Updated FFIEC compliance guidelines specifically delineate APIs as a distinct attack surface, shedding light on the amplified risks they introduce. Financial institutions might be on a tighter compliance timeline than anticipated to prioritize fortifying their API security.
Cyber Security
Cyber criminals, state-sponsored hackers and even the occasional disgruntled employee are constantly looking to gain unauthorized access for a variety of purposes: theft of money, cyber espionage, personal information for sale or for use in scams, and damage to critical infrastructure for just a few of the most common.
So how does an organization mitigate an entire world full of continual cyber attacks? Just as buildings have a number of necessary elements of physical security: access control, cameras, alarms and so on; there are similar key elements of cyber security that are absolutely vital for just about any modern business.
It starts with identifying and closing the most common doors that attackers use. For example, phishing attacks on employees are far and away the most common initial point of entry. The breach of even a low-level employee account can quickly turn into an escalation in access privileges and the ability to reach sensitive information. This is also true of smart devices, which are generally more poorly secured than computers and phones.
Report found that API security was a major concern for businesses as malicious traffic grew triple that of legitimate sources and causing delays in application rollout.
API Vulnerabilities and Bot Attacks Cost Businesses $187 Billion, Increased Adoption Worsens Problem
API vulnerabilities and bot attacks cost businesses $187 billion annually, and the problem is worsening with rapid adoption, underscoring the need for investment in API security and bot management.
A API vulnerability documented by independent security blogger "bobdahacker" created a path to replacing the FIFA World Cup matches playing out on televisions and devices all over the world with any video of the attacker's choosing.
Apparel giant VF Corporation has disclosed in a regulatory filing that the December ransomware attack leaked the personal information of over 35 million customers.
Apple has introduced their Business Essentials offering which brings together device management, 24/7 support and cloud storage. But the move is garnering mixed responses within the community, with stakeholders involved expressing optimism and legitimate concern.
Apple certified the most prevalent macOS malware through its notarization process. Despite a quick response, the malware succeeded in bypassing Apple's security controls for a second time.
Apple attributes iPhone security to its "walled garden" approach. Among other claims, Apple says that an Android device is up to 47 times more likely to contract malware and that allowing app sideloading would attract a wave of cyber crime to the iOS platform.
A zero-day vulnerability that has been with iOS since the first iPhone launched has been identified and patched out by Apple, but with the warning that there is evidence it has been exploited in attack chains for quite some time.
New report from Apple serves as an invective against the practice of sideloading apps to get around the App Store rules. Apple characterizes any sideloaded app as a "serious security risk.”










