Tag: api
-
Twilio’s Authy Breach: The Attack via an Unsecured API Endpoint
A recap of Twilio’s Authy app breach, which exposed 33 million phone numbers. Including the impacts, lessons learnt and recommendations to enhance you… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/twilios-authy-breach-the-attack-via-an-unsecured-api-endpoint/
-
Understanding API Key Verification
Tags: apiAs organizations look to improve their API security, two distinct approaches to API key verification have emerged, centralized and decentralized verif… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/understanding-api-key-verification/
-
Breach Debrief Series: Twilio’s Authy Breach is a MFA Wakeup Call
Inside the Hack Earlier this week, Twilio issued a security alert informing customers that hackers had exploited a security lapse in the Authy API to … First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/breach-debrief-series-twilios-authy-breach-is-a-mfa-wakeup-call/
-
Authy: Hacker greifen Millionen von Telefonnumern über eine ungesicherte API ab
Nachdem Kriminelle eine CSV-Datei mit Telefonnummern von angeblich 33 Millionen Authy-Nutzern geleakt haben, drohen unter anderem SMS-Phishing-Attacke… First seen on heise.de Jump to article: www.heise.de/news/MFA-App-Authy-Unzaehlige-Telefonnummern-ueber-ungesicherte-API-abgegriffen-9789229.html
-
MFA-App Authy: Unzählige Telefonnummern über ungesicherte API abgegriffen
Nachdem Kriminelle eine CSV-Datei mit Telefonnummern von angeblich 33 Millionen Authy-Nutzern geleakt haben, drohen unter anderem SMS-Phishing-Attacke… First seen on heise.de Jump to article: www.heise.de/news/MFA-App-Authy-Unzaehlige-Telefonnummern-ueber-ungesicherte-API-abgegriffen-9789229.html
-
Weaponizing API discovery metadata
Tags: apiFirst seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/weaponizing-api-discovery-metadata/
-
An Analysis of Kuppinger Cole’s Selection Criteria for API Management and Security
Tags: apiFirst seen on securityboulevard.com Jump to article: securityboulevard.com/2024/07/an-analysis-of-kuppinger-coles-selection-criteria-for-api-management-and-security/
-
Sicherheitslücke in Gefängnis-Telefonanlage legt sensible Daten offen
Sicherheitsforscherin Lilith Wittmann hat eine schwere Sicherheitslücke in der API einer Gefängnis-Telefonanlage öffentlich gemacht. Über die API konn… First seen on borncity.com Jump to article: www.borncity.com/blog/2024/06/27/sicherheitslcke-in-gefngnis-telefonanlage-legt-sensible-daten-offen/
-
What is Crowdsourced Penetration Testing: Benefits,Risks,Comparisons
Organisations of all sizes rely heavily on new technology such as cloud, mobile, web applications, and APIs, making them prime targets for cyberattack… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/what-is-crowdsourced-penetration-testing-benefitsriskscomparisons/
-
New Malware Targets Exposed Docker APIs for Cryptocurrency Mining
Cybersecurity researchers have uncovered a new malware campaign that targets publicly exposed Docket API endpoints with the aim of delivering cryptocu… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/new-malware-targets-exposed-docker-apis.html
-
6 Tips for Preventing DDoS Attacks Using Rate Limits
Rate limiting is a well-known technique for limiting network traffic to web servers, APIs, or other online services. It is also one of the methods ava… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/6-tips-for-preventing-ddos-attacks-using-rate-limits/
-
Salt Security Survey Reveals 95% of Respondents Experienced API Security Problems in Past Year
Tags: apiAPI security professionals at Salt Security have revealed the findings of their latest Salt Labs State of API Security Report, 2024. The research, whi… First seen on itsecurityguru.org Jump to article: www.itsecurityguru.org/2024/06/18/salt-security-survey-reveals-95-of-respondents-experienced-api-security-problems-in-past-year
-
Developer errors lead to long-term exposure of sensitive data in Git repos
Credentials, API tokens, and passkeys collectively referred to as secrets from organizations around the globe were exposed for years, according to Aqu… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/26/git-exposed-secrets/
-
Coding Error In Forgotten API Blamed For Massive Data Breach
