Issue 211: SQLi vulnerability in Zendesk Explore, Twitter API vulnerability, API threats to data-driven enterprises
Brief
This week, we have news of a vulnerability in the API of the Zendesk Explore platform allowing an attacker to inject malicious SQL payloads. We also have coverage of the recent breach affecting up to 5. 4 million users of the Twitter platform.
We also have two articles — the first is an article on the threats posed to data-driven enterprises due to API attacks, and the second is a report on the 257% increase in API attacks on financial services.
Vulnerability: SQL injection vulnerability in Zendesk Explore API
This week Varonis Threat Labs reported two vulnerabilities within the popular Zendesk ticketing and support system affecting their Explore component. The first was an SQL injection vulnerability allowing attackers to inject arbitrary commands into the underlying database.
