RSS Amplifier

API Security Newsletter · Jul 26, 2022

The API Security Newsletter - Issue #11

0
Sign in to vote or save

Filip Verloy · API Security Newsletter

There's a disconnect between the importance of apps versus the resources applied to protect organizational apps against runtime threats.

Mobile apps are key channels through which businesses serve their customers, and their importance to organizations has tripled in the last two years. Our research reveals that while enterprise app development and deployment are among an organization’s highest priorities, unfortunately, the runtime security of the app, its API secrets and the user data collected do not receive similarly high prioritization and budget. 

Attackers are targeting APIs with great success. Here's how to begin assessing your API attack surface and minimize your risk.

While many of the attack vectors may not seem unique to APIs, they become very concerning when you couple them with the pervasive presence of APIs in the modern digital ecosystem. Luckily, several trends are emerging including increased investment in API security startups and products, more guidance around API security, and an increased industry awareness of just how problematic insecure APIs can be.

Government organizations at all levels are focused on modernization and digital transformation efforts. But not all modernization methods are created equal.

Building solutions in increments with APIs does more than reduce risk and enable speedy time to value. It also makes IT teams integral to the operational effectiveness of governments. Moreover, an API-first approach gives agencies the flexibility to add services as needed and drop them when they’re no longer useful.

As we enter a new era of cloud-first and cloud-native software development, it is natural to embrace an API-first approach to the way we build our new inherently connected IT services for the decade ahead.

Should all organizations think about API-first development and integrating connectivity points to and from the API universe into their own IT stack as it adopts an increasing number of cloud-native technologies? The answer is yes, hence the notion of the "composable enterprise." The industry outlook is clear, APIs are here, and being API-first is the smart route forward.

API adoption can help organizations increase interoperability, efficiency, and security, but healthcare cybersecurity concerns must be addressed.

“APIs provide a lot of benefits, but depending on how they're implemented, they may not be as secure as they should be,” Ahrens said. “From a healthcare standpoint, I see it as this aspect of duality. Healthcare needs to provide easier access to more data. But because of that, it must have a greater focus on data privacy and security.”

Application Programming Interfaces are an integral part of the emerging digital space. Without them,...

Tools for API platforms, analytics, and security are increasingly used thanks to the advancement of mobile technologies. This motivates companies to develop their solutions for internal and external use. 

Twitch is the world's leading video platform and community for gamers.

Ian Douglas, Sr. Developer Advocate at Postman joins Nick Taylor to demonstrate all the things Postman can do. TLDR; It's more than a tool for querying APIs! Ian also discusses interviewing, and how he helps those in the Tech space level up on it.

We're obsessed with our lengthening to-do lists, our overfilled inboxes, the struggle against distraction, and the sense that our attention spans are shrivelling. Still, we rarely make the connection between our daily struggles with time and the ultimate time management problem: the question of how best to use our ridiculously brief time on the planet, which amounts on average to about four thousand weeks.

Oliver Burkeman sets out to realign our relationship with time and to liberate us from its tyranny.

No posts

Read the original on apisec.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.

    Reading · API Security Newsletter · RSS Amplifier