OAuth 2.

0 is still the most popular authorization protocol, but it has a number of limitations that are being addressed by OAuth 3.0 and OpenID Connect (OIDC). The main problem with OAuth 2.0 is that it does ...

Continue Reading
The session is an excellent introduction to the OAuth standard and its evolution, and also serves as a good refresher for those who have been working with it for years.

Video: GraphQL Security The conference apidays has published the recorded session “GraphQL Security” by Paul Dix. The talk covers how to secure your GraphQL API, including authentication, authoriza ...

Continue Reading
The data makes it clear: more companies are suffering more API attacks than ever, and companies remain as ill-prepared as ever.

The Salt Labs team today released the latest edition of the pioneering “State of API Security” report. The data, drawn from a combination of survey responses and empirical data from Salt Security cu ...

Continue Reading
API security is hard, but it’s not impossible.

This e-book offers a warning on what happens when you overestimate the security of your APIs. It provides a look into the tactics and techniques of API hacker Alissa Knight. This e-book covers: Wh ...

Continue Reading
The difference between the two is that one has a single-sided tail, and the other has a double-sided tail.

The only thing I can think of to explain this is that it's an artifact from how they're made. A single-sided tailed version would be easier to make in some ways (no need for extra material), but you'd ...

Continue Reading
This course is a great introduction to the OWASP Top 10 for software developers who are new to security.

It's not very technical, but it does cover all of the major topics in an easy-to-understand way. The Introduction to the OWASP API Security Top 10 course will teach students why API security is neede ...

Continue Reading
  Join us for a lively discussion on the top five common industry myths surrounding API security.

You'll learn the pitfalls of some misguided API security approaches, cut through the hype around a few security trends, and get recommendations on how to improve your organization's API security strat ...

Continue Reading
The Cequence Application Security Platform provides a comprehensive approach to API security that addresses the most difficult challenges enterprises face.

Cequence Bot Defense is an AI-based, runtime solution for preventing and detecting attacks from bots and other automated agents such as crawlers, scrapers or web robots. It uses machine learning algor ...

Continue Reading

Back to Main

Subscribe for the latest news: