APIs provide the digital glue that binds apps, cloud resources, app services and data altogether – and they’re increasingly an appsec security threat.
Last year the category of underprotected APIs cracked the OWASP Top 10 list for the first time. The breach trends since then are starting to prove that inclusion was pretty prescient. Just in 2018 alone we’ve seen at least half a dozen high-profile data breaches and security exposures caused by poor API security. And that doesn’t even include incidents last year at T-Mobile, Instagram, and McDonalds that all together exposed sensitive data about millions of their users.
This week the latest API security incident to make waves struck Salesforce, which reported to customers that a bug in an API in its Marketing Cloud service potentially exposed customer data. The flaw could have caused API calls to retrieve or write data from one customer’s account to another’s, the company stated.