• Top API testing firm APIsec exposed customer data during security

    From TechnologyDaily@1337:1/100 to All on Tuesday, April 01, 2025 16:30:08
    Top API testing firm APIsec exposed customer data during security lapse

    Date:
    Tue, 01 Apr 2025 15:27:00 +0000

    Description:
    An unprotected APIsec database was found sitting on the internet, and was subsequently locked down.

    FULL STORY ======================================================================Research ers found an unprotected database containing sensitive customer data It belongs to APIsec, a company specializing in API security testing Affected customers were allegedly notified

    APIsec, a company specializing in proactive, automated, and continuous API security testing, may have inadvertently leaked sensitive customer data online, experts have said.

    The discovery was first made by cybersecurity researchers UpGuard, and later confirmed by the company itself.

    The data was being stored in an internet-connected database that wasnt password-protected, and has apparently remained like that for several days before being locked down as soon as UpGuard notified APIsec.

    Monitor your credit score with TransUnion starting at $29.95/month

    TransUnion is a credit monitoring service that helps you stay on top of your financial health. With real-time alerts, credit score tracking, and identity theft protection, it ensures you never miss important changes. You'll benefit from a customizable online interface with clear insights into your credit profile. Businesses also benefit from TransUnions advanced risk assessment tools.

    Preferred partner ( What does this mean? ) View Deal Notifying affected customers

    Since the company tracks its clients APIs for security weaknesses, most of
    the data was generated by its own products.

    Some of the data dated back to 2018, and included both customer employees and users names, email addresses, as well as API security posture information. Since this data included things like whether or not 2FA was activated, it is the type of information that can prove quite useful for a threat actor.

    APIsec reportedly first tried to downplay the importance of the incident, saying the database held test data, that it wasnt the companys production database, and that it didnt hold customer data, but changed its stance when presented with information suggesting otherwise.

    Apparently, UpGuard found evidence that the database also held data from real-world corporate customers, including names and emails, and scan results.

    When TechCrunch shared the information with APIsec, it later said that it notified customers whose personal information was found in the data. However, it didnt want to say how many people were affected, nor did it want to share
    a copy of the breach notification letter.

    Unprotected databases remain one of the key causes of sensitive data leaks. Many organizations use the cloud to host information about their employees, clients, or customers, forgetting the fact that cloud hosting works on a shared responsibility model. You might also like Massive online data breach sees 2.7 billion records leaked - here's what we know We've rounded up the best password managers Take a look at our guide to the best authenticator app



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/top-api-testing-firm-apisec-exposed-cus tomer-data-during-security-lapse


    --- Mystic BBS v1.12 A47 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)