< ciso
brief />
Tag Banner

All news with #api security tag

37 articles

Cloudflare introduces OAuth scope customization

๐Ÿ”’ Cloudflare announced task-based OAuth consent to let client owners mark specific scopes as optional, enabling users to grant a narrower subset of requested access during authorization. The change builds on OAuth's existing ability to grant fewer scopes than requested and keeps existing client behavior by default. Developers must check granted scopes after the token exchange and can opt in when configuring a client.
read more โ†’

Humanโ€‘Amplified AI for Security Research Advances

๐Ÿ”Ž A new AI-driven system called HTTP Terminator found hundreds of live websites vulnerable to HTTP request smuggling and even proposed a novel class of flaw, โ€œshared-parser confusion,โ€ but it operated under continuous human guidance. PortSwigger researcher James Kettle designed the system around his own methodology, applying ideation, large-scale evaluation, anomaly detection, weaponization checks, and cascade analysis. Kettle open-sourced the tool and blueprint, stressing that human oversight, deterministic code and careful evaluation strategies amplified AI capabilities and produced more reliable, improvable research outcomes.
read more โ†’

Prisma AIRS Integrates with OpenAI Codex

๐Ÿ”’ Palo Alto Networks announces native integration of Prisma AIRS Runtime API with OpenAI Codex, enabling centralized, API-level security controls for developer workflows. The integration inspects developer inputs and prevents sensitive data leakage without requiring client-side hooks, preserving developer productivity in Codex. SecOps benefit from consistent policy enforcement, audit-ready logging, and organization-wide visibility through the Codex Enterprise Management UI.
read more โ†’

AWS WAF Adds Salt Security Managed Rule Group

๐Ÿ”’ AWS WAF now offers the Salt Security managed rule group, available via AWS Marketplace as Salt Managed Rules for AWS WAF - AI Agent & API Security. The group provides detection and mitigation for API-focused attacks and traffic from AI agents and Model Context Protocol (MCP) endpoints without requiring customers to write custom rules. It addresses threats such as credential brute force, excessive GraphQL queries, SSRF, prototype pollution, and JWT anomalies while labeling MCP traffic and sensitive request attributes. Customers can subscribe and add the rule group to a web ACL directly in the AWS WAF console; pricing and versioning are managed by Salt Security through AWS Marketplace.
read more โ†’

MCP v2: Stateless Model Context Protocol Update

๐Ÿ› ๏ธ The MCP 2026-07-28 specification makes the Model Context Protocol fully stateless, removing session handshakes and Mcp-Session-Id requirements. The update simplifies deployment by allowing MCP servers to run on request-scoped infrastructure like Cloudflare Workers, while preserving elicitation via Multi Round-Trip Requests and tightening authorization with CIMD and RFC 9207 issuer checks. SDKs and migration guidance accompany the release.
read more โ†’

Deutsche Bankโ€™s API-First Transformation with Apigee

๐Ÿงฉ Deutsche Bank adopted Google Cloud's Apigee to transform monolithic systems into a governed, scalable API ecosystem. The platform centralizes documentation, security policies, and governance while enabling discoverability and reuse across teams. Apigee enforces least-privilege access, rate limiting, and observability, and supports resilience, auto-scaling, and caching for high performance. This API-first foundation positions the bank for AI-ready, low-latency services and emerging standards.
read more โ†’

Secure AI adoption begins with API best practices

๐Ÿ”’ AI adoption is accelerating rapidly, but so are API-linked security incidents, making mature API management essential. The article argues that without comprehensive API discovery, runtime protection and governance, investments in AI security will fall short. It highlights shadow and zombie APIs, rising AI-related CVEs, and real-world incidents where agents deleted production data. The piece recommends continuous API inventory, runtime defenses and stricter permissions to manage AI risk.
read more โ†’

Authenticate Legitimate AI Agent Traffic with WAF

๐Ÿ”’ This post introduces Web Bot Authentication (WBA) in AWS WAF Bot Control, a cryptographic, standards-based method for verifying automated agent identities using HTTP Message Signatures. It explains how asymmetric signatures and IETF drafts enable tamper-proof verification, the new WAF labels (verified, invalid, expired, unknown_bot, vendor, name, account), and how verified traffic is handled by default. The article also outlines deployment steps, supported rule group versions, monitoring guidance, and future registration APIs.
read more โ†’

Cloudflare Monetization Gateway and x402 Payments

๐Ÿ”’ Cloudflare announced the Monetization Gateway, a control plane to charge for any asset protected by Cloudflare โ€” web pages, APIs, datasets, or MCP tools โ€” and to enforce payments at the edge. At launch payments will settle in stablecoins over the open x402 protocol, enabling micropayments and sub-second settlement. The Gateway moves metering and payment verification off your origin while preserving your pricing and rules.
read more โ†’

Practical Guidance for Securing Google API Keys

๐Ÿ” This post explains why API keys are sensitive credentials for accessing Google AI and Cloud services and why careless handling leads to misuse or billing abuse. It outlines simple, actionable steps: create keys in dedicated projects, apply API and application restrictions, and store keys in Secret Manager or equivalent. The article also covers detection and responseโ€”how to list keys, monitor usage metrics, delete compromised keys, and rotate keys to reduce risk.
read more โ†’

