← Back to feed
Vulnerabilities & PatchesEmerging1 sourceFeb 22, 2024 · 13:06via API Security News

Issue 240: Spoutible API leakage, 15M Trello profiles scraped, API secret tokens leaked

Brief

This week, we have news of a record four API security related incidents. The first comes from Troy Hunt on a leakage on the new Spoutible social media site, with the second big ticket item being the leakage of 15 million profiles on Atlassian’s Trello. There’s also a report on the leakage of over 18,000 API tokens and the leakage of Office 365 accounts via a misconfigured server.

We also feature a guide on implementing basic authentication on Spring Boot.

Vulnerability: Vulnerabilities in Spoutible API

The first vulnerability this week comes to us from the founder of Have I Been Pwned , Troy Hunt, and features several significant vulnerabilities in the API of the new Spoutible social media platform. In Troy’s own words, “No way! No way!” — this is almost a case study on how not to implement an API. Let’s dig in — fasten your seatbelts.

Read more on API Security News