Tag: api
-
7 Deadly Sins of API Security Testing
Tags: apiExplore the misconceptions and anti-patterns of applying security testing to APIs, and how to address them. The post the misconceptions and anti-patte… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/7-deadly-sins-of-api-security-testing/
-
Case Study: How Sungage Financial improved their application security within 1 week
Sungage Financial chose Escape’s API security solution to secure their new GraphQL APIs. Escape’s easy setup, actionable remediation, and GraphQL supp… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/case-study-how-sungage-financial-improved-their-application-security-within-1-week/
-
Solaris SE partners with Salt Security
Salt Security, the leading API security company, today announced that Solaris SE, Europe’s leading embedded finance platform, has deployed Salt Securi… First seen on itsecurityguru.org Jump to article: www.itsecurityguru.org/2024/05/30/solaris-se-partners-with-salt-security/
-
Three ways to deliver API security
Tags: apiFirst seen on scmagazine.com Jump to article: www.scmagazine.com/perspective/three-ways-to-deliver-api-security
-
Security challenges mount as companies handle thousands of APIs
Tags: apiModern applications are taking over enterprise portfolios, with apps classed as modern now making up 51% of the total, up by more than a quarter in th… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/04/companies-api-management-security/
-
Cox Communications Patches Newly Discovered Critical API Bug
Security Researcher Says Flaw Came From 700 Exposed APIs Belonging to Cox. An independent security researcher discovered a critical flaw in the backen… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/cox-communications-patches-newly-discovered-critical-api-bug-a-25409
-
Cox fixed an API auth bypass exposing millions of modems to attacks
‹Cox Communications has fixed an authorization bypass vulnerability that enabled remote attackers to abuse exposed backend APIs to reset millions of m… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cox-fixed-an-api-auth-bypass-exposing-millions-of-modems-to-attacks/
-
Why HAST is important to API hackers
Learn why Human Application Security Testing (HAST) is important to API hackers. The post y Human Application Security Testing (HAST) is important to … First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/why-hast-is-important-to-api-hackers/
-
Dropbox discloses data breach involving Dropbox Sign
A threat actor accessed Dropbox Sign customer names, emails and hashed passwords as well as API keys, OAuth tokens. multifactor authentication informa… First seen on techtarget.com Jump to article: www.techtarget.com/searchsecurity/news/366583233/Dropbox-discloses-data-breach-involving-Dropbox-Sign
-
Security challenges mount as as companies handle thousands of APIs
Tags: apiModern applications are taking over enterprise portfolios, with apps classed as modern now making up 51% of the total, up by more than a quarter in th… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/04/companies-api-management-security/
-
Impart Security: Leading the Charge in API Security with SOC 2 Type 2 Certification | Impart Security
We’re incredibly proud to share some exciting news at Impart Security: We’ve achieved SOC 2 Type 2 certification! This certification represents our un… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/impart-security-leading-the-charge-in-api-security-with-soc-2-type-2-certification-impart-security/
-
Ungeschützte API: Sicherheitslücke macht Studenten zu Wäsche-Millionären
In vielen Hochschulen und Wohnheimen stehen Wäscheautomaten von CSC Serviceworks. Zwei Studenten haben darin eine Sicherheitslücke entdeckt – mit erhe… First seen on golem.de Jump to article: www.golem.de/news/ungeschuetzte-api-sicherheitsluecke-macht-studenten-zu-waesche-millionaeren-2405-185242.html
-
Writing Burp extensions in Kotlin
Tags: apiLearn how to write Burp Suite extensions using the new Montoya API with Kotlin and Visual Studio Code (VS Code) The post w to write Burp Suite extensi… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/writing-burp-extensions-in-kotlin/
-
10 Ways a Digital Shield Protects Apps and APIs
Tags: apiFirst seen on darkreading.com Jump to article: www.darkreading.com/cloud-security/10-ways-a-digital-shield-protects-apps-and-apis-in-a-distributed-cloud-world
-
Apple API Allows Wi-Fi AP Location Tracking
Privacy FAIL: Apple location service returns far more data than it should, to people who have no business knowing it, without your permission. The pos… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/apple-wi-fi-location-privacy-richixbw/
-
API missbraucht: Hacker teilt Details zum Cyberangriff auf Dell
Ein Cyberkrimineller hat rund 49 Millionen Kundendatensätze von Dell abgegriffen. Möglich gewesen ist ihm dies über eine unzureichend geschützte API e… First seen on golem.de Jump to article: www.golem.de/news/api-missbraucht-hacker-teilt-details-zum-cyberangriff-auf-dell-2405-185010.html
