Issue 154: Views on APIs and security, report into API misconfiguration, detecting malicious API activity
Brief
This week, we have a viewpoint on what security officers can do to address API security. There’s also a report from IBM revealing that two-thirds of cloud breaches are due to misconfigured APIs, the best practices for detecting malicious activity on API endpoints, and a description of common attack vectors on GraphQL implementations.
Correction: In last week’s issue I incorrectly attributed an article on false-negatives in API scanning – my apologies to Corey Ball ( @hAPI_hacker ) for this error.
Opinion: APIs and security
This week, the 42Crunch Field CTO Isabelle Mauny was featured in Security Boulevard, discussing how security officers should approach the challenges of securing APIs.
