Examining 10 high-profile API breaches from 2022
In my professional role, I produce a weekly newsletter on API security topics at APISecurity.io (https://apisecurity.io/). From my work at APISecurity.io, I have picked ten of the top breaches from 2022, which give a representative sample of real-world API vulnerabilities and how they lead to the loss of data or personal information. Let’s get started.
Errors and omissions excepted
Information in this section is taken from publicly disclosed sources, including bug reports, vulnerability tracking sites, first- and third-party blogs and research sites, and industry news websites.
To the best of the my knowledge, the information is accurate at the time of writing; however, as is the nature of technology, the landscape changes rapidly, and new information or details may have come to light in the interim.
1–Global shipping company
In February 2022, security researchers at Pen Test Partners disclosed details of...