<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #API Security</title><description>Cybersecurity articles tagged #API Security on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Securing Model Context Protocol (MCP) Traffic with Cloudflare</title><link>https://runtimerebel.com/blog/securing-model-context-protocol-mcp-traffic-with-cloudflare</link><guid isPermaLink="true">https://runtimerebel.com/blog/securing-model-context-protocol-mcp-traffic-with-cloudflare</guid><description>Learn how Cloudflare One identifies inspected Model Context Protocol traffic and controls AI agent tool calls to secure enterprise environments.</description><pubDate>Fri, 14 Aug 2026 16:44:20 GMT</pubDate><category>Cloud Security</category><category>Zero-Day</category><category>API Security</category><category>Identity Access</category></item><item><title>AI Agent Insecure Direct Object Reference Leads to Booking Abuse</title><link>https://runtimerebel.com/blog/ai-agent-insecure-direct-object-reference-leads-to-booking-abuse</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-agent-insecure-direct-object-reference-leads-to-booking-abuse</guid><description>An autonomous AI agent exploited missing authorization controls in a gym booking API to cancel reservations and alter waitlists.</description><pubDate>Tue, 11 Aug 2026 16:51:58 GMT</pubDate><category>Artificial Intelligence</category><category>API Security</category><category>Insecure Direct Object Reference</category><category>Vulnerability</category></item><item><title>AI Token Jacking: How Cybercriminals Steal API Keys for Profit</title><link>https://runtimerebel.com/blog/ai-token-jacking-how-cybercriminals-steal-api-keys-for-profit</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-token-jacking-how-cybercriminals-steal-api-keys-for-profit</guid><description>Discover how attackers use AI token jacking to steal API keys, fuel underground transfer stations, and cause massive financial losses.</description><pubDate>Thu, 06 Aug 2026 10:31:56 GMT</pubDate><category>Cloud Security</category><category>Credential Theft</category><category>Supply Chain Attack</category><category>API Security</category></item><item><title>Vatican Click to Pray App API Leak Exposes 700K User Records</title><link>https://runtimerebel.com/blog/vatican-click-to-pray-app-api-leak-exposes-700k-user-records</link><guid isPermaLink="true">https://runtimerebel.com/blog/vatican-click-to-pray-app-api-leak-exposes-700k-user-records</guid><description>An insecure API endpoint in the Vatican&apos;s Click to Pray app exposed PII of 700,000 users, including location data and emails, risking targeted phishing.</description><pubDate>Fri, 24 Jul 2026 13:53:14 GMT</pubDate><category>Vatican</category><category>API Security</category><category>PII</category><category>Mobile App Security</category><category>Click to Pray</category></item><item><title>GitHub API Abuse: Detecting Ghost Account Reconnaissance Campaigns</title><link>https://runtimerebel.com/blog/github-api-abuse-detecting-ghost-account-reconnaissance-campaigns</link><guid isPermaLink="true">https://runtimerebel.com/blog/github-api-abuse-detecting-ghost-account-reconnaissance-campaigns</guid><description>Threat actors are leveraging thousands of ghost accounts to map GitHub organizations via API abuse, facilitating future targeted supply chain attacks.</description><pubDate>Sat, 11 Jul 2026 20:51:29 GMT</pubDate><category>GitHub</category><category>API Security</category><category>Reconnaissance</category><category>Ghost Accounts</category></item><item><title>Klue-Salesforce Breach Exposes Competitive Data; Threat Actors Hacked</title><link>https://runtimerebel.com/blog/klue-salesforce-breach-exposes-competitive-data-threat-actors-hacked</link><guid isPermaLink="true">https://runtimerebel.com/blog/klue-salesforce-breach-exposes-competitive-data-threat-actors-hacked</guid><description>Klue&apos;s Salesforce instance breach exposed customer competitive intelligence and contact data via an API vulnerability.