US companies face a combined $12 billion to $23 billion in losses in 2022 from compromises linked to Web application programming interfaces (APIs), which have proliferated with the increased adoption of cloud services and DevOps-style development methodologies, according to an analysis of breach data.
The Office for the National Coordinator’s progress report on the current state of healthcare APIs shows developers are aware of and are working to correct some key privacy and security concerns, as the Department of Health and Human Services’ continues its interoperability push.
Amazon arguably kicked off the API explosion with Jeff Bezos’ instructions in 2002: "All teams should expose their data and functionality through service interfaces and communicate with each other through these interfaces which should be designed from the ground up to be externalisable."
Shifting security left means that API security can’t be left only to security teams. Developers need to be on top of potential vulnerabilities and remediate them as they develop. Building security into DevOps means we need to be thinking about how to deliver secure, high-quality code at velocity. Having some basic API security info under your belt will help.
API (security) related videos
WeTransfer VP of Product Alianna Inzana talks about architecting an API program. Having a great API platform is a good starting point, but what is available on that platform and how well are teams supported to design good APIs for that platform?
James King and Steve Greenblatt record in person at InfoComm22 along with Will Dewitt and Brittany DiCesare to discuss the details of APIs, their importance, and how their value can be realized.
One more thing...
Lex Fridman is an AI researcher working on autonomous vehicles, human-robot interaction, and machine learning at MIT and beyond. He also hosts a really nice podcast. In this episode he talks to Demis Hassabis, the CEO and co-founder of DeepMind, about AI, Superintelligence & the Future of Humanity.
Disclaimer: The author of this newsletter is employed by Noname Security, but this is not an official Nonane Security publication, the newsletter is meant to provide independent API Security News. I encourage you to reach out with comments and/or suggestions for the newsletter via https://twitter.com/filipv (DM’s are open).

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.