Issue 213: Supply chain vulnerability in IBM Cloud, hardcoded API keys in Algolia portal, JSON-based SQL attacks
Brief
This week, we have news of three vulnerabilities. First up is a supply chain vulnerability in the IBM Cloud platform, which is reported to be the first of its kind to affect a cloud provider. The second is another case of hardcoded API keys, this time in the Algolia AI search portal, and the third is a fantastic piece of research into a JSON-based SQL attack on WAFs.
Finally, we have coverage of a report on the increase in attacks on shadow APIs.
Vulnerability: Supply chain vulnerability in IBM Cloud
The first vulnerability this week is, according to security researchers at Wix, the first of its kind affecting the public cloud. With some dramatic flair, the researchers coined the name “Hell’s Keychain” to describe their attack technique which is meticulously described in their blog .