</description><pubDate>Fri, 26 Jun 2026 16:48:46 GMT</pubDate><category>Klue</category><category>Salesforce</category><category>Data Breach</category><category>Supply Chain Attack</category><category>White Rabbit</category><category>DarkVault</category><category>IntelBroker</category><category>API Security</category></item><item><title>ServiceNow Data Exposure via Unauthenticated API Flaw</title><link>https://runtimerebel.com/blog/servicenow-data-exposure-via-unauthenticated-api-flaw</link><guid isPermaLink="true">https://runtimerebel.com/blog/servicenow-data-exposure-via-unauthenticated-api-flaw</guid><description>ServiceNow warns customers about a security incident after attackers exploited an unauthenticated API vulnerability to access and query customer instance data.</description><pubDate>Wed, 10 Jun 2026 01:03:52 GMT</pubDate><category>ServiceNow</category><category>API Security</category><category>Data Exposure</category><category>Unauthenticated Access</category><category>Cloud Security Incident</category></item><item><title>Detecting API Discovery Scans for swagger.json: Security Guide</title><link>https://runtimerebel.com/blog/detecting-api-discovery-scans-for-swagger-json-security-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/detecting-api-discovery-scans-for-swagger-json-security-guide</guid><description>Analysis of automated scans for swagger.json and OpenAPI files. Learn how to secure RESTful APIs against discovery-based attacks and reconnaissance.</description><pubDate>Wed, 03 Jun 2026 13:51:10 GMT</pubDate><category>API Security</category><category>Reconnaissance</category><category>Swagger</category><category>OpenAPI</category><category>SANS ISC</category></item><item><title>Cisco Secure Workload RCE via CVE-2025-20165 — Mitigation Guide</title><link>https://runtimerebel.com/blog/cisco-secure-workload-rce-via-cve-2025-20165-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/cisco-secure-workload-rce-via-cve-2025-20165-mitigation-guide</guid><description>Cisco patches a critical 9.8 CVSS vulnerability in Secure Workload REST APIs that allows unauthenticated attackers to gain Site Admin privileges.</description><pubDate>Thu, 21 May 2026 13:21:33 GMT</pubDate><category>CVE-2025-20165</category><category>Cisco Secure Workload</category><category>API Security</category><category>Privilege Escalation</category></item><item><title>TeamPCP Threatens Sale of Mistral AI Source Code Repositories</title><link>https://runtimerebel.com/blog/teampcp-threatens-sale-of-mistral-ai-source-code-repositories</link><guid isPermaLink="true">https://runtimerebel.com/blog/teampcp-threatens-sale-of-mistral-ai-source-code-repositories</guid><description>TeamPCP hackers claim to have exfiltrated 22GB of source code from Mistral AI. This report analyzes the breach impact and API key security risks.</description><pubDate>Fri, 15 May 2026 00:52:30 GMT</pubDate><category>TeamPCP</category><category>Mistral AI</category><category>Data Breach</category><category>Source Code Theft</category><category>API Security</category></item><item><title>Exposed Google API Keys in Android Apps Grant Gemini Access</title><link>https://runtimerebel.com/blog/exposed-google-api-keys-in-android-apps-grant-gemini-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/exposed-google-api-keys-in-android-apps-grant-gemini-access</guid><description>Analysis of Google API keys found in Android apps that enable unauthorized access to Gemini AI endpoints, detailing risks and mitigation for developers.</description><pubDate>Thu, 09 Apr 2026 12:47:35 GMT</pubDate><category>Google API Keys</category><category>Android Security</category><category>Gemini AI</category><category>API Security</category><category>Data Exposure</category><category>Misconfiguration</category></item><item><title>UK Companies House Vulnerability: API Flaw Exposed Millions of Firms</title><link>https://runtimerebel.com/blog/uk-companies-house-vulnerability-api-flaw-exposed-millions-of-firms</link><guid isPermaLink="true">https://runtimerebel.com/blog/uk-companies-house-vulnerability-api-flaw-exposed-millions-of-firms</guid><description>A broken access control vulnerability at UK Companies House allowed unauthorized access to sensitive records and potential modification of corporate filings.