Tag: api
-
Top 10 Best External Attack Surface Management (EASM) Platforms 2026
In the sprawling digital ecosystem of 2026, organizations grapple with an increasingly complex and often poorly understood external attack surface. This attack surface encompasses all internet-facing assets that are discoverable and potentially exploitable by malicious actors. These assets extend far beyond traditional network perimeters to include cloud resources, web applications, APIs, orphaned infrastructure, exposed databases,…
-
AI code security with Claude Mythos Preview: Inside Tenable’s 500+ hours of testing for Project Glasswing
Tags: access, ai, api, application-security, compliance, control, cyber, cybersecurity, data, exploit, flaw, reverse-engineering, risk, software, threat, tool, update, vulnerabilityWe spent 500+ hours and 40 billion tokens testing Anthropic’s Claude Mythos Preview for Project Glasswing. The takeaway: frontier AI won’t run your code security program, but used well, it can make one even stronger. Key takeaways Frontier AI dramatically scales security testing. In one month, Tenable dedicated 11 security experts and more than 40…
-
Critical Paperclip AI Agent Flaws Allow Unauthenticated Remote Code Execution
Critical vulnerabilities in the open-source Paperclip AI-agent orchestration platform could allow attackers to execute commands remotely on exposed servers or on a developer’s local machine. These flaws arise from broken authorization boundaries across agent imports and API routes, as well as trust assumptions for localhost. Paperclip is designed to coordinate autonomous agents across >>companies,<< with…
-
Cloudflare Launches Open-Source OS to Secure AI Agents’ Access to Internal Data
Cloudflare has open-sourced Cloudflare OS, a platform designed to provide enterprise AI agents with controlled access to internal systems, company context, and workflows without exposing long-lived credentials or bypassing access controls. This release addresses a significant security challenge for enterprises: while agents need access to business data and tools to be effective, conventional API keys…
-
Thales bringt Imperva WAF nativ auf Amazon CloudFront
Thales bringt Imperva WAF auf Amazon CloudFront. Die SaaS-Lösung schützt Webanwendungen, APIs und KI-Systeme vor Angriffen und bösartigen Bots. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/thales-bringt-imperva-waf-nativ-auf-amazon-cloudfront/a46039/
-
Angreifer folgen dem Geld, APIs sind ihr neues Ziel – APIs werden zur zentralen Angriffsfläche für Unternehmen
Tags: apiFirst seen on security-insider.de Jump to article: www.security-insider.de/apis-zentrale-angriffsflaeche-unternehmen-a-a4aff75a1650ad0a6d9d9afcd3fd05ef/
-
Surf AI Adds Claude Compliance Integration and Exposure Reduction Operations
Surf AI has added an integration with Claude’s Compliance API and made Exposure Reduction Operations generally available, extending its platform to govern AI model connectivity alongside identity, cloud and SaaS exposures. The Claude integration pulls activity logs from an organization’s Claude environment, maps connection and access paths to an accountable owner in Surf’s Context Graph,..…
-
Novee Brings Continuous AI Pentesting to Mobile Applications
Novee has expanded its AI penetration testing platform to mobile applications, extending continuous testing across mobile, web, APIs, desktop software and AI-enabled applications. The company announced the update ahead of Black Hat USA 2026. Novee said users can upload a mobile application package and receive results within hours, alongside findings from their other application assets……
-
Pre-auth RCE in enterprise Java hits Bonita and OFBiz servers
An attacker sends a single web request to a Bonita server and lands inside an internal API that assumed nobody could reach it. The request arrives unauthenticated. From there … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/05/pre-auth-rce-java-bonita-ofbiz-cve-2026-31986/
-
Salt Security Launches Industry-First AWS WAF Managed Ruleset for AI Agents and API Protection
Salt Security has unveiled what it says is the industry’s first AWS WAF managed ruleset designed specifically to protect both APIs and AI agents, extending native AWS Web Application Firewall (WAF) capabilities to address emerging threats driven by agentic AI. Announced at Black Hat USA 2026, the new Salt Managed Rules for AWS WAF are…
-
Aembit Adds Workload Identity Federation Support for the Claude API
5 min readToday, we’re announcing the Aembit Claude Workload Identity Federation Credential Provider, the latest addition to Aembit’s growing Claude support. Aembit already covers a lot of ground with Claude: workloads can authenticate to the Claude API using static API key injection, Claude Web and the Claude App are supported as Client Workloads, direct API…
-
From Inspection to Authorization: Securing Networks for AI Agents
Tags: access, ai, api, business, ceo, cloud, communications, control, crowdstrike, cryptography, data, encryption, endpoint, finance, firewall, identity, infrastructure, login, network, office, risk, saas, service, usa, vpn<div cla An Industry Perspective By Rajiv Pimplaskar, CEO, Dispersive Holdings, Inc. Agentic AI changes the network security problem from inspection to authorization. As more traffic is generated by agents, models, and workloads operating at machine speed, the network has to make trust decisions continuously, evaluate policy in real time, revoke access automatically, and keep…
-
Leaked n8n API Tokens Exposed Live Instances to Credential Theft
GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability.We scanned public GitHub commits for exposed n8n API tokens and identified 4,576 unique credentials associated with 1,255 hostnames. Of the 896…
-
Cloudflare gives AI agents wallets with built-in spending controls
