-
Issue 227: GhostToken on Google Cloud, Gartner on zero trust, API authentication Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 226 : Jetpack WordPress plugin has API vulnerability, how to address API security in 2023 Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 225 : API security needs a reset, vAPI walkthrough, five stages to attain API security Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 224 : API security is critical in 2023, API contract testing, and Fencer security testing tool Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 223 : Becoming an API security expert, AI for API hackers, building API cross-functional teams Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 222: Attackers exploiting APIs faster than ever, DVGA walkthrough, Twitter outage Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 221: Credential leakage fueling API breaches, API gateway security, PCI DSS 4 impact on API security Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 220: API flaw in Booking.com, apps leaking sensitive API data, API security testing checklist Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 219: Money Lover app exposes user data, most web API flaws missed by standard testing Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 218: Three Argo CD API exploits, distributed identity for modern API security Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 217: Wordle API exposes answers, Twitter API breach updates, AWS exposed dangerous API Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 216: Hacking a .Net application, state of API security report, myths of API security Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 215: API flaws in Lego marketplace, API style guides, 42Crunch joins MISA Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 214: Google Cloud’s four pillars of API security, Cerbos for API permissions, attacking predictable GUIDs Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 213: Supply chain vulnerability in IBM Cloud, hardcoded API keys in Algolia portal, JSON-based SQL attacks Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 212: Remote control of vehicles, API hacking for QA teams, API Top 10 walkthrough Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 211: SQLi vulnerability in Zendesk Explore, Twitter API vulnerability, API threats to data-driven enterprises Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 210: CSRF vulnerability in F5, supply chain attacks, hacking APIs, GCP API security report Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 209: CSRF in Plesk API-enabled server, top five API security myths, Ory Hydra authentication server Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 208: Urlscan.io leaks sensitive data, Dropbox phishing attack, contract test for microservices Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 207: Tinder API gateway, runtime secrets protection for mobile APIs, and Open Banking APIs Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 205: Manufacturing industry seeing more API incidents than other industries, two guides on developing secure APIs Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 204: API attacks on shadow APIs, PII leaks from e-commerce APIs, API runtime security Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 203: Optus data breach, API security guide, AuthN/AuthZ vulnerabilities Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 202: Six top API security risks, why APIs have no clothes, and a guide on API security testing Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 201: API security in Kubernetes, Corey Ball podcast, broken access controls for APIs, 200th issue prize giveaway Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 200: Injection vulnerability in BitBucket, OAuth2 exploitation, and 200th issue prize giveaways Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 199: Vulnerability in Zulip server, broken access controls threat to APIs, introduction to BOLA Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 198: API security certification, API authentication webinar, optimizing API security Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 197: Apps leaking Twitter tokens, parameter smuggling attack in Golang, API catalogs for security Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 196: Software supply chains, APIs in healthcare, Azure API management baselines Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 195: How DevOps teams defend against API attacks, empathy for the API developer Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 194: API testing checklist, API security testing resources, CVSS for API security Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 193: Five API security best practices, AppSec tools for APIs Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 192: Vulnerable APIs costing $75 billion, new Google API security platform Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 191: API insecurity causing rising incidents, policy-as-code for API security Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 190: Akamai’s report on APIs, API security checklist, dangers of API security overconfidence Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 189: Vulnerability in Travis CI log API, Microsoft guide to API security, and why API security needs special attention Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 188: API security for smart cars, ownership of the API lifecycle, APIs a top CISO concern Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 187: RCE and API vulnerability in OAS platform, account takeover in Yunmai smart scale Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 186: Kubernetes API servers exposed, vulnerability in Swagger-UI library, Google views on API economy Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 185: Three trends in API