News & Updates

Pro-Russia group NoName took down multiple France sites, including the French Senate one

The French Senate’s website was taken offline by a DDoS attack launched by the pro-Russian hacker group NoName. The pro-Russia hacker group NoName is claiming responsibility for a DDoS attack that took the website of the French Senate offline. “Access to the Senate website has been disrupted since this morning, our team is fully mobilized […]

The post Pro-Russia group NoName took down multiple France sites, including the French Senate one appeared first on Security Affairs.

News & Updates

Azure API Management flaws highlight server-side request forgery risks in API development

Microsoft recently patched three vulnerabilities in its Azure API Management service, two of which enabled server-side request forgery (SSRF) attacks that could have allowed hackers to access internal Azure assets. The proof-of-concept exploits serve to highlight common errors that developers could make when trying to implement blacklist-based restrictions for their own APIs and services.

Web APIs have become an integral part of modern application development, especially in the cloud. They allow services to communicate and exchange data, non-browser clients such as mobile apps and IoT devices to securely access data and perform operations on behalf of users, and companies to abstract older server backends and quickly interconnect them with modern apps and services. APIs are standardized and easy to interact with rather than relying on custom and legacy protocols that were not built for the web.

To read this article in full, please click here

Exit mobile version