-
Sensitive Data Detection using AI for API Hackers
Learn how to use artificial intelligence (AI) to discover sensitive data in the APIs you are hacking with the help of Microsoft Presidio. The post w t… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/sensitive-data-detection-using-ai-for-api-hackers/
-
49 Million Customers Impacted by API Security Flaw
How safe is your data? With the increasing reliance on online services, this question weighs heavily on everyone’s mind. The recent cyber incident ser… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/49-million-customers-impacted-by-api-security-flaw/
-
Shifting the Security Mindset: From Network to Application Defense
Web application development and usage are at an all-time high, but businesses aren’t sure which APIs to monitor or how to protect them. The post icati… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/shifting-the-security-mindset-from-network-to-application-defense/
-
An Open Letter to API Vendors: Embrace Secure Authentication Methods, Abandon API Keys
3 min read… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/an-open-letter-to-api-vendors-embrace-secure-authentication-methods-abandon-api-keys/
-
Dell Data Breach: Personal Information of 49 Million Customers Compromised due to latest API Abuse
Dell recently issued a notice regarding a data breach that occurred on May 9, which has reportedly affected over 49 million customers across the globe… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/dell-data-breach-personal-information-of-49-million-customers-compromised-due-to-latest-api-abuse/
-
Akamai confirms acquisition of Noname for $450M
Akamai will integrate Noname into its API Security business, and expects the acquisition deliver approximately $20 million of revenue in its fiscal ye… First seen on techcrunch.com Jump to article: techcrunch.com/2024/05/07/akamai-confirms-acquisition-of-noname-for-450m/
-
Hackers Increasingly Abusing Microsoft Graph API for Stealthy Malware Communications
Threat actors have been increasingly weaponizing Microsoft Graph API for malicious purposes with the aim of evading detection.This is done to facilita… First seen on thehackernews.com Jump to article: thehackernews.com/2024/05/hackers-increasingly-abusing-microsoft.html
-
Reverse Engineering Electron Apps to Discover APIs
Learn how to reverse engineer an Electron app to find artifacts like source code and API endpoints, and capture live traffic with Burp Suite. The post… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/reverse-engineering-electron-apps-to-discover-apis/
-
Salt Security Unveils First AI-Infused API Security Platform to Address Proliferation of GenAI Application Development
This week, Salt Security, a frontrunner in API security, have unveiled its groundbreaking API Security Protection Platform. This platform, powered by … First seen on itsecurityguru.org Jump to article: www.itsecurityguru.org/2024/05/08/salt-security-unveils-first-ai-infused-api-security-platform-to-address-proliferation-of-genai-application-development
-
RSAC 2024 Highlights, Connecting on API Security and Bot Management
Tags: apiAnother RSAC has wrapped! Thank you to everyone who stopped by our booth to learn how the Cequence Unified API Protection platform’s integrated API se… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/05/rsac-2024-highlights-connecting-on-api-security-and-bot-management/
-
Dell-Leak: Daten wochenlang über Dell-API abgezogen
Beim Computerhersteller Dell gab es ein Datenleck, bei dem ein Angreifer Daten von gut 49 Millionen Dell-Kunden abziehen konnte. Das sind wohl Daten a… First seen on borncity.com Jump to article: www.borncity.com/blog/2024/05/11/dell-leak-daten-wochenlang-ber-dell-api-abgezogen/
-
Dell reagierte nicht auf Warnung vor Diebstahl von Kundendaten
Während ein Angreifer über eine API von Dell Kundendaten abgriff, schickte er Mails an das Unternehmen. Das reagierte erst, als die Daten veröffentlic… First seen on heise.de Jump to article: www.heise.de/news/Dell-reagierte-nicht-auf-Warnung-vor-Diebstahl-von-Kundendaten-9714977.html
-
Dell API abused to steal 49 million customer records in data breach
The threat actor behind the recent Dell data breach revealed they scraped information of 49 million customer records using an partner portal API they … First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/dell-api-abused-to-steal-49-million-customer-records-in-data-breach/
-
CISO Corner: Verizon DBIR Lessons; Workplace Microaggression; Shadow APIs
Our collection of the most relevant reporting and industry perspectives for those guiding cybersecurity strategies and focused on SecOps. Also include… First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/ciso-corner-

