EMA Research –Only 33% of enterprises enforce AI agent least privilege access
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
BlogContact Us
Cequence Security
Financial Services
2023-predictions-staying-one-step-ahead-in-api-protection,api-security-2024-predictions,api-security-financial-services,api-security-lacking-for-ecosystem-and-third-party-apis,api-security-breaches,cfpb-announces-major-open-banking-proposed-rule,ffiec-api-security-guidance,financial-aggregators-a-vehicle-for-credential-exploitation,financial-services-api-protection,financial-services-customer-stops-millions-of-api-based-account-takeover-attacks-ato,guest-blog-api-security-off-to-a-booming-start-but-were-not-done-yet,reaching-a-tipping-point-in-identity-verification,regulations-and-standards-drive-need-for-api-security,revised-payment-services-directive-psd2,shield-right-while-shifting-left-to-eliminate-fdx-api-security-gaps-at-runtime,tales-from-the-front-lines-protecting-financial-services-mobile-application-apis-from-automated-attacks,the-open-banking-api-security-imperative,unpacking-the-new-cfpb-rule-on-open-banking
financial-services
Current Events
api-breach-duolingo,api-security-need-to-know-lessons-learned-from-the-peloton-security-incident,disney-account-takeovers-how-the-information-is-used-2
current-events
Industry Reports
api-layer-attacks-2026-dbir,best-in-class-api-security,dbir-api-security,new-api-threat-research-shows-that-shadow-apis-are-the-top-threat-vector,survey-highlights-api-business-value-and-api-security-balancing-act,verizon-2025-dbir-review,verizon-dbir-insights,when-does-comparison-shopping-become-malicious
industry-reports
OWASP
2023-predictions-staying-one-step-ahead-in-api-protection,api-breach-duolingo,api-protection-and-cloud-native-application-protection-platforms-cnapp,api-security-financial-services,api-security-meets-government-regulators,api-security-need-to-know-top-5-authentication-pitfalls,api-security101,api-security-breaches,cfpb-announces-major-open-banking-proposed-rule,connected-car-safety-and-api-security,evolution-of-owasp-api-top-10,owasp-api-risks-cant-be-blocked-but-can-be-fixed,owasp-api-vulnerabilities-exploited-to-bypass-api-security,tales-from-the-front-lines-how-third-party-apis-simplify-enumeration-attacks,top-7-selection-criteria-for-automated-bot-prevention-solutions,unpacking-the-new-cfpb-rule-on-open-banking,zero-trust-api-security-model
owasp
Product News
a-winning-trifecta-api-gateways-api-security-and-api-protection,advance-your-api-security-with-amazon-api-gateway-api-sentinel,ai-agent-prompt-injection-credential-theft,api-protection-in-heterogeneous-environments,application-security-in-kubernetes-why-we-joined-cncf,cequence-achieves-pci-dss-3-2-and-soc-2-compliance,cequence-end-of-year-product-recap-strengthening-your-api-security,cequence-security-awarded-best-enterprise-cybersecurity-solution-of-the-year,cequence-securitys-unified-api-protection-solution-wins-three-2023-globee-awards,cequence-unified-api-protection-wins-2023-cyber-top-20-award,cequence-api-security-and-hpe-greenlake,complete-api-security-coverage-with-proxy-and-service-mesh-integration,complete-api-security-with-cequence-uap-and-cdn-integrations,groundbreaking-api-security-generative-ai,sinet16-innovators-award-validates-api-security-and-bot-management-belong-together
cequence-product-news
CQ Prime Threat Research
