apisecurityio Profile Banner
APIsecurity.io Profile
APIsecurity.io

@apisecurityio

Followers
4K
Following
131
Media
117
Statuses
2K

API security news, standards, vulnerabilities, tools.

Joined September 2018
Don't wanna be here? Send us removal request.
@apisecurityio
APIsecurity.io
13 days
In Issue 275 of our #APIsecurity newsletter the theme is: how secure is your API security? Included are two recent attacks on major financial platforms, a new industry survey, and technical deep-dives into JWT flaws and host header injection attacks.
Tweet media one
0
0
1
@apisecurityio
APIsecurity.io
2 days
The rise of Business Logic Attacks on APIs.
0
0
2
@apisecurityio
APIsecurity.io
6 days
Researchers hack Internal API using IDOR / BOLA attack to gain McDonald's job application data.
0
0
0
@apisecurityio
APIsecurity.io
6 days
Why APIs are vital for AI success. #API #AI #APIsecurity.
0
0
0
@apisecurityio
APIsecurity.io
8 days
Even Stalkerware app has API security issues.
0
0
0
@apisecurityio
APIsecurity.io
9 days
Hard coded API key and no access rules opens up Food Delivery App.
0
0
1
@apisecurityio
APIsecurity.io
13 days
Oversight in the API design led to the VPN connection shared key retrieval being implemented as a GET request, bypassing intended security controls.
0
0
1
@apisecurityio
APIsecurity.io
14 days
".measures must get beyond MFA, and incorporate a comprehensive zero-trust approach to API security.".
0
0
0
@apisecurityio
APIsecurity.io
15 days
Cisco release patches linked with APIs that allow insufficient input validation and malicious file uploads.
0
0
0
@apisecurityio
APIsecurity.io
22 days
Hard coded API key and no access rules opens up backend of food delivery app.
0
0
1
@apisecurityio
APIsecurity.io
24 days
Malicious popup on blockchain security service provider linked with backend API vulnerability.
0
0
0
@apisecurityio
APIsecurity.io
27 days
API authorization gone wrong. Real-world authorization failures, case studies with lessons for API security teams, missteps that led to a £2.3M fine for 23andMe, data exposure from the Asana MCP and a new resource on securing OAuth for cloud native APIs.
Tweet media one
0
0
0
@apisecurityio
APIsecurity.io
30 days
AI zero-day attacks and undocumented APIs are some of the major challenges facing security teams.
0
0
2
@apisecurityio
APIsecurity.io
1 month
Beware of LLM hijacking and system prompt leakage.
0
0
0
@apisecurityio
APIsecurity.io
1 month
An unsafe deserialization issue affecting Wazuh servers was accessible via API.
0
0
0
@apisecurityio
APIsecurity.io
1 month
APIs are the backbone of an AI strategy.
0
0
0
@apisecurityio
APIsecurity.io
1 month
In Issue 273, a case of humans spoofing AI, three real-world OWASP API Security attacks, insights on rising API attack trends and explore how GitHub’s MCP vulnerability may signal a new set of authorization challenges.
Tweet media one
0
0
0
@apisecurityio
APIsecurity.io
1 month
Splunk REST endpoint vulnerable to XSS attack.
0
0
3
@apisecurityio
APIsecurity.io
1 month
Reducing development costs through early security practices.
0
0
0
@apisecurityio
APIsecurity.io
1 month
Hacker Claims Massive TikTok Data Breach via API Exploit.
0
0
1