The CISOs Report, Perspectives, Challenges and Plans for 2022 and Beyond, reveals that Chief Information Security Officers (CISOs) are grappling with a wide range of risks and challenges, especially linked to accelerating utilization of technologies like cloud-based applications and the use of Application Programming Interfaces (APIs).
Tony Lauro, director of security and strategy for Akamai, said it appears that cybercriminals are now squarely focused on exploiting vulnerabilities in web applications and APIs. The bulk of APIs are now regularly inspected so as they continue to proliferate, they have become a favored target that can be easily compromised, he noted.
Open banking’s reliance on APIs has made them prime targets for cyber attacks. API security threats have increased in frequency and complexity.
Notably, there is a trend towards banks offering more APIs, indicated by a 17% increase in APIs offered per bank. The APIs now cover a broader variety of common banking functionalities, but account information (for various account types), payment initiation (for various payment instruments) and payment management (for various user-initiated actions around the payment) still top the list.
According to Joachim Herschmann, senior director and analyst on the application design and development team at Gartner, the number of APIs in applications has grown tremendously over the past few years because APIs offer a great way to extend the functionality of an application without having to write code. However, the sheer number of API tests has created many challenges for developers; challenges that are similar to those in other types of testing.
Ownership of an API is dynamic and is bound to change over time based on the changing needs of an Organization, API consumer, career growth, and changes of the assigned owner. However, both the Business and IT API owners are responsible for keeping the API flexible, operable, and secure.
In the digitally transformed world, APIs suddenly are among the hottest attack vectors. Yet too many organizations fail to even have visibility into their API inventory, much less security. Oz Golan, CEO of Noname Security, discusses API security trends.
What are Shadow and Zombie APIs? Both of them create API security risks, and modern API management needs to make sure that they are being properly managed. The larger an organization is, the harder (and the more important) it gets to have a complete and accurate overview of its API landscape. In order to manage risk, getting such an overview is an important first step.
Alissa Knight discusses previous API research on the FHIR ecosystem, including vulnerabilities caused by data aggregators and app developers, which pose data privacy and security concerns. Knight will examine potential solutions to securing the backbone of the healthcare sector's interoperability plan.
Learn GitLab CI/CD by building a complete CICD pipeline for a python demo project | with Docker
Software code has come under attack in innovative and deeply troubling ways, says Noname Security Co-founder and CTO Shay Levi. These attacks have altered the security landscape for both developers and their organizations, not to mention their suppliers, partners, and customers. API security testing has emerged as one solution, as has a more proactive approach to application security, without impededing development speed and efficiency, Levi says.
If you are a bit of an AI/ML enthousiast you should check out "Making Friends with Machine Learning" by Cassie Kozyrkov, it was an internal-only Google course specially created to inspire beginners and amuse experts. Today, it is available to everyone!
Disclaimer: The author of this newsletter is employed by Noname Security, but this is not an official Nonane Security publication, the newsletter is meant to provide independent API Security News. I encourage you to reach out with comments and/or suggestions for the newsletter via https://twitter.com/filipv (DM’s are open).
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.