Four common API vulnerabilities and how to prevent them

Proper security measures are one of the most important aspects of building an application programming interface, or API. It’s great for an API to connect systems and give developers access to the data and functions they need to create new apps and digi… Continue reading Four common API vulnerabilities and how to prevent them

Firefox news: Fresh releases, Firefox Quantum for Enterprise, privacy protections

Firefox 59 (for desktop and mobile) and Firefox ESR 52.7 have been released to the public. Privacy enhancements and security fixes The former sports some performance enhancements that should lead to faster load times, new search engine options for Germ… Continue reading Firefox news: Fresh releases, Firefox Quantum for Enterprise, privacy protections

Security Strategies for DevOps, APIs, Containers and Microservices

More and more IT professionals see DevSecOps, a practice which integrates security measures earlier in the development process to improve production code quality, as a mainstay for future application development. Much of this stems from the growing tre… Continue reading Security Strategies for DevOps, APIs, Containers and Microservices

Hundreds of GPS Location Tracking Services Leaving User Data Open to Hackers

Security researchers have unearthed multiple vulnerabilities in hundreds of GPS services that could enable attackers to expose a whole host of sensitive data on millions of online location tracking devices managed by vulnerable GPS services.

The serie… Continue reading Hundreds of GPS Location Tracking Services Leaving User Data Open to Hackers

DLP APIs: The next frontier for Data Loss Prevention

According to the Breach Level Index, there have been 7,094,922,061 data records lost or stolen since 2013 with 4,417,760 records lost or stolen every day, 184,073 records every hour, 3,068 records every minute and 51 every second. There are more and more signs showing that the infosec paradigm has to change. The data security violations’ impact, as we have learnt throughout the years, is extending to more than the business environment, affecting hospitals, public institutions, … More Continue reading DLP APIs: The next frontier for Data Loss Prevention

Introducing security into software through APIs

Application programming interfaces (APIs) can make life easier for software developers, allowing them to concentrate on what they do best and preventing them from being forced to fiddle with things they know little about. Identity and Access Management APIs APIs are also a great way to implement/enhance the information security aspects of a product. One good example of this are IAM (Identity and Access Management) APIs. “An API receives so much data that it can … More Continue reading Introducing security into software through APIs

OWASP set to address API security risks

OWASP has started a new project and is set to publish a new guide on security risks. The issue they aim to tackle this time is API security. The new OWASP API Security Project has been introduced at the recently concluded NolaCon, by project leader David Shaw and colleague Leif Dreizler (presentation recorded by Adrian Crenshaw): The goal of the project is to provide software developers and security assessors with information about the risks brought … More Continue reading OWASP set to address API security risks