惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Security Archives - TechRepublic
Security Archives - TechRepublic
C
CXSECURITY Database RSS Feed - CXSecurity.com
NISL@THU
NISL@THU
S
Schneier on Security
T
Threat Research - Cisco Blogs
Scott Helme
Scott Helme
T
The Exploit Database - CXSecurity.com
P
Palo Alto Networks Blog
Hacker News: Ask HN
Hacker News: Ask HN
T
Tenable Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Google Online Security Blog
Google Online Security Blog
GbyAI
GbyAI
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Apple Machine Learning Research
Apple Machine Learning Research
Forbes - Security
Forbes - Security
博客园 - 叶小钗
量子位
I
Intezer
腾讯CDC
博客园 - Franky
Microsoft Security Blog
Microsoft Security Blog
Microsoft Azure Blog
Microsoft Azure Blog
阮一峰的网络日志
阮一峰的网络日志
P
Proofpoint News Feed
F
Fortinet All Blogs
C
Cyber Attacks, Cyber Crime and Cyber Security
Jina AI
Jina AI
Project Zero
Project Zero
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
G
Google Developers Blog
Latest news
Latest news
Cyberwarzone
Cyberwarzone
Security Latest
Security Latest
Spread Privacy
Spread Privacy
M
MIT News - Artificial intelligence
F
Full Disclosure
P
Proofpoint News Feed
B
Blog
W
WeLiveSecurity
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
AWS News Blog
AWS News Blog
www.infosecurity-magazine.com
www.infosecurity-magazine.com
The GitHub Blog
The GitHub Blog
Hacker News - Newest:
Hacker News - Newest: "LLM"
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
博客园 - 聂微东
小众软件
小众软件
Schneier on Security
Schneier on Security
PCI Perspectives
PCI Perspectives

Fastly Blog

Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Fastly Six Common Live Streaming Mistakes (And How to Avoid Them) How Fastly and Skyfire Enable Trusted Agentic Commerce at the Edge Bot Defense is Table Stakes. Machine Traffic Requires a Business Strategy AI Traffic Grew 6.5x Faster Than Human Traffic This Year Python SDK Beta: How the Language of AI Runs Faster and Safer with Fastly Give AI Agents the Markdown They Actually Want How to Configure Local Logging for an On-Prem Next-Gen WAF Agent Accountability Without Control Is Breaking Security Leadership Fastly Joins the Agentic AI Foundation (AAIF) to Guide Edge AI Interoperability The E-commerce Industry in the AI Era: Has the Agentic Flood Hit? No Margin for Error: What the FIFA World Cup Teaches Us About Performance at the Edge Why iGaming Infrastructure is Breaking and What Comes Next The Publishing Industry in the AI Era: Why Bot Strategy is Now a Business Strategy Bad Performance Kills SaaS/PaaS Growth — Why Your CDN Matters Why your code is safe from Copy Fail on Fastly Compute Myth or Marvel: Claude Mythos and What it Means for Security Introducing Compliance Audit Reports Supporting Google Private AI Compute with Privacy-Preserving Edge Infrastructure Fastly Nearly Half the Web Isn’t Human: Inside Fastly’s Threat Insight Report Media over QUIC: Can Streaming Finally Have Both Scale and Low Latency? Introducing Fastly’s Redesigned Homepage: Your Central Hub for Actionable Insights The False Choice of Indiscriminate Blocking: Why Technical Precision is the New Standard for an Open Internet What is CVE-2026-23869? React Server Components Security Alert Fastly enables first-party tagging for Google Advertisers Shrink Your Bill With Efficient Software Your AI coding agent just got better at Fastly Fastly Ranked as a Leader in the 2026 Forrester Wave™ for Edge Development Platforms Fastly at RSAC 2026: New Advances in AppSec, Bot Management, and Deception Mastering the Edge: What Golf Can Teach Us About Speed, Precision, and Performance Real-Time CDN Monitoring for Live Events with Bronto Imperva Alternatives Fastly + Scalepost: Extending the Fastly platform to manage AI Crawlers Best content delivery networks for bot management Vibe Shift? Senior Developers Ship nearly 2.5x more AI Code than Junior Counterparts Maximizing Compute Performance with Log Explorer & Insights Fastly CDN Expands Scaling Fastly Network: Balancing Requests | Fastly Best Practices for Multi-CDN Implementations | Fastly Compute@Edge: Serverless Insights by Company | Fastly Fastly can teach you about the Wasm future in just 6 talks Fastly's Observability Unleashed: New Updates and Insights Optimizing your multi-CDN infrastructure to improve performance Stay ahead of attackers by pushing your security perimeter to the edge Fastly Academy: on-demand learning at your fingertips. | Fastly 30 Years of Web: Building for Tomorrow 4 Ways Legacy WAF Fails to Protect Your Apps Adobe boosts performance and MTTR with Epsagon and Fastly logs | Fastly Beta" A New Serverless Compute Environment Early TLS at Fastly Technical trainings & the future of edge delivery at Altitude 2016: a year in review Innovation Capacity Defined: Tech Stack Values | Fastly Deep Log Visibility Offered by Logentries | Fastly Caching the Uncacheable: CSRF Security Increase Your Hit Ratio With This Simple Tip
Are APIs the Key to Digital Innovation or a Trojan Horse?
2024-03-20 · via Fastly Blog

