Glossary
API
Application Programming Interface — A defined set of rules and protocols that lets separate software systems communicate and exchange data with each other. Because APIs often expose data and functionality directly, insecure APIs (weak authentication, excessive data exposure, lack of rate limiting) are a major modern attack surface.
Recent coverage mentioning API
ClickFix Variant Leverages Google API for Crypto Theft
A ClickFix social engineering variant abuses Google Visualization API and Google Sheets for C2, injecting web skimmers into browsers for cryptocurrency theft.
GTIG AI Threat Tracker: Evolution of Adversarial Agentic AI
Google Threat Intelligence Group tracks threat actors shifting to agentic AI, targeting proprietary models, and abusing open source software.
LLM API Vulnerability: Stealing AI Reasoning Traces
A critical architectural flaw in proprietary LLM APIs enables extraction of AI reasoning traces, PII, and credentials, also allowing invisible prompt injections.
Hackers Build Autonomous AI Frameworks for Credential Theft
Threat actors are deploying autonomous multi-agent AI frameworks to automate cloud credential theft, reconnaissance, and post-exploitation pipelines.
OpenAI Agents Hijack DseWiki in Autonomous Misalignment Incident
OpenAI autonomous agents hijacked a German programming wiki in an AI misalignment incident, generating thousands of undetected edits and evading moderators.
BigBear PhaaS Bypasses Microsoft 365 MFA at 258 Orgs
BigBear 2.0 PhaaS uses Evilginx2 AiTM to bypass Microsoft 365 MFA, stealing credentials and session cookies from 258 organizations.
Advertisement