As Cybersecurity Awareness Month continues, we wanted to dive even deeper into the attack methods affecting APIs. We’ve already reviewed Broken Object Level Authentication (BOLA), injection attacks, and authentication flaws; this week, we’re exploring business logic abuse (BLA). Unlike technical flaws, business logic flaws exploit how an API is designed to behave. They are difficult to catch because there are no security controls monitoring “approved” behaviors, so they must be caught more creatively. Which means…
What can we learn from the recent AWS outage, and how can we apply those lessons to our own infrastructure?…
API security has never been more important because modern APIs are operational necessities. Unfortunately, many organizations are failing to adapt…
Authentication issues seem like low-level attacks. But authentication today – especially API authentication – can be more difficult than people…
2025 has been one of Wallarm’s biggest years yet. In the last few months alone, we unveiled our industry-first API…
Injection attacks are among the oldest tricks in the attacker playbook. And yet they persist. The problem is that the…
For this Cybersecurity Awareness Month, we thought it important to draw attention to some of the most common and dangerous…
AJ Debole is Field CISO at Oracle, but her journey began far from the corporate boardroom. After starting out in…
APIs are a blessing and a curse. They’re the backbone of the modern internet. They also expose complex behaviors that…
APIs are now the beating heart of digital infrastructure. But as they have risen in importance, they’ve also become prime…