RSS Amplifier

API Security Newsletter · Jul 11, 2022

The API Security Newsletter - Issue #10

0
Sign in to vote or save

This page did not load. You can still read it on the original site — the toolbar below keeps your place in the directory.

Hi Everyone! Welcome to this 10th edition of The API Security Newsletter, as always I welcome any feedback via Twitter DM (https://twitter.com/filipv)This is one a bit shorter as you can see, seems like slower summer news cycles are upon us. Enjoy the time off and let’s get to the news!

A recent analysis of breaches involving application programming interfaces (APIs) arrives at some eye-popping damage figures, but which companies are most affected, and in what ways?

US companies face a combined $12 billion to $23 billion in losses in 2022 from compromises linked to Web application programming interfaces (APIs), which have proliferated with the increased adoption of cloud services and DevOps-style development methodologies, according to an analysis of breach data.

A progress report on the state of healthcare APIs and app ecosystem shows developers and aggregators are making progress on pinpointing privacy and security challenges with data exchange.

The Office for the National Coordinator’s progress report on the current state of healthcare APIs shows developers are aware of and are working to correct some key privacy and security concerns, as the Department of Health and Human Services’ continues its interoperability push.

In today’s modern eCommerce world, consumers have more digital-first and convenient ways of shopping than ever before. Among the critical technologies that have made this possible are Application Programming Interfaces (APIs) which give retailers the ability to transform their systems and processes in quick and efficient ways. Retailers need to reach as many users as possible and to facilitate this they need a well-constructed interface between the eCommerce site and the consumer.  

Amazon arguably kicked off the API explosion with Jeff Bezos’ instructions in 2002: "All teams should expose their data and functionality through service interfaces and communicate with each other through these interfaces which should be designed from the ground up to be externalisable."

The OWASP API Security Top 10 list highlights the most critical API security risks to web applications. The post OWASP API Security Top 10: Security risks that should be on your radar appeared first on Application Security Blog.

Shifting security left means that API security can’t be left only to security teams. Developers need to be on top of potential vulnerabilities and remediate them as they develop. Building security into DevOps means we need to be thinking about how to deliver secure, high-quality code at velocity. Having some basic API security info under your belt will help. 

API (security) related videos

WeTransfer VP of Product Alianna Inzana talks about architecting an API program. Having a great API platform is a good starting point, but what is available on that platform and how well are teams supported to design good APIs for that platform?

James King and Steve Greenblatt record in person at InfoComm22 along with Will Dewitt and Brittany DiCesare to discuss the details of APIs, their importance, and how their value can be realized.

One more thing...

Lex Fridman is an AI researcher working on autonomous vehicles, human-robot interaction, and machine learning at MIT and beyond. He also hosts a really nice podcast. In this episode he talks to Demis Hassabis, the CEO and co-founder of DeepMind, about AI, Superintelligence & the Future of Humanity.

Disclaimer: The author of this newsletter is employed by Noname Security, but this is not an official Nonane Security publication, the newsletter is meant to provide independent API Security News. I encourage you to reach out with comments and/or suggestions for the newsletter via https://twitter.com/filipv (DM’s are open).

Read on apisec.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.