← Back to feed
Breaches & RansomwareEmerging1 sourceOct 24, 2024 · 12:34via API Security News

Issue 257: Internet Archive under attack, API Gateways insecure by default, OWASP injection attacks

Brief

This week, we look at the recent data breach at the Internet Archive and the critical role of API token management. We have a report from Trend Micro detailing security issues with API Gateway deployments, and we look at recently discovered OWASP API vulnerabilities in popular enterprise and open source platforms. Also a quick look at the new GNAP protocol and what it offers over OAuth 2.

  • Vulnerability: Key Lessons at the Internet Archive

Since early October, the Internet Archive, home of the popular Wayback Machine web archive, has suffered a number of high-profile attacks by groups credibly claiming to have breached Internet Archive’s systems and platforms.

According to one report , the attacker initially gained unauthorized access after discovering an exposed Gitlab authentication token on an Internet Archive development server.

Read more on API Security News