Issue 256: Privilege escalation bugs in Kia vehicles, Cisco and Gov APIs, NIST’s new rules for password security
Brief
This week, we review three different cases of API authorization and privilege escalation vulnerabilities, each of which is a wake-up call for API teams. We examine NIST updates on password security guidelines and share findings from an industry survey on API security and an upcoming OWASP API Top 10 webinar.
Also this week we celebrate APISecurity. io’s 6th anniversary! Since publishing Issue #1 on October 11, 2018, the newsletter has become a trusted resource for staying up-to-date on the latest threats, best practices, innovations, and solutions in the API security space.
Thank you to all subscribers for your continued feedback and support as we work to provide timely and valuable content to drive the conversation around API security.
Industry News: NIST updates the rules for password security
In the latest revision of Special Publication 800-63 Digital Identity Guidelines , the U.
