Aite Group Research Validates API Security Gaps

2020 is moving into the final quarter and it appears to be the year of the API security incident with MGM, Starbucks, Data Viper and Docker as just a few examples of API security incidents. The reasons are obvious – API use has exploded for both develo… Continue reading Aite Group Research Validates API Security Gaps

Swap Detector: Open source tool for detecting API usage errors

GrammaTech has released Swap Detector, an open source tool that enables developers and DevOps teams to identify errors due to swapped function arguments, which can also be present in deployed code. The tool, developed as part of a research project spon… Continue reading Swap Detector: Open source tool for detecting API usage errors

API Security Need to Know: Questions Every Executive Should Ask About Their APIs

Using NIST CSF to Reign in your API Footprint As your digital transformation accelerates, it’s API volume and usage has accelerated in tandem. It is also very likely that your API security efforts have lagged behind your increase in API usage. Un… Continue reading API Security Need to Know: Questions Every Executive Should Ask About Their APIs

Meetup vulnerabilities enabled group takeovers, payment redirections

Two high-risk vulnerabilities in Meetup, a popular online service that’s used to create groups that host local in-person events, allowed attackers to easily take over any Meetup group, access all group functions and assets, and redirect all Meetu… Continue reading Meetup vulnerabilities enabled group takeovers, payment redirections

Running ConnectWise Automate on-prem? Fix this high-risk API vulnerability

ConnectWise has fixed a high-severity vulnerability affecting a ConnectWise Automate API and is urging users who run the solution on their premises to implement the provided hotfixes. About ConnectWise Automate and the vulnerability ConnectWise is a pr… Continue reading Running ConnectWise Automate on-prem? Fix this high-risk API vulnerability

Understanding cyber threats to APIs

This is the fourth of a series of articles that introduces and explains API security threats, challenges, and solutions for participants in software development, operations, and protection. Security issues for APIs The many benefits that APIs bring to … Continue reading Understanding cyber threats to APIs

Factors driving API growth in industry

This is third in a series of articles that introduces and explains application programming interfaces (API) security threats, challenges, and solutions for participants in software development, operations, and protection. Explosion of APIs The API expl… Continue reading Factors driving API growth in industry

Understanding the basics of API security

This is the first of a series of articles that introduces and explains application programming interfaces (API) security threats, challenges, and solutions for participants in software development, operations, and protection. Purpose of article series … Continue reading Understanding the basics of API security