< ciso
brief />
Tag Banner

All news with #api security tag

42 articles

Networking architectures for AI inference model serving

๐Ÿ”’ This post compares two reference networking architectures for AI inference model serving: one tailored for Google Kubernetes Engine (GKE) and one for mixed or alternative backends. It explains a common control-plane pattern using Private Service Connect, optional Apigee, and Model Armor as a centralized entry point for secure, private inference calls. The GKE design adds a specialized GKE Inference Gateway, inference pools, and replica sets for GPU/TPU workloads. The multi-backend design uses a regional internal Application Load Balancer, a Cloud Run payload processor service extension to inject model headers, and Network Endpoint Groups to route to heterogeneous backends.
read more โ†’

Cloudflare Application Profiles for Positive Security

๐Ÿ”’ Cloudflare is launching Application Profiles to enforce positive security by learning the expected structure and format of HTTP requests and flagging deviations. The feature extends existing API Schema Learning to web applications, creating per-operation profiles that validate paths, query parameters, headers, cookies, and request bodies. Profiles are learned from observed traffic, updated weekly, and produce metadata (cf.schema_validation.learned.violated) that teams can use in Security Rules to monitor or enforce blocking. A closed beta is available to invited Enterprise customers and those with API Security already have access.
read more โ†’

Nearly 1 in 10 LiteLLM Gateways Exposed Default Key

๐Ÿ”’ Wiz Research found that many internet-facing LiteLLM gateways still accept the example admin key sk-1234 from the setup guide, allowing full admin access. The master key controls admin rights and authentication; if left default or unset, attackers can retrieve provider API keys and potentially cloud IAM credentials via pass-through endpoints. Several CVEs affecting guardrails, MCP authentication, and sandbox escapes have been fixed in recent releases, and upgrades plus key rotation are recommended.
read more โ†’

Data Agent Kit: Agentic Analytics in IDEs

๐Ÿงญ The Data Agent Kit streamlines exploratory data investigations by enabling agents inside IDEs to query multiple systemsโ€”data warehouses, operational databases, and object storesโ€”via the open Model Context Protocol (MCP) and modular skills. It integrates with popular IDEs and plugins so developers can run queries, inspect execution trails, and grant scoped permissions without switching tools. The kit can convert ad-hoc analysis into reproducible dbt projects and iteratively fix issues, though human oversight and data quality checks remain important.
read more โ†’

Kinesis Data Streams adds Dry Run API checks

๐Ÿ” Amazon Kinesis Data Streams introduces a DryRun option allowing customers to validate API requests and permissions without executing operations. Previously, teams used brittle workarounds like deliberately failing requests to check access, risking unintended writes if limits changed. The new optional DryRun parameter returns a DryRunOperationException when validation succeeds and is supported for five APIs across all Regions.
read more โ†’

Cloudflare introduces OAuth scope customization

๐Ÿ”’ Cloudflare announced task-based OAuth consent to let client owners mark specific scopes as optional, enabling users to grant a narrower subset of requested access during authorization. The change builds on OAuth's existing ability to grant fewer scopes than requested and keeps existing client behavior by default. Developers must check granted scopes after the token exchange and can opt in when configuring a client.
read more โ†’

Humanโ€‘Amplified AI for Security Research Advances

๐Ÿ”Ž A new AI-driven system called HTTP Terminator found hundreds of live websites vulnerable to HTTP request smuggling and even proposed a novel class of flaw, โ€œshared-parser confusion,โ€ but it operated under continuous human guidance. PortSwigger researcher James Kettle designed the system around his own methodology, applying ideation, large-scale evaluation, anomaly detection, weaponization checks, and cascade analysis. Kettle open-sourced the tool and blueprint, stressing that human oversight, deterministic code and careful evaluation strategies amplified AI capabilities and produced more reliable, improvable research outcomes.
read more โ†’

Prisma AIRS Integrates with OpenAI Codex

๐Ÿ”’ Palo Alto Networks announces native integration of Prisma AIRS Runtime API with OpenAI Codex, enabling centralized, API-level security controls for developer workflows. The integration inspects developer inputs and prevents sensitive data leakage without requiring client-side hooks, preserving developer productivity in Codex. SecOps benefit from consistent policy enforcement, audit-ready logging, and organization-wide visibility through the Codex Enterprise Management UI.
read more โ†’

AWS WAF Adds Salt Security Managed Rule Group

๐Ÿ”’ AWS WAF now offers the Salt Security managed rule group, available via AWS Marketplace as Salt Managed Rules for AWS WAF - AI Agent & API Security. The group provides detection and mitigation for API-focused attacks and traffic from AI agents and Model Context Protocol (MCP) endpoints without requiring customers to write custom rules. It addresses threats such as credential brute force, excessive GraphQL queries, SSRF, prototype pollution, and JWT anomalies while labeling MCP traffic and sensitive request attributes. Customers can subscribe and add the rule group to a web ACL directly in the AWS WAF console; pricing and versioning are managed by Salt Security through AWS Marketplace.
read more โ†’

MCP v2: Stateless Model Context Protocol Update

๐Ÿ› ๏ธ The MCP 2026-07-28 specification makes the Model Context Protocol fully stateless, removing session handshakes and Mcp-Session-Id requirements. The update simplifies deployment by allowing MCP servers to run on request-scoped infrastructure like Cloudflare Workers, while preserving elicitation via Multi Round-Trip Requests and tightening authorization with CIMD and RFC 9207 issuer checks. SDKs and migration guidance accompany the release.
read more โ†’