a-defenders-view-of-log4j-in-automated-attacks,anatomy-of-a-retail-shopping-bot,api-security-need-to-know-excessive-data-exposure,api-threat-research-validates-robust-api-security,bot-as-a-service-the-consumerization-of-botting,cequence-blocks-credential-stuffing-attack,fake-account-creation-its-fraud-by-any-other-name,heres-why-javascript-based-bot-detection-doesnt-work-is-your-site-listed-here,hidden-dangers-of-untrusted-mcp-servers,how-this-cool-sneakerhead-mom-beat-the-bots,long4j,long4j-findings-confirm-log4j-vulnerability-patching-gaps,moving-from-threat-hunting-to-threat-catching,multi-tenant-saas-authentication-bypass-or-works-as-designed,network-iq-how-the-largest-api-threat-database-protects-your-apis,new-api-research-shows-62-growth-in-atos-targeting-login-apis,new-report-big-breaches-breed-bad-bots,reality-check-automated-shopping-bots-are-a-business-problem,romance-scams-plague-dating-apps,state-of-api-security-activity,the-api-security-conversation-that-the-verizon-data-breach-report-missed,what-are-api-keys-and-why-do-i-need-api-key-security
cq-prime-threat-research
About Cequence
3-steps-to-shielding-right-while-shifting-left-for-api-protection,agentic-ai-monetization,are-api-threat-protection-and-bot-management-related,cequence-achieves-aws-security-competency-status,cequence-announces-ml-based-security-enhancements,cequence-security-awarded-best-enterprise-cybersecurity-solution-of-the-year,cequence-security-named-a-2021-tag-cyber-distinguished-vendor,cequence-securitys-unified-api-protection-solution-wins-three-2023-globee-awards,cequence-unified-api-protection-wins-2023-cyber-top-20-award,cfpb-announces-major-open-banking-proposed-rule,comprehensive-api-protection,enabling-retail-deals-and-repelling-the-steals,ffiec-api-security-guidance,guest-blog-api-security-off-to-a-booming-start-but-were-not-done-yet,hand-sanitizer-samples-face-masks-and-api-security-an-rsa-2020-recap,industry-recognition-for-api-sentinel-kuppingercole,javascript-injection-good-for-fraud-detection-bad-for-security-2,making-a-build-vs-buy-bot-prevention-decision,organizations-are-changing-application-security-must-change-too,predictions-2021-getting-an-edge-against-the-bots,prep-the-halls-readying-your-retail-environment-for-the-holiday-rush,reaching-a-tipping-point-in-identity-verification,rsa-conference-2023-api-security,safeguarding-financial-health-why-cfos-should-prioritize-api-security,shield-right-while-shifting-left-to-eliminate-fdx-api-security-gaps-at-runtime,sinet16-innovators-award-validates-api-security-and-bot-management-belong-together,some-recent-api-security-related-gaffes-and-how-they-might-have-been-avoided,ten-things-your-api-security-solution-must-do-part-i,ten-things-your-api-security-solution-must-do-part-ii,the-analyst-perspective-observations-from-cequences-2021-api-specification-survey,unified-api-protection,unpacking-the-new-cfpb-rule-on-open-banking,what-happens-when-your-entire-company-learns-ai-together-we-found-out,why-do-i-need-api-security-if-i-have-a-waf-and-api-gateway,why-unified-api-protection
about-cequence
Customer Case Studies
api-security-case-study,application-security-solving-the-hardest-problem-first,balancing-bot-detection-with-customer-experience,cequence-unified-api-protection-squashes-phishing-campaign-in-a-matter-of-hours-time-to-value,customer-story-zoosk-security,financial-aggregators-a-vehicle-for-credential-exploitation,flash-sales-and-sneaker-drops,gift-card-and-loyalty-program-abuse,poshmark-api-protection-case-study,sms-pumping-fraud,tales-from-the-front-lines-protecting-financial-services-mobile-application-apis-from-automated-attacks,tales-from-the-front-lines-retail-customer-stops-200k-gift-card-fraud-scheme
customer-case-studies
API Security
