← Back to feed
Vulnerabilities & PatchesEmerging1 sourceOct 16, 2025 · 15:03via API Security News

Issue 282: Poker Hacks, Credential Leaks, API Injection Threats, and DDoS Risks

Brief

This week, we examine a World Poker Tour website hack and also the exposure of Nagios Log Server API credentials, we explore an article on the causes of API drift, review common injection attacks targeting APIs, and highlight how DDoS campaigns are increasingly focusing on API endpoints.

Vulnerability: Security Pros Go All In on Poker Website

Security researchers Sam Curry and Shubs Shah uncovered a series of vulnerabilities that granted unauthorized access to the administrator panel of the online poker platform ClubWPT Gold.

Early in their investigations, the researchers discovered the full source code for the admin application exposed online. Using information from an exposed configuration file, hardcoded credentials, and easily guessed passwords, they were able to log in to a staging environment of the admin app.

Read more on API Security News