Tag: api
-
Google Plans Global Rollout of Privacy-Focused Age Signals API
Google plans to expand its Play Age Signals API globally, helping Android developers tailor app experiences without collecting exact birth dates. The post Google Plans Global Rollout of Privacy-Focused Age Signals API appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-play-age-signals-api-global-rollout/
-
Eine Million offengelegte Datensätze: Was der Merkur-Datenleak über API-Sicherheit verrät
Bild: magnific.com/rajibcpcs1986 Ein massiver Sicherheitsvorfall bei Plattformen der bekannten Glücksspiel-Marke zeigt erneut die kritischen Schwachstellen moderner API-Architekturen auf. Über eine Million Datensätze darunter hochsensible KYC-Dokumente, Finanztransaktionen und Spielverhaltensprofile waren über ungesicherte Schnittstellen frei im Netz abrufbar. Der Fall illustriert eindringlich, warum API-Sicherheit längst zur Chefsache werden muss und welche Lehren IT-Verantwortliche daraus… First seen…
-
ServiceService Authentication: Patterns for Securing API and Microservices
First seen on scworld.com Jump to article: www.scworld.com/tech-explainer/service-to-service-authentication-patterns-for-securing-api-and-microservice
-
Vatican’s Official Prayer App Leaks 700K+ Global Users’ PII
A porous API endpoint exposes, names, email addresses, location, and site status, all of which can be easily gleaned by anyone with a browser. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/vatican-official-prayer-app-leaks-700k-pii
-
New TriBack Loader Evades EDR Using Signed Binaries and Win32 Callback APIs
A new shellcode loader, dubbed “TriBack Loader,” to a China-nexus intrusion cluster tracked as JadeProx, with the malware explicitly engineered to evade modern EDR by abusing signed binaries and uncommon Win32 callback APIs. Across at least four observed variants, the loader underpins simultaneous espionage campaigns in South-East Asia and Latin America, including targeting of a…
-
Critical Gitea Flaw Lets Public-Only Tokens Write to Private Repositories and Trigger Actions Workflows
Gitea administrators are strongly encouraged to upgrade their systems following the discovery of a critical authorization vulnerability. This flaw allows public-only API tokens to modify private pull request branches and potentially trigger Gitea Actions workflows. The vulnerability, tracked as CVE-2026-58443 and GHSA-xxjv-752h-3vp2, affects Gitea versions up to and including 1.26.4. The issue has been resolved…
-
HOLLOWGRAPH Malware Turns Microsoft 365 Calendar Events Into Covert CommandControl Channels
HOLLOWGRAPH, a Windows malware implant that transforms Microsoft 365 calendar events into a covert command-and-control channel. This malware, which is highly likely linked to the Cavern modular backdoor framework, utilizes the Microsoft Graph API to retrieve tasks from operators and to exfiltrate stolen data via a compromised Microsoft 365 mailbox. This technique enables malicious communications…
-
HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.Group-IB, which named the malware HollowGraph, says the approach moves tasking and stolen data through legitimate Microsoft Graph API traffic, so…
-
Salt Security tackles AI governance challenge with 100 pre-built agentic security policies
Salt Security has expanded its Policy Hub to include 100 pre-built security policies, as organisations look for practical ways to govern AI agents across enterprise environments. The company says the milestone creates one of the industry’s largest libraries of governance policies for agentic AI, covering APIs, Model Context Protocol (MCP) servers, authentication, access controls, compliance…
-
New HollowGraph Malware Hijacks Microsoft 365 Calendars for Covert C2 Communications
Researchers have linked HollowGraph malware to the Cavern framework after discovering its use of Microsoft 365 calendars and Microsoft Graph APIs as a stealthy C2 channel First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/hollowgraph-microsoft-calendars/
-
AI Can Find Bugs, But Human Knowledge Still Proves Them
Artificial intelligence (AI) is changing offensive security, but it has not changed the standard that matters most: a finding has to be proven before it becomes useful. AI-assisted tools can read code quickly, generate payloads, summarize attack surfaces, explain unfamiliar APIs, and run repetitive testing workflows at impressive speed. That is a real advantage for…
-
Akamai API Security Impact Study 2026 Sicherheitsvorfälle kosten deutsche Firmen rund 470.000 Euro
Tags: apiFirst seen on security-insider.de Jump to article: www.security-insider.de/akamai-api-security-studie-2026-a-fb981232e722203172722c32cb9c6169/
-
The AI Supply Chain Is Your Latest Unguarded Attack Surface
When You Consume AI, You Inherit Every Upstream Risk You Can’t See Most enterprises don’t build AI, they consume it through APIs, open-source models and orchestration frameworks. Each layer inherits upstream risk with little visibility. This piece maps the four-layer AI supply chain and the existing security disciplines that bring it under control. First seen…
-
Fast die Hälfte des Datenverkehrs auf Reise-Websites stammt von bösartigen Bots
Reiseunternehmen stehen unter Druck, das Vertrauen und die Treue ihrer Kunden vor Cyberkriminellen zu schützen. Ausgeklügelte KI-gestützte Bots nehmen zunehmend Buchungssysteme, Treuekonten und kritische Reise-APIs ins Visier. Die Ergebnisse des ‘Thales Bad Bot Reports 2026″ zeigen, dass mittlerweile 49 Prozent des gesamten Datenverkehrs auf Reise-Portalen von bösartigen Bots generiert werden. Dadurch gehört die Reisebranche zu…
-
Bösartige Bots auf Reiseportalen: Thales warnt vor Account Takeover, API-Missbrauch und Vertrauensverlust
Tags: apiFür die Branche entsteht daraus ein strategischer Handlungsdruck. Wer Buchungssysteme, APIs, Treuekonten und Kundendaten nicht wirksam schützt, riskiert mehr als technische Störungen. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/boesartige-bots-auf-reiseportalen-thales-warnt-vor-account-takeover-api-missbrauch-und-vertrauensverlust/a45693/