2026-verizon-dbir-bots-web-app-attacks-agentic-ai,a-year-in-review-in-one-word-momentum,agentic-ai-application-protection-platform-waap,announcing-api-sentinel,announcing-cequence-waap,announcing-general-availability-of-cequence-api-sentinel-2-0,announcing-unified-api-protection-v2-0,api-layer-attacks-2026-dbir,api-security-api10-defined-as-bots-abusing-well-formed-apis,api-security-lacking-for-ecosystem-and-third-party-apis,api-security-need-to-know-lessons-learned-from-the-peloton-security-incident,api-security-threat-research-retail-holiday-report-2023,app-instrumentation,attack-detection-and-threat-hunting-common-topics,automating-attacks-with-chatgpt,better-bot-management,bola-attack-protection-telecom,business-logic-abuse,canadas-largest-retail-pizza-chain-moves-from-reactive-to-proactive-api-protection-with-cequence,cequence-achieves-pci-dss-3-2-and-soc-2-compliance,cequence-and-software-ag-partner-to-deliver-end-to-end-api-security,cequence-api-security-at-black-hat-2024,cequence-end-of-year-product-recap-strengthening-your-api-security,cequence-named-to-cyber-66-list,cequence-q4fy26-momentum-agentic-ai-security,cequence-security-makes-its-rsa-debut-2,cequence-unified-api-protection-squashes-phishing-campaign-in-a-matter-of-hours-time-to-value,cequence-api-security-and-hpe-greenlake,chatgpt-for-api-security,comprehensive-api-protection,discover-public-api-attack-surface-with-new-api-spyder,end-to-end-api-security,financial-services-api-protection,gartner-recognition-when-it-rains-it-pours,gift-card-and-loyalty-program-abuse,hey-api-what-you-token,how-a-broken-object-level-authorization-vulnerability-exposed-sensitive-data-api-security-report,how-automated-api-attacks-are-the-digital-equivalent-of-mockingbirds,how-bola-leads-to-enumeration-and-ato-attacks,idor-vulnerability,introducing-api-bites-from-cequence-security,iocs-in-your-apis,kasa-camera-vulnerability-discovery,leading-telecom-slashed-account-takeovers,looking-for-a-silver-tail-replacement,mergers-and-acquisitions-in-api-security-and-bot-management,new-api-threat-research-shows-that-shadow-apis-are-the-top-threat-vector,owasp-api-security-top-10-a-framework-for-improving-your-api-security-efforts,owasp-api-security-top-10-from-a-real-world-perspective,owasp-api-vulnerabilities-exploited-to-bypass-api-security,owasp-appsec-training-day-api-attacks-beyond-the-owasp-api-top-10,owasp-top-10-lists-end-state-or-starting-point,prying-eye-vulnerability-direct-to-api-enumeration-attack-enables-snooping,regulations-and-standards-drive-need-for-api-security,tales-from-the-front-lines-attackers-on-lockdown-focus-on-apis,tales-from-the-front-lines-attackers-target-apis-with-get-based-atos,tales-from-the-front-lines-protecting-financial-services-mobile-application-apis-from-automated-attacks,tales-from-the-frontlines-api-sentinel-drives-security-collaboration,the-cequence-security-blog-top-5-posts-of-2020,the-danger-of-web-scraping-and-how-to-prevent-it,ulta-beauty-reduces-costs-by-blocking-api-based-enumeration-attacks,unified-api-protection-7-3,unified-api-protection-for-telcos-customer-testimonial,unified-api-protection-recognized-kuppingercole,whats-new-cequence-api-security-platform-further-advances-end-to-end-vulnerability-and-automated-attack-mitigation,whats-new-cequence-unified-api-protection-siem-integration
api-security
Bot Management
2022-predictions-protecting-an-api-centric-world,2025-api-security-predictions,2026-verizon-dbir-bots-web-app-attacks-agentic-ai,a-defenders-view-of-log4j-in-automated-attacks,agentic-ai-api-security,agentic-ai-application-protection-platform-waap,agentic-ai-security-behavioral-analysis,ai-agents-are-bots-api-defense,analysis-preventing-fake-account-creation-and-romance-scams-2,announcing-cequence-waap,api-0day-response-a-moveit-story,api-breach-duolingo,api-layer-attacks-2026-dbir,api-protection-and-cloud-native-application-protection-platforms-cnapp,api-protection-in-heterogeneous-environments,api-protection-in-telecommunication-protected-in-less-than-30-minutes,api-security-2024-predictions,api-security-api10-defined-as-bots-abusing-well-formed-apis,api-security-in-your-operational-technology-ot,api-security-lacking-for-ecosystem-and-third-party-apis,api-security-podcast-how-apis-enable