Back in April we took an in-depth look at the proposed OWASP Top-10 API Security Risks list for 2023. This Release Candidate (RC) contained a few changes from the 4-year-old version, most notably: Created a new category API3:2023RC (Broken Object Property Level Authorization) by essentially combining API6:2019 (Mass Assignment) with API3:2019 (Excessive Data Exposure). Created a new category API6:2023RC (Server Side Request Forgery), overlapping with A10:2021 from the web application security risks version. Created a…
According to a Mar-2022 API survey by Gartner, 98% of organizations use or are planning to use internal APIs –…
What’s hiding in the shadows? It’s a well understood reality that unmanaged IT assets tend to be unmonitored IT assets,…
Welcome to our April API newsletter, recapping some of the events of last month. This month’s topic is Generative AI…
We’re looking forward to seeing you at this year’s RSA Conference! Don’t forget to set up a meeting with our…
Welcome to our March API newsletter, recapping some of the events of last month. And what a month it was.…
ChatGPT is spreading like wildfire all over the internet, being used in everything from casual tools to cybersecurity and even…
ICYMI, we recently presented A CISOs Guide to the New 2023 OWASP API Security Update. In this first of two…
March has arrived and is roaring like a very confused lion, at least in the northern hemisphere. And much like…
In 2022, the Wallarm Threat Research team went through almost 350,000 reports to find 650 API-specific vulnerabilities, and tracked 115…