APIs are a huge attack surface, and they’re often overlooked during security assessments.

Corey Ball: “You can design an API you think is ultra-secure, but if you don’t test it, then a cybercriminal somewhere is going to do it for you. You need to be able to scan your APIs - and this mea ...

Continue Reading
I am a big fan of this book.

I think it is an excellent resource for anyone who wants to learn more about the history of science and how we know what we know. It’s not just about physics, but also chemistry, biology, geology, as ...

Continue Reading
If you pick a random GraphQL framework and run it with default settings in production, disaster is waiting to happen.

2. The GraphQL Schema# The schema defines the structure of your API, including all possible queries and mutations that can be executed against it. It's also used by the client-side library to generat ...

Continue Reading
SoundCloud’s API was vulnerable to DoS attacks.

On the other hand, SoundCloud's API had no rate-limiting mechanism for some endpoints such as /me/following and /me/followers . This means that an attacker could have followed or unfollowed any number ...

Continue Reading
I’m a software engineer with experience in both front-end and back-end development.

I have worked on several projects, including an online game (with over 100k users), a social network for gamers, and various other web applications. I am currently working as the lead developer at The ...

Continue Reading
The Mayhem for Code and Mayhem for API products are now available.

Mayhem is an automated security testing solution that finds vulnerabilities in code, APIs, and microservices. It's the first product to combine fuzzing with random testing to find bugs that other tool ...

Continue Reading
We’re excited to announce that we have released the first version of our new API Gateway, which adds a number of new features and enhancements.

In addition to being able to create custom APIs from scratch, you can now use the gateway as an API proxy for existing RESTful web services. This allows you to add authentication and authorization cap ...

Continue Reading
We’re excited to be recognized by Gartner in the Hype Cycle for Application Security, Market Guide for Online Fraud Detection and Prevention, and API Security: Protect your APIs from Attacks and Data Breaches webinar.

We look forward to continuing our work with customers across the globe on their API-first initiatives https://t.co/PiF3pbB1qz ...

Continue Reading

Back to Main

Subscribe for the latest news: