Security News

No password? No worries! Two new standards aim to make logins an API experience
2018-04-11 05:30

WebAuthn and CTAP published this week A pair of authentication standards published this week have received endorsement from Mozilla, Microsoft and Google: the WebAuthn API, and the FIDO Alliance's...

Widespread API use heightens cybersecurity risks
2018-01-31 11:00

A new Imperva survey showed a heightened concern for cybersecurity risk related to API use. Specifically, 63 percent of respondents are most worried about DDoS threats, bot attacks, and...

Secure coding in Java: Bad online advice and confusing APIs
2017-10-03 15:15

For programmers and software developers, the Internet forums provide a great place to exchange knowledge and seek answers to concrete coding conundrums. Alas, they are not always the source of...

Using behavior analysis to solve API security problems
2017-09-12 14:00

When people think about complex security challenges, airport security might be the most familiar. The scope of challenges and implications of breaches are daunting. This is especially true when...

Attackers exploited Instagram API bug to access users’ contact info (Help Net Security)
2017-08-31 17:54

Instagram has confirmed that “one or more individuals obtained unlawful access to a number of high-profile Instagram users’ contact information — specifically email address and phone number — by...

Deprecated, Insecure Apple Authorization API Can Be Abused to Run Code at Root (Threatpost)
2017-08-24 14:32

An insecure Apple authorization API is used by numerous popular third-party application installers and can be abused by attackers ro run code as root.

Netflix Helps Identify APIs at Risk of Application DDoS Attacks (Security Week)
2017-08-01 16:41

Netflix has published tools and information to help defenders identify systems that could be leveraged by malicious actors for damaging application layer distributed denial-of-service (DDoS)...

VMware API Allows Limited vSphere Users to Access Guest OS (Security Week)
2017-07-28 14:30

LAS VEGAS - BLACK HAT USA - Researchers discovered that a VMware API can be abused by vSphere users with limited privileges to access the guest operating system without authentication. VMware has...

Elastic Beam Emerges From Stealth With API Security Solution (Security Week)
2017-06-21 12:39

Redwood City, Calif.-based Elastic Beam emerged from stealth mode on Wednesday with the launch of a security solution designed to detect and block cyberattacks targeting application programming...

DLP APIs: The next frontier for Data Loss Prevention (Help Net Security)
2017-06-19 14:00

According to the Breach Level Index, there have been 7,094,922,061 data records lost or stolen since 2013 with 4,417,760 records lost or stolen every day, 184,073 records every hour, 3,068 records...