Category

OWASP

Category

In early June 2023, OWASP released the final version of the OWASP API Security Top-10 list update. At that time we published a “hot take” on this final version and followed that up with an in-depth look at the new risk ratings for 2023. Today we’re kicking off a multi-post series in which we take a deeper dive into each of the new categories to understand the details, the impact and what you can do…

Welcome to our May API newsletter, recapping some of the events of last month. As the old proverb goes, April showers bring May flowers – and this means the bees at the Wallarm hive have been in full foraging mode and the honey is flowing: lots of updates & improvements to the platform, and much more. After all, as the old nursery rhyme says: A swarm of bees in May is worth a load of…

As you know by now, the final version of the OWASP API Security Top-10 2023 has been released. At first blush, the final 2023 release seems to retain most of the changes in category naming, language and intent from the 2019 edition which we saw in the RC version. In this post, we are going to further explore the comment in yesterday’s post about risk ratings– because it turns out the changes buried in them…

Back in April we took an in-depth look at the proposed OWASP Top-10 API Security Risks list for 2023. This Release Candidate (RC) contained a few changes from the 4-year-old version, most notably: Created a new category API3:2023RC (Broken Object Property Level Authorization) by essentially combining API6:2019 (Mass Assignment) with API3:2019 (Excessive Data Exposure). Created a new category API6:2023RC (Server Side Request Forgery), overlapping with A10:2021 from the web application security risks version. Created a…

ICYMI, we recently presented A CISOs Guide to the New 2023 OWASP API Security Update. In this first of two planned webinars, Stepan Ilyin and Tim Ebbers provided an overview of what’s in and what’s out in the planned update and had a lively discussion about how this impacts your API security plans for the foreseeable future. You can watch the entire webinar on-demand to get the full story. OWASP API Security Top-10 Comparison To…

There is no doubt that you heard about and seen the latest OpenAI’s brilliant called ChatGPT. It can write poems, speak many languages, answer questions, play chess, make code and impress everyone. In this post, we show a few more of how this AI model is good in cybersecurity, in particular in API Security implementations. ChatGPT is a natural language processing (NLP) model that uses large amounts of data to generate human-like responses to chat…