Deutsche Bankโ€™s API-First Transformation with Apigee

๐Ÿงฉ Deutsche Bank adopted Google Cloud's Apigee to transform monolithic systems into a governed, scalable API ecosystem. The platform centralizes documentation, security policies, and governance while enabling discoverability and reuse across teams. Apigee enforces least-privilege access, rate limiting, and observability, and supports resilience, auto-scaling, and caching for high performance. This API-first foundation positions the bank for AI-ready, low-latency services and emerging standards.
read more โ†’

Secure AI adoption begins with API best practices

๐Ÿ”’ AI adoption is accelerating rapidly, but so are API-linked security incidents, making mature API management essential. The article argues that without comprehensive API discovery, runtime protection and governance, investments in AI security will fall short. It highlights shadow and zombie APIs, rising AI-related CVEs, and real-world incidents where agents deleted production data. The piece recommends continuous API inventory, runtime defenses and stricter permissions to manage AI risk.
read more โ†’

Authenticate Legitimate AI Agent Traffic with WAF

๐Ÿ”’ This post introduces Web Bot Authentication (WBA) in AWS WAF Bot Control, a cryptographic, standards-based method for verifying automated agent identities using HTTP Message Signatures. It explains how asymmetric signatures and IETF drafts enable tamper-proof verification, the new WAF labels (verified, invalid, expired, unknown_bot, vendor, name, account), and how verified traffic is handled by default. The article also outlines deployment steps, supported rule group versions, monitoring guidance, and future registration APIs.
read more โ†’

Cloudflare Monetization Gateway and x402 Payments

๐Ÿ”’ Cloudflare announced the Monetization Gateway, a control plane to charge for any asset protected by Cloudflare โ€” web pages, APIs, datasets, or MCP tools โ€” and to enforce payments at the edge. At launch payments will settle in stablecoins over the open x402 protocol, enabling micropayments and sub-second settlement. The Gateway moves metering and payment verification off your origin while preserving your pricing and rules.
read more โ†’

Practical Guidance for Securing Google API Keys

๐Ÿ” This post explains why API keys are sensitive credentials for accessing Google AI and Cloud services and why careless handling leads to misuse or billing abuse. It outlines simple, actionable steps: create keys in dedicated projects, apply API and application restrictions, and store keys in Secret Manager or equivalent. The article also covers detection and responseโ€”how to list keys, monitor usage metrics, delete compromised keys, and rotate keys to reduce risk.
read more โ†’

Microsoft Named Leader in IDC MarketScape for API Management

๐Ÿ† Microsoft has been named a Leader in the IDC MarketScape: Worldwide API Management 2026 Vendor Assessment, reflecting its emphasis on scaling APIs and AI together. Built on a decade-old foundation, Azure API Management governs over 38,000 customers, nearly 3 million APIs, and 3 trillion monthly requests while extending to AI gateway capabilities used by 2,000+ enterprises. The platform provides a single, Azure-native control plane to enforce policy, observability, and cost controls for both APIs and AI workloads.
read more โ†’

Check Point WAF Named Technology Innovation Leader

๐Ÿ›ก๏ธ Check Point has been honored with Frost & Sullivanโ€™s 2026 Technology Innovation Leadership recognition for WAF and API security. The accolade underscores a shift in application security as apps span APIs, microservices, AI-driven services and hybrid/multiโ€‘cloud deployments. Check Pointโ€™s WAF is positioned to help organizations secure rapid DevSecOps releases, reduce attack surface and protect both traditional web and emerging AI applications.
read more โ†’

Cloudflare Launches Registrar API Beta for Automation

๐Ÿš€ Cloudflare today launched the Registrar API in beta, enabling programmatic domain search, availability checks, and direct registration. Designed for editors, CI pipelines, and agent-driven workflows, the API exposes a simple Search โ†’ Check โ†’ Register flow that agents can use to suggest names, confirm pricing, and complete purchases using account defaults. Registrations are offered at-cost, with WHOIS privacy enabled by default and explicit fee acknowledgement required for premium domains.
read more โ†’

Google API Key Flaw Exposes Mobile Apps to Gemini Access

๐Ÿ”’ A flaw in Google's API key model has allowed embedded Android app keys to gain silent access to the Gemini AI endpoints when the API is enabled in a project. CloudSEK's April 8 advisory found 32 active keys across 22 apps with more than 500 million installs and demonstrated retrieval of user-uploaded audio via the Gemini Files API. Developers should immediately audit projects, rotate exposed keys and apply strict API restrictions.
read more โ†’

AI Is Changing App Threats Faster Than Teams Can Adapt

๐Ÿ”’ AI-driven changes in web applications and APIs are outpacing traditional controls, creating large visibility and detection gaps. The 2026 Web Application Security Report, based on a global survey of over 800 security professionals, finds only 29% confidence in overall application security and just 15% for AI-integrated apps. FortiAppSec Cloud is presented as an integrated platform combining WAF, API protection, bot mitigation, and application security services to provide shared telemetry and consistent enforcement across dynamic, service-generated traffic.
read more โ†’