Hacker Newsnew | past | comments | ask | show | jobs | submit | stepan_'s commentslogin

Some other data:

The OWASP Business Logic Abuse Top 10, released this year, formalizes this growing class of attacks. And with 82% of businesses now describing themselves as API-first, the logic layer has become a lucrative new target.

Security Misconfiguration (API8) once again topped the list with 605 cases, up 33% quarter over quarter.

Broken Authorization (API5, API1) accounted for roughly 28% of all API vulnerabilities.

Broken Authentication (API2) climbed sharply, driven by weak credential enforcement in REST and SOAP APIs.


Like the idea of the Spotlight across all the services. Does it index any data for the quick search?


It indexes history, and documents for most commonly used services (like Google docs, Messenger or Notion) - but it's all done locally, personal data is never sent to the backend.


Congrats with the launch!


Thank you!


I was pretty impressed when you shared your datasets with the community. Glad you're launching these virtual challenges now!


For those who is new to the world of SSRF vulnerabilities, check the SSRF Bible (full disclaimer: I'm with Wallarm): https://docs.google.com/document/d/1v1TkWZtrhzRLy0bYXBcdLUed...


This is a list of what you can do for application security with Nginx (mostly with open source tools): https://github.com/wallarm/awesome-nginx-security

My talk from Nginx conference: https://www.nginx.com/blog/build-application-security-shield...

Important note. Care about vulnerabilities. Not about attacks. Buy Burp license. Run appsec training for all of your developers; it's easy while you're small.

Disclaimer: I am a co-founder of Wallarm mentioned in preso.


Awesome job, guys! We have several team members (mostly sales) using Polymail as a default email client.


One of the most promising companies among the whole S16 batch. Congatz!


Thank you Stepan :) Means a lot


+1. Success factor, API.ai, Evernote — three logos from my memory


Thanks!


Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: