← Back to feed
Policy & RegulationEmerging1 sourceMar 2, 2022 · 21:13via API Security News

Issue 174: APIs increasingly used for account takeover, API hacking book, OAuth in Postman

Brief

This week, we have new research in APIs that reveals how they are increasingly used for account takeover, a look at a great new book on hacking APIs, an article on using Postman for OAuth 2.0 authorization code grants, and a guide on documenting APIs.

Article: APIs increasingly used for account takeover

New research covered by Security Boulevard reveals how APIs are increasingly favored by developers: they are becoming the development tool of choice, with data indicating that of the 21.1 billion application requests analyzed, nearly 70% of them were API-based.

Unfortunately, APIs are also the favorite attack vector for adversaries: correspondingly, the data indicated that 80% of blocked attacks were targeting APIs. In particular, the research revealed a 62% increase in account takeovers (ATO) using login APIs.

Read more on API Security News