RSS Amplifier

API Security Newsletter · Jun 13, 2022

The API Security Newsletter - Issue #8

0
Sign in to vote or save

Filip Verloy · API Security Newsletter

Research surveying over 400 CISOs finds they are prioritizing Zero Trust and partner risk management to help mitigate critical security challenges.

The CISOs Report, Perspectives, Challenges and Plans for 2022 and Beyond, reveals that Chief Information Security Officers (CISOs) are grappling with a wide range of risks and challenges, especially linked to accelerating utilization of technologies like cloud-based applications and the use of Application Programming Interfaces (APIs).

A series of reports from Akamai showed web applications and APIs are now favorite targets for highly organized cybercriminal gangs.

Tony Lauro, director of security and strategy for Akamai, said it appears that cybercriminals are now squarely focused on exploiting vulnerabilities in web applications and APIs. The bulk of APIs are now regularly inspected so as they continue to proliferate, they have become a favored target that can be easily compromised, he noted.

Application programming interfaces (APIs) enable the needed connectivity for the transfer of financial data inherent to open banking.

Open banking’s reliance on APIs has made them prime targets for cyber attacks. API security threats have increased in frequency and complexity. 

INNOPAY’s Open Banking Monitor shows the efforts banks are making in expanding their API product off...

Notably, there is a trend towards banks offering more APIs, indicated by a 17% increase in APIs offered per bank. The APIs now cover a broader variety of common banking functionalities, but account information (for various account types), payment initiation (for various payment instruments) and payment management (for various user-initiated actions around the payment) still top the list.

Demand for healthcare services continues to accelerate at pace, heightened in the last two years by the pandemic and the knock-on effect of delayed operations and treatments, all of which is challenging the NHS. Healthcare technology innovation and the digitisation of worldwide healthcare services is seen as the way to overcome many of these challenges. Consequently, the UK Government is investing in growing capabilities in areas such as AI, machine learning, and more broadly around data-driven healthcare to make it more accessible, affordable and sustainable. However, with patients’ increasing expectations around the quality and safety of such services, and ever-growing complex regulations that demand stricter governance, this is no easy task. Protecting sensitive data While digitising services and sharing data […]

Software Development News

According to Joachim Herschmann, senior director and analyst on the application design and development team at Gartner, the number of APIs in applications has grown tremendously over the past few years because APIs offer a great way to extend the functionality of an application without having to write code. However, the sheer number of API tests has created many challenges for developers; challenges that are similar to those in other types of testing. 

By Mo Amao Application Programming Interfaces (API) have become the foundation for transmitting data, logs, traces, and metrics within and around an organization. Prioritizing API security from development to production should be paramount for organizations, not

Ownership of an API is dynamic and is bound to change over time based on the changing needs of an Organization, API consumer, career growth, and changes of the assigned owner. However, both the Business and IT API owners are responsible for keeping the API flexible, operable, and secure.

In the digitally transformed world, APIs suddenly are among the hottest attack vectors. Yet too many organizations fail to even have visibility into their API

In the digitally transformed world, APIs suddenly are among the hottest attack vectors. Yet too many organizations fail to even have visibility into their API inventory, much less security. Oz Golan, CEO of Noname Security, discusses API security trends.

What are Shadow and Zombie APIs? Both of them create API security risks, and modern API management needs to make sure that they are being properly managed. The larger an organization is, the harder (and the more important) it gets to have a complete and accurate overview of its API landscape. In order to manage risk, getting such an overview is an important first step.

Alissa Knight discusses previous API research on the FHIR ecosystem, including vulnerabilities caused by data aggregators and app developers, which pose data privacy and security concerns. Knight will examine potential solutions to securing the backbone of the healthcare sector's interoperability plan.

Learn GitLab CI/CD by building a complete CICD pipeline for a python demo project | with Docker

Software code has come under attack in innovative and deeply troubling ways, says Noname Security Co-founder and CTO Shay Levi. These attacks have altered the security landscape for both developers and their organizations, not to mention their suppliers, partners, and customers. API security testing has emerged as one solution, as has a more proactive approach to application security, without impededing development speed and efficiency, Levi says.

If you are a bit of an AI/ML enthousiast you should check out "Making Friends with Machine Learning" by Cassie Kozyrkov, it was an internal-only Google course specially created to inspire beginners and amuse experts. Today, it is available to everyone!

Disclaimer: The author of this newsletter is employed by Noname Security, but this is not an official Nonane Security publication, the newsletter is meant to provide independent API Security News. I encourage you to reach out with comments and/or suggestions for the newsletter via https://twitter.com/filipv (DM’s are open).

No posts

Read the original on apisec.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.