APIsecurity.io

@apisecurityio

API security news, standards, vulnerabilities, tools.

Liittynyt syyskuu 2018

Twiitit

Olet estänyt käyttäjän @apisecurityio

Haluatko varmasti nähdä nämä twiitit? Twiittien näyttäminen ei poista käyttäjän @apisecurityio estoa.

  1. 21 tuntia sitten

    Today we feature a comprehensive guide on API security design best practices from Yuri Kopylovski. This should prove useful to API developers particularly the coverage of error handling and anti-patterns to be aware of.

    Kumoa
  2. 13. jouluk.

    A new report from suggests that the number of APIs may now number 200 million globally — “If data is the new oil, then APIs will become the new plastic.” Read further to understand how to mitigate and manage this sprawl.

    Kumoa
  3. 13. jouluk.

    Scoring a perfect 10 on the CVSS scale the ‘Log4Shell’ vulnerability poses a critical threat to applications using Java logging package Apache Log4j.

    Kumoa
  4. 9. jouluk.

    API Security weekly newsletter issue #163 is out. Main stories this week from on why API security strategy fails, at on API good design, and on the biggest API attacks in 2021.

    Kumoa
  5. 8. jouluk.

    Last week was AWS re:Invent and in the keynote CTO Werner Vogels addressed 6 rules for good API design — good to see APIs receiving prominent attention they deserve.

    Kumoa
  6. 7. jouluk.

    As we head to the end of the year a recap of some big API security breaches in 2021 — "For as long as security remains an afterthought in the development life cycle, hackers will continue to successfully exploit API security flaws."

    Kumoa
  7. 6. jouluk.

    "The disconnect between the necessity of application programming interfaces (APIs) and their horrible reputation as security black holes" — views from 's Vijoy Pandey on API security in

    Kumoa
  8. 3. jouluk.

    Seven reasons your API security is failing — most important for me is "Putting the onus of API security on the developer"

    Kumoa
  9. 3. jouluk.

    API Security weekly newsletter issue #162 is out. Main stories this week from on GCP vulnerabilities, on GraphQL, André Rainho' Awesome API security list, and on API security training.

    Kumoa
  10. 1. jouluk.

    There are several API security guides online but this has to be the most comprehensive: Awesome API Security from André Rainho. Absolutely guaranteed to be something for everyone in here.

    Kumoa
  11. 30. marrask.

    Interesting read from on utilizing GraphQL as an enterprise API Gateway enabling security features such as depth limiting, rate limiting, and query cost limitations.

    Kumoa
  12. 29. marrask.

    Threat Horizons report published into vulnerable Google Cloud Platforms — "in most cases, the unauthorized access was attributed to the use of weak or no passwords for user accounts or API connections (48%)"

    Kumoa
  13. 26. marrask.

    Always good to see new API security training courses and this one is no exception: check out the 2021 guide to API security

    Kumoa
  14. 25. marrask.

    API Security weekly newsletter issue #161 is out. Main stories this week from on a vulnerability in Wipro Holmes Orchestrator, tips for API security from , research from and views from on shift-left from

    Kumoa
  15. 24. marrask.

    Today we have an excellent resource from on API security tips — there are some really good insights in here, many of them real quick wins for any API developer. Definitely one to bookmark!

    Kumoa
  16. 23. marrask.

    Today I'm featured in the ST Times discussing how a developer-first approach can benefit both development and security teams by embedding "security as code" into your software build process.

    Kumoa
  17. 22. marrask.

    A vulnerability CVE-2021-38146 was disclosed in the Wipro Holmes Orchestrator file download API allowing for arbitrary file download via path manipulation. Further details here:

    Kumoa
  18. 19. marrask.

    Latest research from featured in a report “Scorched Earth: Hacking Bank APIs” — accessing 55 banks through their APIs, giving her the ability to change customers' PIN codes and move money in and out of customer accounts.

    Kumoa
  19. 18. marrask.

    API Security weekly newsletter issue #160 is out. Main stories this week include stories on AWS API gateway vulnerabilities from , K8S API hardening from , on API security, and Jason Kent.

    Kumoa
  20. 17. marrask.

    Interesting views from Jason Kent on a possible update to the OWASP API Security Top 10 — definitely a shift in focus toward upfront design.

    Kumoa

Lataaminen näyttää kestävän hetken.

Twitter saattaa olla ruuhkautunut tai ongelma on muuten hetkellinen. Yritä uudelleen tai käy Twitterin tilasivulla saadaksesi lisätietoja.

    Saatat pitää myös

    ·