form, a mobile app, an API client, a file upload, an integration partner, or another internal service. In practice, many security issues start……
-
Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance
Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activity logs alone cannot tell you whether an agent’s access is legitimate.AI has moved…
-
Extortion Group FulcrumSec Claims 86GB Manchester Airports Group Data Theft
Extortion group FulcrumSec claims they stole 86GB of Manchester Airports Group data after finding API credentials exposed in client-side JavaScript. Manchester Airports Group (MAG) disclosed a data breach on August 27 affecting customers of Manchester, London Stansted, and East Midlands airports. Two days later, BleepingComputer reports the extortion group FulcrumSec claimed responsibility, saying it stole…
-
Key Reasons Why Identity Fabric Matters in 2026
An Identity Fabric knits fragmented identity systems into a coherent layer that observes how identities behave across applications, APIs, and infrastructure. As enterprise access spans more cloud services and automated workloads, identity security depends less on static configuration and more on runtime visibility. This article covers the architecture, the risks of unmanaged identities, and First…
-
Centralize Like You Mean It, Federate Like You Have To
Tags: ai, api, attack, automation, breach, cloud, compliance, control, data, detection, dns, endpoint, identity, infrastructure, network, PCI, radius, regulation, resilience, risk, saas, service, siem, soc, technology, threat, tool, windows, worm(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?””Š”, “Šan admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earliest surviving deck is from 2003), we may be running out of…
-
Centralize Like You Mean It, Federate Like You Have To
Tags: ai, api, attack, automation, breach, cloud, compliance, control, data, detection, dns, endpoint, identity, infrastructure, network, PCI, radius, regulation, resilience, risk, saas, service, siem, soc, technology, threat, tool, windows, worm(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?””Š”, “Šan admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earliest surviving deck is from 2003), we may be running out of…
-
Centralize Like You Mean It, Federate Like You Have To
Tags: ai, api, attack, automation, breach, cloud, compliance, control, data, detection, dns, endpoint, identity, infrastructure, network, PCI, radius, regulation, resilience, risk, saas, service, siem, soc, technology, threat, tool, windows, worm(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?””Š”, “Šan admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earliest surviving deck is from 2003), we may be running out of…
-
Centralize Like You Mean It, Federate Like You Have To
Tags: ai, api, attack, automation, breach, cloud, compliance, control, data, detection, dns, endpoint, identity, infrastructure, network, PCI, radius, regulation, resilience, risk, saas, service, siem, soc, technology, threat, tool, windows, worm(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?””Š”, “Šan admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earliest surviving deck is from 2003), we may be running out of…
-
Centralize Like You Mean It, Federate Like You Have To
Tags: ai, api, attack, automation, breach, cloud, compliance, control, data, detection, dns, endpoint, identity, infrastructure, network, PCI, radius, regulation, resilience, risk, saas, service, siem, soc, technology, threat, tool, windows, worm(by Anton Chuvakin & Usman Chaudhary) Prologue: Three Years After “The End Is Nigh” Back in 2023, one of us wrote “Log Centralization: The End Is Nigh?””Š”, “Šan admittedly incomplete-thought blog with a scary premise: after 20+ years of yelling “centralize your logs!” (the earliest surviving deck is from 2003), we may be running out of…

