← Back to feed
Vulnerabilities & PatchesEmerging1 sourceJan 26, 2023 · 18:43via API Security News

Issue 213: Supply chain vulnerability in IBM Cloud, hardcoded API keys in Algolia portal, JSON-based SQL attacks

Brief

This week, we have news of three vulnerabilities. First up is a supply chain vulnerability in the IBM Cloud platform, which is reported to be the first of its kind to affect a cloud provider. The second is another case of hardcoded API keys, this time in the Algolia AI search portal, and the third is a fantastic piece of research into a JSON-based SQL attack on WAFs.

Finally, we have coverage of a report on the increase in attacks on shadow APIs.

Vulnerability: Supply chain vulnerability in IBM Cloud

The first vulnerability this week is, according to security researchers at Wix, the first of its kind affecting the public cloud. With some dramatic flair, the researchers coined the name “Hell’s Keychain” to describe their attack technique which is meticulously described in their blog .

Read more on API Security News