Welcome to the 2nd post in our weekly series on the new 2023 OWASP API Security Top-10 list, with a particular focus on security practitioners. This post will focus on API1:2023 Broken Object Level Authorization. In this series we are taking an in-depth look at each category – the details, the impact and what you can do about it. To see previous posts you might have missed, click here. TL;DR The application behind the API…
📣 Good news for all tech enthusiasts! The highly anticipated 2023 State of the API Report, conducted by Postman -…
In early June 2023, OWASP released the final version of the OWASP API Security Top-10 list update. At that time…
Wallarm is excited to be back at Black Hat USA this year and meet with our friends in the community…
Our Q2-2023 API ThreatStats™ report is out. It provides API builders, defenders, breakers, and decision-makers with a comprehensive look at…
Introduction In today’s digital landscape, ensuring the security and performance of web applications is paramount. To achieve optimal protection against…
In recent years there’s been a rise in “API Abuse” attacks, which includes detrimental automated behaviors such as malicious bots,…
This post delves into a very impactful JWT Authentication Bypass vulnerability (CVE-2023-30845) found in ESP-v2, an open-source service proxy that…
The MOVEit Vulnerabilities and Latest Exploits. Impact On Governmental Agencies And Large Organizations Governmental agencies and large organizations around the…
Welcome to our May API newsletter, recapping some of the events of last month. As the old proverb goes, April…