First seen on packetstormsecurity.com Jump to article: packetstormsecurity.com/news/view/36018/Coding-Error-In-Forgotten-API-Blamed-For-Massive-Data-Breach.html
-
How to build a Copilot for Security API Plugin Part 1
Tags: apiFirst seen on thesecurityblogger.com Jump to article: www.thesecurityblogger.com/how-to-build-a-copilot-for-security-api-plugin-part-1/
-
Chrome for Android tests feature that securely verifies your ID with sites
Google is testing a new feature called Digital Credential API for Chrome on Android that will allow websites to request identity information from mobi… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/google/chrome-for-android-tests-feature-that-securely-verifies-your-id-with-sites/
-
FireTail Unveils Free Access for All to Cutting-Edge API Security Platform
First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/firetail-unveils-free-access-for-all-to-cutting-edge-api-security-platform/
-
Hacking APIs with HTTPie
First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/hacking-apis-with-httpie/
-
Quarter of Firms Suffer an API-Related Breach
First seen on infosecurity-magazine.com Jump to article: www.infosecurity-magazine.com/news/quarter-firms-suffer-api-related/
-
Hackers Attacking Vaults, Buckets, And Secrets To Steal Data
Hackers target vaults, buckets, and secrets to access some of the most classified and valuable information, including API keys, logins, and other usef… First seen on gbhackers.com Jump to article: gbhackers.com/hackers-attacking-vaults-buckets-secrets/
-
How bots abuse APIs and tips to protect against it
Tags: apiFirst seen on scmagazine.com Jump to article: www.scmagazine.com/native/how-bots-abuse-apis-and-tips-to-protect-against-it
-
Simplifying Azure Key Vault Updates With AppViewX Automation
Azure Key Vault service offers a secure storage solution for cryptographic keys, API keys, passwords, and certificates in the cloud. However, managing… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/simplifying-azure-key-vault-updates-with-appviewx-automation/
-
Novel malware campaign sets sights on misconfigured Docker APIs
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/novel-malware-campaign-sets-sights-on-misconfigured-docker-apis
-
Lack of visibility into APIs leaves blind spots, says new study
Tags: apiFirst seen on scmagazine.com Jump to article: www.scmagazine.com/news/lack-of-visibility-into-apis-leaves-blind-spots-says-new-study
-
PCI DSS 4.0.1: New Clarifications on Client-Side Security What You Need to Know
As a leading provider of web application and API security solutions, Imperva is committed to helping merchants, payment processors, and anyone seeking… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/pci-dss-4-0-1-new-clarifications-on-client-side-security-what-you-need-to-know/
-
Cryptojacking campaign targets exposed Docker APIs
A malware campaign targets publicly exposed Docker API endpoints to deliver cryptocurrency miners and other payloads. Researchers at Datadog uncovered… First seen on securityaffairs.com Jump to article: securityaffairs.com/164668/cyber-crime/malware-campaign-docker-api-endpoints.html
-
Understanding the Dell Data Breach | Impart Security
Recently, Dell faced a significant data breach, where a threat actor exploited API vulnerabilities to steal 49 m… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/understanding-the-dell-data-breach-impart-security/
-
Hackers Employing New Techniques To Attack Docker API
Attackers behind Spinning YARN launched a new cryptojacking campaign targeting publicly exposed Docker Engine hosts by using new binaries chkstart (re… First seen on gbhackers.com Jump to article: gbhackers.com/new-hacking-techniques-docker-api/
-
42% plan to use API security for AI data protection
While 75% of enterprises are implementing AI, 72% report significant data quality issues and an inability to scale data practices, according to F5. Da… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/18/ai-widespread-implementation-challenge/
-
APIs: The Silent Heroes of Data Center Management
In the intricate ecosystem of data center operations, managing and optimizing infrastructure is a complex, continuous task. Data Center Infrastructure… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/apis-the-silent-heroes-of-data-center-management/

