Security News

Let there be light: Ensuring visibility across the entire API lifecycle
2021-12-02 05:41

The following article is based on a webinar series on enterprise API security by Imvision, featuring expert speakers from IBM, Deloitte, Maersk, and Imvision discussing the importance of centralizing an organization's visibility of its APIs as a way to accelerate remediation efforts and improve the overall security posture. In these organizations, it is imperative to have a centralized API location with deployment into each of these locations, to ensure greater visibility and better management of API-related business activities.

API security awareness: The first step to better assessing the risk
2021-12-01 05:30

In this Help Net Security interview, Tal Steinherz, CTO at Wib, talks about the importance of API security awareness and how to tackle numerous thretas that are plaguing it. API security is widely being considered, yet breaches continue to plague many organizations.

Lack of API visibility undermines basic principle of security
2021-11-19 06:30

The new visibility challenge, with so much core business depending on interconnecting processes and data via APIs, requires that companies need to know what APIs they expose externally and internally and how they should behave. Traditional tools, such as WAFs and API Gateways were built for a different purpose and lack the ability to discover APIs and provide a complete inventory of them.

Bots are lurking in your zombie and shadow APIs
2021-11-18 06:35

Zombie APIs commonly arise when old and less secure versions of your APIs are left to live another day. For some reason, finding shadow and zombie APIs seems to be a much easier task for bad actors than it is for internal security and risk teams.

API sprawl: A threat you might want to address later, but you can’t ignore it
2021-11-09 06:00

Continuous software development results in the frequent release of new API versions. API sprawl introduces significant operational and security challenges.

Our journey to API security at Raiffeisen Bank International
2021-11-04 06:21

This article was written by Peter Gerdenitsch, Group CISO at Raiffeisen Bank International, and is based on a presentation given during Imvision's Executive Education Program, a series of events focused on how enterprises are taking charge of the API security lifecycle. We've got an API security course and cloud security course to deepen our security-related knowledge in these domains.

Our journey to API security at Raiffeisen Bank International
2021-11-04 06:21

This article was written by Peter Gerdenitsch, Group CISO at Raiffeisen Bank International, and is based on a presentation given during Imvision's Executive Education Program, a series of events focused on how enterprises are taking charge of the API security lifecycle. We've got an API security course and cloud security course to deepen our security-related knowledge in these domains.

Predicting the Next OWASP API Security Top 10
2021-11-03 17:05

API security risk has dramatically evolved in the last two years. Jason Kent, Hacker-in-Residence at Cequence Security, discusses the top API security concerns today and how to address them.

Only 2% of IT practitioners are confident in their organization’s ability to reduce API security issues
2021-11-03 04:00

API security issues: Enterpises must apply a zero trust approach. The findings revealed that only a staggering 2% of enterprise IT practitioners in these industries feel completely confident in their organization's ability to reduce API security issues such as unauthorized access, data privacy, compliance risk and security threats.

Financial services need to prioritize API security to protect their customers
2021-11-01 04:30

Whether pursued as a compliance requirement or a business strategy, open banking has ignited financial services firms to focus on APIs and API security. Financial services API security issues 54 of the 55 mobile apps that were reverse engineered contained hardcoded API keys and tokens including usernames and passwords to third-party services.