apisecurityio Profile Banner
APIsecurity.io Profile
APIsecurity.io

@apisecurityio

Followers
4K
Following
131
Media
126
Statuses
2K

API security news, standards, vulnerabilities, tools.

Joined September 2018
Don't wanna be here? Send us removal request.
@apisecurityio
APIsecurity.io
14 days
In issue 284, vulnerabilities in trusted AI platforms, a blog post claiming an API BOLA vulnerability at Mercury Energy New Zealand, a recent interview exploring a range of API security topics and news of a new OWASP Top 10 list. https://t.co/YyZu5a5JSd #apisecurity #AIsecurity
0
0
0
@apisecurityio
APIsecurity.io
6 days
Threat Intelligence: Analysis of the NOFX AI Automated Trading Vulnerability https://t.co/0PS37qpLtq
Tweet card summary image
slowmist.medium.com
Although the NOFX project has undergone attempted fixes, the core issue remains unresolved.
0
0
1
@apisecurityio
APIsecurity.io
8 days
The OWASP Business Logic Abuse Top 10 complements and enhances existing OWASP Top 10 projects by providing a cross-domain focus on business logic vulnerabilities that transcend technology stacks https://t.co/QExSbuz7vc
Tweet card summary image
owasp.org
A very brief, one-line description of your project
0
1
2
@apisecurityio
APIsecurity.io
21 days
"..APIs are not just developer conveniences, they are business-critical assets that demand the same rigor as financial systems or customer databases..." https://t.co/WyYdGiJF2o #APIsecurity
0
1
1
@apisecurityio
APIsecurity.io
27 days
"AI is deeply intertwined with APIs, and organizations aren’t yet prepared for how these AI interfaces expand the attack surface..... AI security is API security.” https://t.co/WrWWYLhhzu
Tweet card summary image
channelinsider.com
Wallarm’s Q3 2025 API ThreatStats Report reveals a 20% rise in API flaws and a 270% surge in MCP risks, highlighting growing AI-API security threats.
0
0
1
@apisecurityio
APIsecurity.io
28 days
In issue 283, critical issues in the WSO2 API Manager and Better-Auth plugin, BOPLA vulnerability in a Formula 1, API security flaws in industrial devices and an interview with former CISA director on using AI to solve today’s security challenges. https://t.co/pIoYV5s6yf
0
1
1
@apisecurityio
APIsecurity.io
29 days
Marina Bay Sands fined over data breach. API omission during large software migration leaves customer data unprotected. https://t.co/XaMT26jB0I
Tweet card summary image
channelnewsasia.com
The leaked data, which included names and contact details that identified Marina Bay Sands' patrons, was later found offered for sale on the dark web.
0
0
1
@apisecurityio
APIsecurity.io
1 month
Hardcoded credentials, access tokens, and API keys are ending up in the darnedest places, prompting a call for organizations to stop over-privileging secrets. https://t.co/soAtzFKVFy
Tweet card summary image
darkreading.com
Hardcoded credentials, access tokens, and API keys end up in the darnedest places, prompting a call for organizations to stop over-privileging secrets.
0
0
0
@apisecurityio
APIsecurity.io
1 month
In issue 282, we examine the World Poker Tour website hack, the exposure of Nagios Log Server API credentials, the causes of API drift, common injection attacks targeting APIs, and how DDoS campaigns are increasingly focusing on API endpoints. https://t.co/c5uuQpKc8V #apisecurity
0
0
1
@apisecurityio
APIsecurity.io
2 months
Issue 281 of the https://t.co/gOdaGFM9Eb newsletter is out now. In this issue we examine OneLogin's API data leak, Cloudflare’s accidental API DoS, a critical Entra ID vulnerability, incidents of mass assignment and excessive data and more.. https://t.co/NeRnzj6V78 #apisecurity
0
0
0