-digital-transformation-and-automated-attacks,api-security-threat-research-retail-holiday-report-2023,api-threat-detection,api-threat-prevention,api-threat-research-validates-robust-api-security,are-api-threat-protection-and-bot-management-related,are-these-13-scary-security-gaps-in-your-apis,automating-api-security,aws-vpc-traffic-mirroring-integration-coming-soon-2,beyond-magecart-understanding-the-risks-and-impacts-of-third-party-javascript,block-api-attacks,bot-attacks-one-week-in-the-life-of-a-customer,bulletproof-proxies-the-evolving-cybercriminal-infrastructure,bulletproof-proxy-market-update,business-impacts-of-api-security-breaches,canadas-largest-retail-pizza-chain-moves-from-reactive-to-proactive-api-protection-with-cequence,cequence-security-awarded-best-enterprise-cybersecurity-solution-of-the-year,cequence-securitys-unified-api-protection-solution-wins-three-2023-globee-awards,cequence-unified-api-protection-wins-2023-cyber-top-20-award,creating-credential-stuffing-resistant-applications,dbir-api-security,disney-account-takeovers-how-the-information-is-used-2,ffiec-api-security-guidance,financial-services-api-protection,forrester-bot-management-wave-2022,fortune-500-retailer-saves-1-7-million-by-eliminating-account-take-overs-2,heres-why-online-holiday-inventory-is-often-gone-before-you-get-there-3,how-shadow-apis-simplify-automated-attacks,implementing-a-dynamic-sampling-strategy-in-spark-streaming,industry-recognition-for-runtime-application-security-omdia-research,introducing-cq-prime-the-cequence-security-threat-research-team,moving-fast-without-api-guardrails,old-habits-die-hard-industrial-controls-credential-sharing-and-password-spraying,pci-dss-4-compliance-api-security,poshmark-api-protection-case-study,rsocks-takedown,simplifying-bot-prevention-with-cdn-integration,sinet16-innovators-award-validates-api-security-and-bot-management-belong-together,state-of-api-security-activity,survey-highlights-api-business-value-and-api-security-balancing-act,tales-from-the-front-lines-a-long-weekend-ruined-for-whom-2,tales-from-the-front-lines-attackers-on-lockdown-focus-on-apis,tales-from-the-front-lines-attackers-target-apis-with-get-based-atos,tales-from-the-front-lines-how-third-party-apis-simplify-enumeration-attacks,tales-from-the-front-lines-large-retailer-achieves-near-immediate-time-to-value,tales-from-the-front-lines-maintaining-detection-efficacy-and-your-cool-in-the-summer-heat,tales-from-the-front-lines-protected-in-just-33-minutes,tales-from-the-front-lines-retailer-prepares-for-holiday-bot-battle-in-a-matter-of-weeks,tales-from-the-front-lines-why-simple-attacks-like-content-scraping-are-the-hardest-to-block,tales-from-the-frontlines-increasingly-sophisticated-cat-and-mouse-games,ten-things-your-api-security-solution-must-do-part-ii,the-critical-role-real-time-protection-plays-in-api-security,the-rise-fall-of-single-request-bots-2,threat-advisory-recent-high-volume-bot-traffic-from-ipvanish-vpn-against-retailers,unified-api-protection,unified-api-protection-7-3,using-an-api-security-checklist-what-should-you-look-for,verifiable-ai-agent-identification,verizon-dbir-insights,what-are-fake-accounts-and-how-can-they-be-worth-44-billion,what-is-account-takeover-ato,what-is-api-threat-detection,what-is-api-threat-mitigation,what-sets-cequence-apart-from-anyone-else,why-unified-api-protection,your-bot-problem-may-be-an-api-problem
bot-management
AI
2026-verizon-dbir-bots-web-app-attacks-agentic-ai,agentic-ai-api-security,agentic-ai-monetization,agentic-commerce-bot-defense,ai-gateway-introduction,automating-attacks-with-chatgpt,beyond-captcha-biometric-verification-bot-detection,bot-defense-pricing-success-penalty,chatgpt-for-api-security,the-genai-gold-rush
ai
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