Microsoft Named Leader in IDC MarketScape for API Management

๐Ÿ† Microsoft has been named a Leader in the IDC MarketScape: Worldwide API Management 2026 Vendor Assessment, reflecting its emphasis on scaling APIs and AI together. Built on a decade-old foundation, Azure API Management governs over 38,000 customers, nearly 3 million APIs, and 3 trillion monthly requests while extending to AI gateway capabilities used by 2,000+ enterprises. The platform provides a single, Azure-native control plane to enforce policy, observability, and cost controls for both APIs and AI workloads.
read more โ†’

Check Point WAF Named Technology Innovation Leader

๐Ÿ›ก๏ธ Check Point has been honored with Frost & Sullivanโ€™s 2026 Technology Innovation Leadership recognition for WAF and API security. The accolade underscores a shift in application security as apps span APIs, microservices, AI-driven services and hybrid/multiโ€‘cloud deployments. Check Pointโ€™s WAF is positioned to help organizations secure rapid DevSecOps releases, reduce attack surface and protect both traditional web and emerging AI applications.
read more โ†’

Cloudflare Launches Registrar API Beta for Automation

๐Ÿš€ Cloudflare today launched the Registrar API in beta, enabling programmatic domain search, availability checks, and direct registration. Designed for editors, CI pipelines, and agent-driven workflows, the API exposes a simple Search โ†’ Check โ†’ Register flow that agents can use to suggest names, confirm pricing, and complete purchases using account defaults. Registrations are offered at-cost, with WHOIS privacy enabled by default and explicit fee acknowledgement required for premium domains.
read more โ†’

Google API Key Flaw Exposes Mobile Apps to Gemini Access

๐Ÿ”’ A flaw in Google's API key model has allowed embedded Android app keys to gain silent access to the Gemini AI endpoints when the API is enabled in a project. CloudSEK's April 8 advisory found 32 active keys across 22 apps with more than 500 million installs and demonstrated retrieval of user-uploaded audio via the Gemini Files API. Developers should immediately audit projects, rotate exposed keys and apply strict API restrictions.
read more โ†’

AI Is Changing App Threats Faster Than Teams Can Adapt

๐Ÿ”’ AI-driven changes in web applications and APIs are outpacing traditional controls, creating large visibility and detection gaps. The 2026 Web Application Security Report, based on a global survey of over 800 security professionals, finds only 29% confidence in overall application security and just 15% for AI-integrated apps. FortiAppSec Cloud is presented as an integrated platform combining WAF, API protection, bot mitigation, and application security services to provide shared telemetry and consistent enforcement across dynamic, service-generated traffic.
read more โ†’

APIs Are the New Perimeter: How Security Leaders Secure Them

๐Ÿ”’ APIs are increasingly the enterprise perimeter, and recent breaches show traditional protections often miss API-layer abuse. Security teams report attacks that exploit business logic or use stolen credentials, which EDR and WAF tools can treat as legitimate traffic. CISOs are adopting API governance, centralized inventories, identity-aware access controls, and API gateways integrated into CI/CD to enforce least-privilege and reduce misconfiguration risk. As agentic AI and automated agents proliferate, stronger token handling, credential rotation, and real-time behavioral monitoring are becoming essential.
read more โ†’

SpyCloud 2026 Report: Surge in Non-Human Identity Theft

๐Ÿ”’ SpyCloud's 2026 Identity Exposure Report details a structural shift in credential theft, reporting a 23% increase in its recaptured datalake to 65.7B distinct identity records. Attackers are increasingly targeting non-human identities โ€” exposed API keys, session tokens and AI-linked credentials โ€” which often lack MFA and rotate infrequently. The report also flags large volumes of phished records, session artifacts, and malware-exfiltrated data that enable persistent, scalable access across cloud and enterprise environments.
read more โ†’

APIs Now Dominant Attack Surface as Incidents Surge

๐Ÿ”’ Akamaiโ€™s 2025 State of the Internet report finds APIs have become the dominant attack surface, with an average of 258 API attacks per organization (up 113% yearโ€‘onโ€‘year). The vendor reports 61% of attacks involved unauthorized workflows or abnormal behavior, signaling a shift towards behaviorโ€‘based exploitation. Top exploited issues included security misconfigurations, broken object property level authorization and broken authentication. Akamai also warns that agentic AI and automation are amplifying the risk of sensitive data exposure across APIs.
read more โ†’

Cloudflare Launches Web and API Vulnerability Scanner

๐Ÿ” Cloudflare today announced the beta of its Web and API Vulnerability Scanner, initially focused on detecting Broken Object Level Authorization (BOLA) in APIs. The scanner integrates with API Shield, leveraging passive schema learning and API discovery to construct stateful, credentialed tests without extensive setup. It builds automatic scan plans from OpenAPI specs, augments missing or ambiguous schema data using Workers AI, and can create owner and attacker request chains to detect logic flaws. Credential handling uses HashiCorp Vault Transit to encrypt secrets and Temporal for orchestration.
read more โ†’

Programmable SASE: Cloudflare Enables Real-Time Policies

๐Ÿ”ง Cloudflare outlines a truly programmable SASE that lets customers run real-time, inline logic at the edge to make decisions rather than just trigger alerts. Beyond basic APIs, webhooks, and Terraform, Cloudflare One and the Developer Platform enable invoking Workers on policy matches to enrich requests, call risk engines, inject headers, and route traffic with millisecond latency. The post describes managed and custom actions, demonstrates an automated device session revocation Worker, and previews deeper integration and custom action support through 2026.
read more โ†’