Welcome to the 6th post in our weekly series on the new 2023 OWASP API Security Top-10 list, with a particular focus on security practitioners. This post will focus on API5:2023 Broken Function Level Authorization. In this series we are taking an in-depth look at each category – the details, the impact and what you can do about it. To see previous posts you might have missed, click here. TL;DR The short summary for Broken…
It’s been reported that 2.6 million user records sourced from the Duolingo app are for sale. The attacker apparently obtained…
We recently discussed the new SEC rule requiring all registered companies to report material cyber incidents within four (4) days.…
The Wallarm API Discovery module has been further enhanced to enable customers to identify Orphan APIs and bring them under…
Welcome to the 5th post in our weekly series on the new 2023 OWASP API Security Top-10 list, with a…
We recently hosted a compact and very engaging panel discussion about the new SEC Cyber Incident Reporting Rules due to…
Welcome to the 4th post in our weekly series on the new 2023 OWASP API Security Top-10 list, with a…
Welcome to another inside story straight from the Wallarm labs. Today we’re taking you behind the scenes of our self-testing…
Welcome to the 3rd post in our weekly series on the new 2023 OWASP API Security Top-10 list, with a…
The recent CISA advisory concerning BOLA (IDOR) vulnerabilities is a wake-up call to bolster our web application security.