Issue 276: API discovery hype, BOLA at McDonalds, Cisco APIs exploited, input validation best practices
Brief
This week, we’re sharing two articles focused on input validation best practices, exploring how weak validation can leave APIs exposed. We also take a closer look at some recent claims about API discovery that risk distracting from real security issues, plus a review of recent API security incidents reported at McDonald’s and Cisco.
Article: How Discovery Hype Is Undermining API Security
An article on API sprawl highlights real risks that emerge when API governance policies aren’t enforced. But a misleading claim about “discovery” really stands out:
“API security is never the problem, it is always the discovery. Once you’ve discovered it, you’ll fix it.”
If only that were true. Unfortunately, decades of experience prove the opposite.
In reality, most API breaches involve known APIs that were simply not properly secured.