security, GraphQL securing risks, the importance of API discovery Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 184: RCE in F5 BIG-IP suite, API security maturity, hardening GCP implementations Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 183: API vulnerability in VeryFitPro, exposed Docker APIs targeted by botnets, TruffleHog finds stored credentials Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 182: Drupal patches API vulnerability, Google Cloud on API security challenges, guide to OAuth2 Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 181: Vulnerability in Wavlink router, API exposing system passwords, views on internal APIs Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 180: API vulnerability in Easy!Appointments platform, new APIs compromising security Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 179: Spring4Shell zero-day, CRI-O container runtime vulnerability, and REST API security reference Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 178: Six areas for Cloud-native security, API governance, DevOps for improved API security, locking down APIs Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 177: Vulnerabilities in Veeam product, RCE in Parse Server module, insecure API threat to mobile apps Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 176: Case study of API vulnerabilities, Riverbed vulnerability, API abuse, JWT safety Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 175: Vulnerabilities affecting Cisco platforms, GitLab instances, and campus access control Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 174: APIs increasingly used for account takeover, API hacking book, OAuth in Postman Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 173: Coinbase vulnerability, AuthN/AuthZ best practices, bad bots, Elgato Key light hack Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 172: Argo CD vulnerability, state of API security survey, API testing with Zap and Postman Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 171: DPD parcel tracking flaw, Apache Pulsar and Casdoor vulnerabilities, trends in API industry Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 170: DevSecOps approach to API security, F5 vulnerabilities, ten API integration trends Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 169: Insecure API in WordPress plugin, Tesla 3rd party vulnerability, introducing vAPI Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 168: Safari 15 IndexedDB API vulnerability, a pair of AWS vulnerabilities, and an API security podcast Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 167: Uber bug allows spoof emails, partner-facing APIs on the rise, omnichannel APIs increase risk Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 166: Securing large API ecosystems, creating OpenAPI from HTTP traffic, Frankenstein APIs, and API proliferation Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 165: Vulnerability in All in One WordPress plugin, why to treat all APIs as public, a beginner’s guide to API security Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 164: Log4Shell vulnerability, API sprawl an increasing threat, API security design best practices, Zero Trust for APIs Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 163: Why API security strategies fail, AWS keynote on good API design, biggest breaches in 2021 Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 162: Compromised Google Cloud accounts, GraphQL as API gateway, API security guide and training Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 161: Vulnerability in Wipro Holmes Orchestrator, report into vulnerabilities in FinTech and banking apps Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 160: Vulnerability in AWS API gateway, Kubernetes API access hardening guide Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 159: Vulnerability in GoCD CI/CD platform, views on full lifecycle API security, articles on API security and sprawl Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 158: Data of 400 000 students exposed, 1 million sites affected by plugin vulnerabilities, views on GraphQL Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 157: Unsafe defaults in Prometheus, mapping API attack surfaces, OpenAPI file trend analysis Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 156: FHIR APIs vulnerable to abuse, 3D printers facing hijacking risk, API security webinar Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 155: Vulnerability in BrewDog mobile app, APIClarity at KubeCon, API attacks in Open Banking Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 154: Views on APIs and security, report into API misconfiguration, detecting malicious API activity Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 153: Rapid proliferation of APIs, WordPress API vulnerability, false-negative API scanning Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 152: Exposed API keys and tokens, SAST/DAST for API security testing, the value of API specifications Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 151: WordPress 5.8.1 security patch, API botnet attacks report, articles on API tokens and API discovery Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 150: Vulnerability in Fortress home security system, API fuzzing techniques, hardening GraphQL implementations, and central governance for APIs Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 149: Vulnerabilities on Cisco routers and Bumble, adopting Zero Trust for APIs, a hacker’s view on API security challenges Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 148: Microsoft Power Apps breach, BOLA on Topcoder portal, RFC 9101 released, API hacking guide Posted on by Colin Domoney
in
Newsletter Archive
-
Issue 147: Vulnerabilities in SEOPress plugin and Steam portal, results from an application security survey Posted on by Colin Domoney
in
Newsletter Archive