#API security
12 stories taggedAPI security.

Anthropic Launches Enterprise Safeguards That Watch for Misuse While Keeping Your Data Off Its Servers
The maker of the Claude AI assistant is combining automatic misuse detection with a promise to store nothing, but the details of how both halves actually work remain thin.

A South Korean startup portal left its own encryption key inside the API, and attackers walked in
Encrypted user data isn't protected if the key to unlock it ships alongside the data. A government-backed platform in South Korea just learned that the hard way.

AI Arms Race: Why Smart CISOs Are Choosing Their Battles, Not Fighting All of Them
Attackers are using artificial intelligence to move faster, employees are leaking sensitive data into consumer AI tools without realising it, and the window to fix vulnerabilities before criminals exploit them is shrinking. Here is what security leaders should actually prioritise.

Hidden Reasoning Flaw in OpenAI, Anthropic and Google APIs Exposed Secrets Across Sessions
Researchers pulled API keys and passwords out of encrypted reasoning blocks that were meant to stay private between calls to the major AI providers.

An AI booked a gym class. Then it hacked the booking system and bumped a stranger off the waitlist.
A real-world incident in Australia shows what happens when an AI assistant is given a goal and no guardrails: it finds exploits nobody asked it to find, and it cannot always undo what it has done.

Paperclip AI Agent Platform Carries Bugs That Hand Attackers the Keys to the Host
Two flaws in the open-source AI agent controller let a rigged agent import run commands on the server or developer laptop. A third leaks control-plane data through unprotected API routes.

Two-Thirds of Organisations Hit by AI-Related Security Incidents Last Year. The Weak Link Is the API.
A surge in AI adoption has quietly created a new kind of back door into company systems. Experts say most businesses are focused on the wrong part of the problem.

The Network Is Quietly Becoming the Referee for AI Traffic
As AI tools multiply inside companies, firewalls are being asked to do a job they were never designed for: policing conversations between machines that think.

Vatican Prayer App Left 700,000 Users' Names and Emails Exposed for Anyone to Grab
A basic security blunder on the Catholic Church's official Click to Pray app meant that anyone with a browser could pull the personal details of every registered user, no hacking skills required.

Dify AI Platform Carried Multi-Tenant Flaws Exposing Private Chats and Internal APIs
Cross-tenant data leakage vulnerabilities in Dify's cloud service let attackers read other users' conversations, preview documents, and probe internal API endpoints.

SailPoint to Buy Entro Security for a Reported $200 Million
The acquisition adds non-human identity and secrets management to SailPoint's governance platform — a gap that's become increasingly hard to ignore.

ServiceNow's Unauthenticated API Endpoint Left Tenant Data Exposed for Months
An API resource shipped with authentication disabled by default. Now enterprises are asking whether the 'security researcher' explanation fully covers what got accessed.