FEATURED BLOG

AI Security Blog

Introducing Agent Trust: Managing Agents with Identity Plus Behavior

AI agent identity verification proves who an agent is. Agent Trust adds behavioral analysis so security teams can govern what it does.
Read More
Introducing Agent Trust: Managing Agents with Identity Plus Behavior
API Authentication Best Practices
API Security

API Security Best Practices: Avoiding the Top 5 Authentication Errors

January 3, 2023

7

Read Blog
API authentication errors are listed as the top two threats outlined in the OWASP API Security Top 10, both of which can be traced back to many of the recent publicly disclosed API security incidents. Unauthenticated APIs, too many API tokens, and improper API authentication logic are just a few of the errors found in […]
Three cartoon speech bubbles with “Hi”, “Hey”, and “Hello” inside them against a yellow background.
CQ Prime Threat Research

The Hidden Risks of JSON Web Tokens in APIs

January 2, 2023

5

Read Blog
Technology is always evolving with some of it widely adopted, while others never get implemented. In some cases, the technology adopted for the sake of the latest and greatest is implemented incorrectly, resulting in security flaws. This latest [insecure] technology adoption trend we are seeing is data buried in API requests utilizing JSON Web Tokens […]
javascript bot detection
Bot Management

Here’s Why JavaScript Bot Detection Doesn’t Work

December 20, 2022

5

Read Blog
We’ve been working with a client who was getting hit with wave after wave of bot attacks that were easily bypassing their JavaScript bot detection tools. It seemed odd that they had such a wide array of attackers, and started researching if there were some new attack configs for sale that would target them. Unlike […]
CNAPP Security
API Security

API Protection and Cloud-native Application Protection Platforms (CNAPP)

November 15, 2022

8

Read Blog
Security Solutions for APIs and Cloud Applications Organizations have gained many benefits by developing applications in the cloud that include flexibility, agility, scalability, and speed – but it’s also created security problems that are not easily solved by just any one solution. These problems become more complicated when considering APIs, which are the glue that […]
API Attack Surface Management
API Security

External Attack Surface Management for APIs

September 28, 2022

7

Read Blog
The Attack Surface Has Grown with API Usage Application programming interfaces (APIs) help ensure a smooth running and engaging experience for mobile and web applications. For example, consumers are leveraging APIs behind the scenes when they use a mobile app to access their video streaming service, or their bank account records. In addition, online business […]
API Bites with Cequence Security - API Security Videos
About Cequence

Introducing API Bites from Cequence Security!

September 27, 2022

2

Read Blog
Live from anywhere, it’s API Bites! A few years ago, Gartner predicted that by 2022, API attacks would become the most-frequent attack vector, causing data breaches for enterprise business applications. The most recent Cequence Security API Usage and Threat Report found that 14.4 billion or 70% of the 21.1 billion application requests analyzed were API-based. In addition, […]
API Runtime Protection - Shield Right
API Security

API Runtime Protection: Shields Right While Shifting Everywhere

September 26, 2022

5

Read Blog
Over the course of the last two and a half years, we have evolved our runtime protection-based offerings to focus more broadly on the six phases of the API protection lifecycle. It’s been a rapid series of changes in a dynamic market that warrants a quick review to demonstrate how we have evolved to where […]
API Key Security
API Security

What are API Keys and Why Do I Need API Key Security?

