Tag: API

Attacks Targeting APIs Increased By 400% in Last Six Months
News

Attacks Targeting APIs Increased By 400% in Last Six Months

In the past six months, attacks on application programming interfaces (APIs) have surged by 400%. These results are from a recent Salt Security research, which also demonstrates that 80% of all attacks took place through authenticated APIs. The State of API Security Q1 Report 2023, built from survey responses of 400 security professionals and API developers, also reveals that 17% of respondents had encountered an API-related breach and that 94% of respondents have experienced security issues in production APIs over the previous year. About half (48%) of respondents stated that API security read more Attacks Targeting APIs Increased By 400% in the Last Six Months. With ReconBee.com Stay ahead of the latest threats with in-depth coverage of cyber attacks and cybersecurity trends, a...
API Security Flaw Found in Booking.com Allowed Full Account Takeover
Resources, Risk, Security

API Security Flaw Found in Booking.com Allowed Full Account Takeover

The Open Authorization (OAuth) social-login mechanism employed by the online travel service Booking.com has been revealed to have several security issues. The vulnerabilities found by Salt Security might have an impact on anyone using their Facebook accounts to get into the website. According to Salt Security security researcher Aviad Carmel, "The OAuth misconfigurations might have enabled both large-scale account takeover (ATO) on users' accounts and server intrusion. OAuth, according to the security expert, makes it easier for users to connect with websites read more API Security Flaw Found in Booking.com Allowed Full Account Takeover. Stay informed with the best cybersecurity news and raise your cybersecurity awareness with our comprehensive coverage of the latest threats, ...
Millions of Vehicles at Risk: API Vulnerabilities Uncovered in 16 Major Car Brands
Risk, Security

Millions of Vehicles at Risk: API Vulnerabilities Uncovered in 16 Major Car Brands

Millions of automobiles from 16 different manufacturers potentially have many flaws that could be exploited to monitor, start, and unlock cars as well as invade the privacy of car owners. Security flaws were discovered in software from Reviver, SiriusXM, and Spireon as well as in the automotive APIs that power Acura, BMW, Ferrari, Ford, Genesis, Honda, Hyundai, Infiniti, Jaguar, Kia, Land Rover, Mercedes-Benz, Nissan, Porsche, Rolls-Royce, and Toyota. The defects cover a wide range, from those that offer access to user information and internal business systems to those that would enable an attacker to remotely send orders to execute malware read the complete article API Vulnerabilities Uncovered in 16 Major Car Brands.