Advertisement
Securing Model Context Protocol (MCP) Traffic with Cloudflare
Learn how Cloudflare One identifies inspected Model Context Protocol traffic and controls AI agent tool calls to secure enterprise environments.
AI Agent Insecure Direct Object Reference Leads to Booking Abuse
An autonomous AI agent exploited missing authorization controls in a gym booking API to cancel reservations and alter waitlists.
AI Token Jacking: How Cybercriminals Steal API Keys for Profit
Discover how attackers use AI token jacking to steal API keys, fuel underground transfer stations, and cause massive financial losses.
Vatican Click to Pray App API Leak Exposes 700K User Records
An insecure API endpoint in the Vatican's Click to Pray app exposed PII of 700,000 users, including location data and emails, risking targeted phishing.
GitHub API Abuse: Detecting Ghost Account Reconnaissance Campaigns
Threat actors are leveraging thousands of ghost accounts to map GitHub organizations via API abuse, facilitating future targeted supply chain attacks.
Klue-Salesforce Breach Exposes Competitive Data; Threat Actors Hacked
Klue's Salesforce instance breach exposed customer competitive intelligence and contact data via an API vulnerability.
Advertisement
ServiceNow Data Exposure via Unauthenticated API Flaw
ServiceNow warns customers about a security incident after attackers exploited an unauthenticated API vulnerability to access and query customer instance data.
Detecting API Discovery Scans for swagger.json: Security Guide
Analysis of automated scans for swagger.json and OpenAPI files. Learn how to secure RESTful APIs against discovery-based attacks and reconnaissance.
Cisco Secure Workload RCE via CVE-2025-20165 — Mitigation Guide
Cisco patches a critical 9.8 CVSS vulnerability in Secure Workload REST APIs that allows unauthenticated attackers to gain Site Admin privileges.
TeamPCP Threatens Sale of Mistral AI Source Code Repositories
TeamPCP hackers claim to have exfiltrated 22GB of source code from Mistral AI. This report analyzes the breach impact and API key security risks.
Exposed Google API Keys in Android Apps Grant Gemini Access
Analysis of Google API keys found in Android apps that enable unauthorized access to Gemini AI endpoints, detailing risks and mitigation for developers.
UK Companies House Vulnerability: API Flaw Exposed Millions of Firms
A broken access control vulnerability at UK Companies House allowed unauthorized access to sensitive records and potential modification of corporate filings.
Escape Secures $18M to Scale Automated API Pentesting and AI Agents
Cybersecurity startup Escape secures $18 million in Series A funding to expand its AI-driven API security platform and automated pentesting capabilities.
Google Cloud API Keys Exposed via Public Gemini Access
Research reveals nearly 3,000 public GCP API keys exposed in client-side code grant unauthorized access to sensitive Gemini and Vertex AI endpoints.
Insecure Google API Keys Expose Gemini AI and Private Data
Exposed Google API keys, once considered low-risk for services like Maps, now allow unauthorized access to Gemini AI models and sensitive project data.
Security Flaws in Android Mental Health Apps Affect 14.7M Users
Multiple Android mental health apps suffer from hardcoded credentials and insecure data storage, putting sensitive patient information at risk.
Mitigating Attack Surface Expansion in Distributed LLM Infrastructure
An analysis of the security implications of exposing inference servers, vector databases, and orchestration APIs in self-hosted LLM environments.