Issue 204: API attacks on shadow APIs, PII leaks from e-commerce APIs, API runtime security
Brief
This week, we have articles on the rise of API attacks that target shadow APIs, how API attacks on on e-commerce sites leak PII, views from Trendmicro on the importance of API runtime security, and a guide on API penetration testing.
Article: API attacks target shadow APIs
First up this week is a report from DarkReading on recent research showing that approximately 5 billion (31%) malicious transactions targeted shadow APIs (unknown, unmanaged, and — most importantly — unprotected APIs).
The report ranks the top three threats to APIs, based on monitoring 20 billion API transactions in the first half of 2022:
- The top threat to APIs was epitomized by the 5 billion malicious requests observed targeted shadow APIs.