-
Google Gemini Live API Flaw Allows RCE via Unconstrained Ephemeral Tokens
Tags: ai, api, cyber, data-breach, endpoint, flaw, google, rce, remote-code-execution, vulnerabilityA significant security vulnerability in Google’s Gemini Live API has exposed applications to remote code execution (RCE) due to misconfigured ephemeral tokens. This flaw allows attackers to inject client-controlled setup frames and execute arbitrary code within AI voice sessions. The issue stems from the improper use of the “Constrained” WebSocket endpoint, particularly when developers neglect…
-
Hackers Use Fake API Documentation to Trick AI Agents Into Sending Crypto Payments
Hackers are now weaponizing documentation and site metadata to mislead autonomous AI agents into executing cryptocurrency payments. The attack leverages indirect prompt injection (IPI): malicious instructions hidden in web content and structured data that influence an AI agent’s reasoning during automated tasks. By combining SEO poisoning, JSON”‘LD abuse and CSS concealment, attackers create seemingly legitimate…
-
Cato CTRL entdeckt neuen Backdoor-Trojaner TencShell – TencShell-Backdoor imitiert Tencent-API-Verkehr zur Tarnung
First seen on security-insider.de Jump to article: www.security-insider.de/tencshell-backdoor-tencent-api-tarnung-china-a-472ef6cffdd0059e47cb06194e619b51/
-
ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API
The threat actor known as ToddyCat has been attributed to a new malware called Umbrij that’s designed to gain surreptitious access to a victim’s email correspondence via the Google API.”In this campaign, the attackers focused their attention on corporate email communications hosted on Gmail, targeting access compromise via APIs,” Kaspersky said in a detailed report…
-
EvilTokens-Linked ARToken Panel Exposes 80+ APIs for Microsoft 365 Token Theft
A fully featured phishing-as-a-service (PhaaS) panel named “ARToken” that closely mirrors the EvilTokens infrastructure first profiled in early 2026, but with a broader and deeper post-compromise toolkit. ARToken’s React single-page application exposes more than 80 API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, mailbox takeover, business email compromise (BEC) workflows, and SharePoint exfiltration…
-
EvilTokens-Linked ARToken Panel Exposes 80+ APIs for Microsoft 365 Token Theft
A fully featured phishing-as-a-service (PhaaS) panel named “ARToken” that closely mirrors the EvilTokens infrastructure first profiled in early 2026, but with a broader and deeper post-compromise toolkit. ARToken’s React single-page application exposes more than 80 API endpoints enabling device-code phishing, Primary Refresh Token (PRT) persistence, mailbox takeover, business email compromise (BEC) workflows, and SharePoint exfiltration…
-
JADEPUFFER Agentic Ransomware Uses LLM to Automate Database Extortion
The first instance of agentic ransomware: JADEPUFFER, an LLM-driven extortion operation that automated an end-to-end database-crippling campaign. The actor gained execution on an internet-facing Langflow instance via CVE-2025-3248, used the AI-host environment to harvest cloud and API credentials, and pivoted into a production MySQL/Nacos deployment to carry out a destructive, database-focused extortion playbook without a…
-
AI-Generated Browser Ransomware Abuses Chromium API on Windows, Linux, macOS, Android
Cybersecurity researchers have flagged a new malware artifact generated using DeepSeek that constructed a novel attack path combining “unrealistic browser-malware concepts with a real browser capability” to turn it into a working ransomware technique that runs entirely inside the browser on both Windows and Android devices.”This is the first documented case where a frontier AI…
-
AI-Generated Browser Ransomware Abuses Chromium API on Windows and Android
Cybersecurity researchers have flagged a new malware artifact generated using DeepSeek that constructed a novel attack path combining “unrealistic browser-malware concepts with a real browser capability” to turn it into a working ransomware technique that runs entirely inside the browser on both Windows and Android devices.”This is the first documented case where a frontier AI…
-
ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365
Talos has identified “ARToken,” a phishing-as-a-service platform that targets Microsoft 365. The ARToken panel exposes 80+ API endpoints for device code phishing, Primary Refresh Token persistence, email access, BEC operations, and SharePoint exfiltration. First seen on blog.talosintelligence.com Jump to article: blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-panel-targeting-microsoft-365/
-
Researcher Analyzes 3,000 Live ClickFix Payloads, Exposing API-Driven Malware Delivery
ClickFix, the trick that fools people into running malware by hand, has quietly grown a back office.New research shows the malicious commands behind its fake “prove you’re human” pages are now handed out by API-driven servers that give each visitor the same malware in a different disguise. The same research also turned up a new…
-
282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study
Researchers tested 444 AI chatbot apps for iPhone and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic.In many cases, the path in was visible just by watching what the app sent: a plaintext API key, a reusable token, or a backend server that accepted requests with no key…
-
Critical Progress Kemp LoadMaster Vulnerability Enables Pre-Auth Remote Code Execution
Progress’s Kemp LoadMaster, a widely deployed edge load balancer and ADC, is at the center of a critical pre-authentication Remote Code Execution (RCE) vulnerability tracked as CVE-2026-8037. The flaw allows unauthenticated attackers with access to the device API to run arbitrary shell commands by exploiting an uninitialized-memory/string-termination bug in LoadMaster’s API handling. Given LoadMaster’s position…