</description><pubDate>Tue, 17 Mar 2026 16:31:20 GMT</pubDate><category>Companies House</category><category>API Security</category><category>UK Government</category><category>Broken Access Control</category><category>Data Integrity</category></item><item><title>Escape Secures $18M to Scale Automated API Pentesting and AI Agents</title><link>https://runtimerebel.com/blog/escape-secures-18m-to-scale-automated-api-pentesting-and-ai-agents</link><guid isPermaLink="true">https://runtimerebel.com/blog/escape-secures-18m-to-scale-automated-api-pentesting-and-ai-agents</guid><description>Cybersecurity startup Escape secures $18 million in Series A funding to expand its AI-driven API security platform and automated pentesting capabilities.</description><pubDate>Tue, 10 Mar 2026 12:19:22 GMT</pubDate><category>API Security</category><category>GraphQL</category><category>Automated Pentesting</category><category>Escape</category><category>AppSec</category></item><item><title>Google Cloud API Keys Exposed via Public Gemini Access</title><link>https://runtimerebel.com/blog/google-cloud-api-keys-exposed-via-public-gemini-access</link><guid isPermaLink="true">https://runtimerebel.com/blog/google-cloud-api-keys-exposed-via-public-gemini-access</guid><description>Research reveals nearly 3,000 public GCP API keys exposed in client-side code grant unauthorized access to sensitive Gemini and Vertex AI endpoints.</description><pubDate>Sat, 28 Feb 2026 12:12:17 GMT</pubDate><category>GCP</category><category>Google Cloud</category><category>Gemini</category><category>API Security</category><category>Truffle Security</category><category>Information Disclosure</category></item><item><title>Insecure Google API Keys Expose Gemini AI and Private Data</title><link>https://runtimerebel.com/blog/insecure-google-api-keys-expose-gemini-ai-and-private-data</link><guid isPermaLink="true">https://runtimerebel.com/blog/insecure-google-api-keys-expose-gemini-ai-and-private-data</guid><description>Exposed Google API keys, once considered low-risk for services like Maps, now allow unauthorized access to Gemini AI models and sensitive project data.</description><pubDate>Fri, 27 Feb 2026 00:35:17 GMT</pubDate><category>Google Cloud</category><category>Gemini AI</category><category>API Security</category><category>Credential Exposure</category><category>Cloudflare</category></item><item><title>Security Flaws in Android Mental Health Apps Affect 14.7M Users</title><link>https://runtimerebel.com/blog/security-flaws-in-android-mental-health-apps-affect-14-7m-users</link><guid isPermaLink="true">https://runtimerebel.com/blog/security-flaws-in-android-mental-health-apps-affect-14-7m-users</guid><description>Multiple Android mental health apps suffer from hardcoded credentials and insecure data storage, putting sensitive patient information at risk.</description><pubDate>Tue, 24 Feb 2026 08:20:26 GMT</pubDate><category>Android</category><category>Data Privacy</category><category>Mental Health Apps</category><category>Hard Coded Credentials</category><category>API Security</category><category>Paii</category></item><item><title>Mitigating Attack Surface Expansion in Distributed LLM Infrastructure</title><link>https://runtimerebel.com/blog/mitigating-attack-surface-expansion-in-distributed-llm-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/mitigating-attack-surface-expansion-in-distributed-llm-infrastructure</guid><description>An analysis of the security implications of exposing inference servers, vector databases, and orchestration APIs in self-hosted LLM environments.</description><pubDate>Mon, 23 Feb 2026 12:20:07 GMT</pubDate><category>LLM</category><category>API Security</category><category>Inference</category><category>SSRF</category><category>Orchestration</category></item></channel></rss>