With businesses under pressure to deliver continuous innovation, APIs stand as both the linchpins of progress and potential vectors of risk. Their ability to enhance system connectivity and streamline operations is undisputed. Yet, APIs have increasingly become favored targets for cybercriminals, serving as gateways for account takeover attacks and identity theft.

Without robust protection, APIs are vulnerable to cyberattacks. Credential stuffing, business logic abuse, and DDoS attacks are just some of the malicious automated bot attacks deployed to take over accounts and perpetrate identity theft and fraud. The ease with which attackers can deploy such tactics, thanks to readily available scripts and tools, underscores a grim reality. Business’s legacy defenses are often ill-equipped to fend off these advanced threats.

This is why we commissioned a new report surveying 235 IT and cybersecurity decision-makers across Europe, to shed light on the state of API security. The findings are a reminder of the need for enhanced protective measures. The report offers crucial insights into companies' API security concerns, providing essential input to shape cybersecurity strategies and help establish a secure digital environment.

We found that 84% of respondents admitted to not having any kind of advanced API security in place. What’s more, only 14% viewed using AI technologies in API security as a priority. This lack of preparedness is not confined to specific sectors. Even highly regulated sectors, such as finance and insurance, find themselves outmatched by the sophistication of attacks on their APIs. Interestingly, only 80% of respondents in financial services placed a high or very high level of importance on API security. This compares with 89% in wholesale, retail and e-commerce.

Other key findings from our report

  • In the last year, 95% of respondents encountered API security issues. Of these, 39% dealt with API vulnerabilities, while 33% encountered authentication problems.

  • 69% of respondents express interest in a unified solution for web application and API security from a single provider.

  • To detect an API attack, 55% of respondents rely on API gateway alerts, 46% search log data, and 37% utilize WAF.

What, then, is the path forward? How can companies fortify their digital assets against cyber threats?

The roadmap to secure APIs

The first step in reinforcing defenses is to integrate web applications and API security solutions from a single provider. This consolidated approach ensures a seamless security posture across all digital touchpoints, reducing the complexity and potential gaps that could be exploited by attackers.

For example, Fastly’s API security enables visibility and protection against OWASP’s Top 10 API Security Risks and payloads, targeting specific API protocols to protect APIs everywhere they live. Our protection enhances companies’ security postures, unifies visibility and decision-making, and empowers application development for organizations making their applications faster, safer, and more engaging.

Furthermore, incorporating AI-based tools into a business's security arsenal could be a step forward in tackling the complexity of the API landscape. Our report found that 58% of security professionals anticipate that generative AI will have a ‘large or very large’ impact on API security over a window of approximately 2-3 years. This expectation increases to 75% among financial institutions and insurers. That said, there is currently little enthusiasm for this. Only 14% of the individuals surveyed regarded the use of AI technologies in API security as a priority.

Going forward, the importance of secure APIs is critical. They are a key driver of digital progress, enabling innovation and growth. However, as our report reveals, there is an urgent need for heightened awareness and action to protect against cyber threats. By embracing a unified and potentially AI-enhanced approach to security, companies can ensure that their APIs serve as conduits for innovation, not vulnerabilities waiting to be exploited.

Download the full report now to delve into key findings, vertical insights, and regional data, enabling the creation of a secure digital environment.