APISEC Conference Sessions Now Available Online |
Written by Nikos Vaggalis | |||
Friday, 12 July 2024 | |||
The talks from APISEC|CON, the largest event dedicated to API security, are now available up on Youtube, for free. The virtual event covered AI and LLM security, defending APIs, API sprawl, governance, testing, shift left, authentication attacks...it's all there. Run in May, APISEC|CON was organized by ApisecUniversity, a company which provides actionable, hands-on training to help you keep APIs secure. Previously we looked into it in "Learn To Protect Your APIs By Hacking Them" where we go through the APIsec Certified Expert path run by security expert Corey Ball that teaches all the techniques necessary to hack APIs. The ultimate goal was to learn how to protect by identifying undiscovered vulnerabilities. This is reflected in for instance the session "Find Your First API Vulnerability" which walks you through all the steps necessary to hack an API the easy way, even if you have no idea what you're doing. A perfect start for beginners. "Attacking and Securing JWTs" explores the security risks associated with JSON Web Tokens (JWTs). It shows how these vulnerabilities can be exploited to hijack user accounts as well as the best practices for implementing them. Another very interesting session was "API Authentication Overview and Advice" which talks about broken authentication, the number 2 of the OWASP top 10 API security risks. Of course AI couldn't have been left out. In "Is there a future for secure data in the world of AI and cyber?" Brenton House looks at AI's impact on data security and APIs as well as its relevance to OWASP Top 10. This was followed with "Using AI to Find Bugs in APIs" and "Securing AI APIs". Other interesting sessions were "API Security Testing Tooling" and "Automating API governance", but really each one was great. Lastly, there's was focus on "Automotive API Security", a pretty important topic nowdays that cars are getting connected to the Internet. Sessions on that subject were "The Internet at 70MPH - Protecting the connected vehicle ecosystem APIs" which delved into the intricacies of protecting APIs within the connected vehicle ecosystem, and "Common API Vulnerabilities in Connected Cars" which talked about the hidden pathways that could grant malicious actors access to control your car or steal your data. As a matter of fact in a couple of weeks (July 25, 2024), there's going to be a new APISEC|CON dedicated to automotive security. You can save your spot by going to https://conf.apisecuniversity.com For the time being you can enjoy all the 23 sessions collected into a single Youtube playlist.
More InformationRelated ArticlesLearn To Protect Your APIs By Hacking Them
To be informed about new articles on I Programmer, sign up for our weekly newsletter, subscribe to the RSS feed and follow us on Twitter, Facebook or Linkedin.
Comments
or email your comment to: comments@i-programmer.info |
|||
Last Updated ( Friday, 12 July 2024 ) |