Cloudflare’s Wallets will give AI agents running on its platform a human-readable wallet handle for paying APIs and online content within limits set by their creator. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/05/cloudflare-wallets-for-ai-agents/
-
Salt Debuts First AWS WAF Managed Ruleset for AI Agent and API Protection
Tags: access, ai, api, attack, ceo, credentials, detection, email, endpoint, exploit, intelligence, marketplace, threat, waf, xssThe WAF gap no one is talking about Your WAF is doing its job. It’s blocking SQLi, XSS, and the usual suspects. But here’s the problem: it wasn’t built for APIs, and it definitely wasn’t built for AI agents. APIs now power nearly every digital experience. And AI agents, the automated systems that access your…
-
Securing Agentic AI Workflows in n8n: From Leaked API Keys to Encryption Key Compromise
A leaked n8n API key is only the start. GitGuardian’s research traces the full chain, from exposed tokens and weak keys to CVE-2026-25053 and the N8N_ENCRYPTION_KEY that protects every stored credential, then lays out a hardened configuration to break it. First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/08/securing-agentic-ai-workflows-in-n8n-from-leaked-api-keys-to-encryption-key-compromise/
-
Microsoft shortens NuGet API key lifetime to improve supply chain security
Microsoft is reducing the lifetime of new NuGet.org API keys from 365 days to 30 days starting August 17, 2026, to improve the security of NuGet, its package repository for … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/08/04/microsoft-reducing-nuget-api-keys-lifetime/
-
30 days with Claude Mythos Preview: How Tenable adapted our security program, and why yours is next
Tags: ai, api, attack, business, control, cybersecurity, data, data-breach, endpoint, exploit, flaw, injection, LLM, remote-code-execution, risk, service, threat, tool, update, vulnerabilityTenable spent 30 days running frontier AI models against our own code. It didn’t just find bugs, it proved they’re real, with reproducible exploits. That fundamentally changes code security from ranking potential code defects to a much higher signal focused on the findings that matter. Read on to learn how it reshaped our security team’s…
-
Alleged Żabka Breach Exposes Jira Data, Source Code, and API Keys
Alleged Å»abka data leak offered for Euro5,000 includes Jira data, GitLab repos, and secrets; researchers verified much of the sample. A brand-new forum account showed up on August 2, posted once, and asked five grand for what it claims is a full data dump from Å»abka Polska. Å»abka Polska is Poland’s largest convenience store operator…
-
OpenAI says its new GPT 5.6 models are becoming more cost-efficient
OpenAI says it has reduced the price of two GPT-5.6 models, cutting Luna’s API price by 80% and Terra’s by 20% as it works to make its models more efficient. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/artificial-intelligence/openai-says-its-new-gpt-56-models-are-becoming-more-cost-efficient/
-
What an LLM Can Find: A Practical, Cheap Path to Code-level Threat Discovery
An AI-assisted audit found 29 flaws in GlobaLeaks, showing LLMs make large-scale code reviews faster, cheaper, and accessible. GlobaLeaks, a mature whistleblowing platform that had already undergone six independent professional audits over the past thirteen years, was subjected to an LLM-assisted security review that cost roughly USD 3,140 in API calls. The review identified 29…
-
Google Plans Global Rollout of Privacy-Focused Age Signals API
Google plans to expand its Play Age Signals API globally, helping Android developers tailor app experiences without collecting exact birth dates. The post Google Plans Global Rollout of Privacy-Focused Age Signals API appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-google-play-age-signals-api-global-rollout/
-
Eine Million offengelegte Datensätze: Was der Merkur-Datenleak über API-Sicherheit verrät
Bild: magnific.com/rajibcpcs1986 Ein massiver Sicherheitsvorfall bei Plattformen der bekannten Glücksspiel-Marke zeigt erneut die kritischen Schwachstellen moderner API-Architekturen auf. Über eine Million Datensätze darunter hochsensible KYC-Dokumente, Finanztransaktionen und Spielverhaltensprofile waren über ungesicherte Schnittstellen frei im Netz abrufbar. Der Fall illustriert eindringlich, warum API-Sicherheit längst zur Chefsache werden muss und welche Lehren IT-Verantwortliche daraus… First seen…
-
ServiceService Authentication: Patterns for Securing API and Microservices
First seen on scworld.com Jump to article: www.scworld.com/tech-explainer/service-to-service-authentication-patterns-for-securing-api-and-microservice
-
Vatican’s Official Prayer App Leaks 700K+ Global Users’ PII
A porous API endpoint exposes, names, email addresses, location, and site status, all of which can be easily gleaned by anyone with a browser. First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/vatican-official-prayer-app-leaks-700k-pii
-
New TriBack Loader Evades EDR Using Signed Binaries and Win32 Callback APIs
A new shellcode loader, dubbed “TriBack Loader,” to a China-nexus intrusion cluster tracked as JadeProx, with the malware explicitly engineered to evade modern EDR by abusing signed binaries and uncommon Win32 callback APIs. Across at least four observed variants, the loader underpins simultaneous espionage campaigns in South-East Asia and Latin America, including targeting of a…
-
Critical Gitea Flaw Lets Public-Only Tokens Write to Private Repositories and Trigger Actions Workflows
Gitea administrators are strongly encouraged to upgrade their systems following the discovery of a critical authorization vulnerability. This flaw allows public-only API tokens to modify private pull request branches and potentially trigger Gitea Actions workflows. The vulnerability, tracked as CVE-2026-58443 and GHSA-xxjv-752h-3vp2, affects Gitea versions up to and including 1.26.4. The issue has been resolved…

