In early May 2025, Cisco released software fixes to address a flaw in its IOS XE Software for Wireless LAN Controllers (WLCs). The vulnerability, tracked as CVE-2025-20188, has a CVSS score of 10.0 and could enable an unauthenticated, remote attacker to upload arbitrary files to a susceptible system – but the real story is that this vulnerability drives home the persistent risks associated with hardcoded credentials, particularly JSON Web Tokens (JWTs), in network infrastructure components. …
As businesses rely more on APIs, attackers are quick to turn that trust into opportunity. Among the most dangerous and…
We recently released The Rise of Agentic AI, our API ThreatStats report for Q1 2025, finding that evolving API threats are…
API security is no longer just a concern; it’s a critical priority for businesses. With APIs serving as the backbone…
Wallarm Research has just released a powerful new Nuclei template targeting a new kind of exposure: the Model Context Protocol…
On March 25, 2025, NIST released the initial public draft of NIST SP 800-228, “Guidelines for API Protection for Cloud-Native…
Agentic AI is transforming business. Organizations are increasingly integrating AI agents into core business systems and processes, using them as…
Despite advancements in API security, access control vulnerabilities, such as broken object-level authentication (BOLA) and broken function-level authentication (BFLA), remain…
Modern organizations are becoming increasingly reliant on agentic AI, and for good reason: AI agents can dramatically improve efficiency and…
Most organizations are using AI in some way today, whether they know it or not. Some are merely beginning to…