API SECURITY BEST PRACTICES 2022

API SECURITY BEST PRACTICES 2022

In this episode of the Virtual Coffee with Ashish edition, we spoke with Corey Ball (Corey's Twitter) about what does API in a modern software stack looks like and how these can be attacked and protected

Episode ShowNotes, Links and Transcript on Cloud Security Podcast: www.cloudsecuritypodcast.tv

Host Twitter: Ashish Rajan (@hashishrajan)

Guest Twitter: Corey Ball (Corey's Twitter)

Podcast Twitter - @CloudSecPod @CloudSecureNews

If you want to watch videos of this LIVE STREAMED episode and past episodes - Check out our other Cloud Security Social Channels:

- Cloud Security News

- Cloud Security Academy

Spotify TimeStamp for Interview Questions

(00:00) Ashish's Intro to the Episode

(02:40) https://snyk.io/csp

(02:51) Corey's professional background

(03:11) Corey's journey to be cybersecurity author

(04:36) What is API and why its important in 2022?

(06:44) Is API is the backend or frontend pf applications?

(08:36) What are people doing wrong with APIs?

(12:16) Best Practice for API Security?

(13:20) Most surprising things being seen in API Security?

(14:35) How do you find API keys?

(16:07) API gateway as a security control point

(18:25) OWASP Top 10 API Security

(20:00) Monitoring and detecting for API Security

(20:57) How to approach pentesting APIs?

(22:35) Learn about API hacking

(25:22) API Security in the Cloud

(29:05) Rest API vs GraphQL

(34:27) Pentest by consuming application documentation

(36:10) Which APIs should be public?

Det här avsnittet är hämtat från ett öppet RSS-flöde och publiceras inte av Podme. Det kan innehålla reklam.

Avsnitt(352)

AI-Powered Forensics: How Attackers Automate Breaches

AI-Powered Forensics: How Attackers Automate Breaches

AI isn't necessarily creating impossible new attacks, but it is drastically lowering the technical barrier to entry for cybercriminals. In this episode, Ashish Rajan speaks with Simon Biggs, Cyber Inc...

23 Juni 39min

The 4 Pillars of AI SOC:From Threat Hunting to Vibe Hunting

The 4 Pillars of AI SOC:From Threat Hunting to Vibe Hunting

Threat hunting has officially evolved into "vibe hunting". However, if your AI security tools lack the right semantic context, they might be doing more harm than good. In this episode, Ashish sits dow...

16 Juni 46min

Native Cloud Firewalls Falling Short in a Multicloud World

Native Cloud Firewalls Falling Short in a Multicloud World

As enterprises expand across multiple cloud environments, on-premise data centers, and dynamic AI workloads, traditional perimeter defenses and siloed cloud-native tools are no longer enough to secure...

11 Juni 36min

How AI Agents Will Negotiate Your Vendor Contracts

How AI Agents Will Negotiate Your Vendor Contracts

Third-Party Risk Management (TPRM) has historically been a tedious, 200-page paper exercise that felt like being catapulted back to 1979. But AI is changing that.In this episode, Ashish sits down with...

27 Maj 37min

How Claude Mythos Changes Vulnerability Management: From CVSS to Exploitability

How Claude Mythos Changes Vulnerability Management: From CVSS to Exploitability

Is your vulnerability management program ready for something like Claude Mythos? The old days of treating vulnerabilities as temporal events (like Heartbleed or Log4J) and patching them on a leisurely...

5 Maj 44min

AISPM Isn't Enough: How to Apply Zero Trust to AI Agents

AISPM Isn't Enough: How to Apply Zero Trust to AI Agents

We are officially entering the "Multi-AI Era." Much like the multi-cloud times, organizations are no longer just using a single AI tool like Microsoft Copilot, they are building custom, agentic workfl...

29 Apr 54min

 The Rise of Agentic Cloud Security: Code-to-Cloud Shrinks to 3 Days

The Rise of Agentic Cloud Security: Code-to-Cloud Shrinks to 3 Days

Is your cloud security strategy ready for the "messy middle" of AI adoption? With developers pushing code from inception to production in under three days using "vibe coding," and adversaries capable ...

21 Apr 26min

Why EDR Fails at AI Security & The Rise of Endpoint Behavior Modeling

Why EDR Fails at AI Security & The Rise of Endpoint Behavior Modeling

Is your EDR blinding you to insider threats? In this episode, Ashish is joined by Brandon Dixon (Co-Founder & CTO of Ent AI, and former Microsoft Security Copilot leader) to discuss why traditional en...

14 Apr 31min

Populärt inom Teknik

uppgang-och-fall
elbilsveckan
bilar-med-sladd
natets-morka-sida
market-makers
rss-laddstationen-med-elbilen-i-sverige
rss-uppgang-och-fall
rss-technokratin
rss-elektrikerpodden
bli-saker-podden
skogsforum-podcast
rss-veckans-ai
developers-mer-an-bara-kod
hej-bruksbil
rss-snacka-om-ai
under-femton
rss-fabriken-2
rss-en-ai-till-kaffet
rss-aximapodden
rss-sakerhetspodcasten