APIsecurity.io (@apisecurityio) 's Twitter Profile
APIsecurity.io

@apisecurityio

API security news, standards, vulnerabilities, tools.

ID: 1040662630916976640

linkhttps://apisecurity.io calendar_today14-09-2018 18:04:40

1,1K Tweet

4,4K Followers

108 Following

APIsecurity.io (@apisecurityio) 's Twitter Profile Photo

More companies are announcing the impact of the Salesloft Drift breach, a supply chain attack targeting business-to-business third-party integrations. Testing 3rd party API integrations for security is as important as testing your own APIs for security vulnerabilities.

APIsecurity.io (@apisecurityio) 's Twitter Profile Photo

In Issue 279, we highlight the common vulnerabilities that continue to surface across government web portals and security platforms to industrial equipment, home devices, and even service robots at your local restaurant. apisecurity.io/issue-279-tax-…

In Issue 279, we highlight the common vulnerabilities that continue to surface across government web portals and security platforms to industrial equipment, home devices, and even service robots at your local restaurant.
apisecurity.io/issue-279-tax-…
APIsecurity.io (@apisecurityio) 's Twitter Profile Photo

Critical API vulnerabilities in solar power devices, API directory traversal flaws affecting LG Smart TVs, common weaknesses in the APIs for password-reset services, and the Stack Overflow Developer AI Survey. apisecurity.io/issue-280-sola…

Critical API vulnerabilities in solar power devices, API directory traversal flaws affecting LG Smart  TVs, common weaknesses in the APIs for password-reset  services, and the Stack Overflow  Developer AI Survey.

apisecurity.io/issue-280-sola…
APIsecurity.io (@apisecurityio) 's Twitter Profile Photo

Cybersecurity study finds LLMs can improve accuracy and consistency in routine decisions but can increase automation bias and overconfidence. It suggests LLMs should not be treated as a static answer engine, but instead used as an adaptive collaborator. arxiv.org/pdf/2509.06595

APIsecurity.io (@apisecurityio) 's Twitter Profile Photo

The OpenAPI Initiative publishes v3.2 of the OpenAPI specification and a patch for v3.1 (3.1.2) spec.openapis.org/oas/v3.2.0.html spec.openapis.org/oas/v3.1.2.html

APIsecurity.io (@apisecurityio) 's Twitter Profile Photo

Some interesting stats and recommendations from the @zimperium global mobile threat report. Once APIs are embedded in app code they turn every app into an attack surface...extend protection into the app itself by hardening APIs... zimperium.com/blog/mobile-ap…

APIsecurity.io (@apisecurityio) 's Twitter Profile Photo

Apache Airflow 3.0.3: Connection sensitive details exposed to users with READ permissions lists.apache.org/thread/jg3jo9l…

APIsecurity.io (@apisecurityio) 's Twitter Profile Photo

Issue 281 of the APIsecurity.io newsletter is out now. In this issue we examine OneLogin's API data leak, Cloudflare’s accidental API DoS, a critical Entra ID vulnerability, incidents of mass assignment and excessive data and more.. apisecurity.io/issue-281-onel… #apisecurity

Issue 281 of the APIsecurity.io newsletter is out now. In this issue we examine OneLogin's API data leak, Cloudflare’s accidental API DoS, a critical Entra ID vulnerability, incidents of mass assignment and excessive data and more..
apisecurity.io/issue-281-onel…

#apisecurity