6

Report shows 92% of orgs experienced an API security incident last year

 1 year ago
source link: https://venturebeat.com/security/report-shows-92-of-orgs-experienced-an-api-security-incident-last-year/
Go to the source link to view the article. You can view the picture content, updated content and better typesetting reading experience. If the link is broken, please click the button below to view the snapshot at that time.
neoserver,ios ssh client

Report shows 92% of orgs experienced an API security incident last year

An image of a digital lock set against an abstract image of code.
Image Credit: Getty Images

Join top executives in San Francisco on July 11-12, to hear how leaders are integrating and optimizing AI investments for success. Learn More


Today, application security provider Data Theorem, announced the release of a new report in partnership with TechTarget’s Enterprise Strategy Group (ESG). ESG surveyed 397 respondents on cloud-native applications and API security and found that 92% of organizations experienced at least one API-related security incident in the last 12 months.

Want must read news straight to your inbox?
Sign up for VB Daily

The report, scheduled to release on May 5, also revealed that 57% experienced multiple API security incidents, highlighting that many organizations still have a lot more to do to defend cloud-native applications and APIs against threat actors. 

This comes just months after a hacker used a Twitter API vulnerability shipped in June 2021 (now patched) to compile and leak the account details and email addresses of 235 million users in January 2023. 

API security incidents ‘no surprise’

One of the key challenges unveiled by the research was the transient nature of the attack surface. For instance, 75% of organizations typically changed or updated their APIs on a daily or weekly basis, creating new vulnerabilities in the attack surface for security teams to confront. 

Event

Transform 2023

Join us in San Francisco on July 11-12, where top executives will share how they have integrated and optimized AI investments for success and avoided common pitfalls.

Register Now

“It’s no surprise that most organizations are experiencing API-related security incidents,” said Melinda Marks, senior analyst for ESG in the announcement press release. 

“Modern development cycles bring faster, more frequent product releases and updates, and the growing number of APIs that change on a daily or weekly basis make it imperative to address the changing attack surface. This rapid rate of change also creates shadow APIs and zombie APIs, which can be hackers’ favorite APIs to exploit because organizations often do not know about them,” Marks said. 

However, many organizations are looking to address API security by increasing their spending over the next 12–18 months by investing in API security tools (45%), cloud-native application protection platforms (CNAPPs) (43%), and integration application security and API security tools (41%). 

CNAPPs and API security tools provide automated support in discovering APIs and highlighting potential entry points, giving defenders valuable insight into how to harden their defenses against cyberattacks. 

VentureBeat's mission is to be a digital town square for technical decision-makers to gain knowledge about transformative enterprise technology and transact. Discover our Briefings.


About Joyk


Aggregate valuable and interesting links.
Joyk means Joy of geeK