September 13, 2022

5

Read Blog
Have you ever thought about how different apps and devices connect to each other, from the car that tells you where the nearest gas station is, to your phone that gets weather and sports updates? The unsung hero of our connected world is the Application Programming Interface (API). They are the connective tissue that enable […]
Integration API Security SIEM
Product News

What’s New: Cequence Unified API Protection SIEM Integration

August 18, 2022

6

Read Blog
The Cequence Unified API Protection cumulative release (v5.2 to v5.4) adds new capabilities to enhance the export, categorization, and the prioritization of security events. In addition, there is enhanced rationalization of API endpoint discovery when multiple endpoints are found. These added capabilities further ensure the discovery and compliance of all your APIs, along with attack […]
Network IQ
Bot Management

Network IQ: How the Largest API Threat Database Protects Your APIs

August 9, 2022

7

Read Blog
Introduction It’s Christmas and your child wants the latest new gaming console – just like everyone else. As a doting parent, you say you will do what you can. On the date they become available, promptly at 9am, using multiple browsers and mobile devices, you try to acquire one. Just one. Before you finish typing […]
Ulta Beauty Reduce Costs - By Blocking API-based Enumeration Attacks
Customer Case Studies

Ulta Beauty Reduces Costs by Blocking API-based Enumeration Attacks

August 3, 2022

3

Read Blog
Executive Summary Cequence Security assisted the Ulta Beauty CTI team to mitigate a persistent, high volume inventory API scraping attack. While the goal of the attack was uncertain, potential motivations include enabling real world shoplifting opportunities by mapping popular inventory. The attack was executed across a 3rd party local-inventory search API with licensing fees, and […]
Unified API Security Bot Management
Bot Management

Mergers and Acquisitions in API Security and Bot Management

July 29, 2022

6

Read Blog
Continued Consolidation in API Security and Bot Management – A Need for Unified API Protection As we have seen of late, in attempts to offer end-to-end application protection, web application firewall (WAF) vendors have been acquiring bot management companies. Examples of this activity include Imperva and Distil Networks, and F5 and Shape. However, the merging […]
Automated API Attacks Mockingbird
Bot Management

How Automated API Attacks Are the Digital Equivalent of Mockingbirds

July 25, 2022

4

Read Blog
My Father’s Day plans involved sitting in my hammock, listening to the birds and enjoying the fruits of my labors. Then I heard a curious bird call and decided to see what species it was. The Merlin App is one of my favorite apps for bird identification, it can take a picture of a bird […]
API Threat Detection
API Security

API Threat Detection – Staying Safe Over Time: Part 2

July 19, 2022

8

Read Blog
The increasing use of APIs by developers has been one of the defining software trends of the past few years. Seeking efficient, standardized and effective ways to build out fully-featured apps, developers are turning to APIs as the backbone of software releases. It’s likely your organization uses numerous API-based applications for fundamental business functions. Assuming […]
Are fake accounts worth $44B?
CQ Prime Threat Research

What are Fake Accounts and How Can They be Worth $44 Billion?

July 18, 2022

6

Read Blog
Fake accounts have been around for years. They are commonly used to anonymously request info, avoid spam from an online merchant or participate anonymously in a conversation. Initially, fake accounts were easy to create manually, but over time the process became automated. More recently, fake accounts (aka bot or spam accounts) used to deliver a […]
API Discovery
API Security

Getting API Discovery Right: Part 1

July 12, 2022

5

Read Blog
APIs are everywhere. Companies have increasingly turned to API development to quickly and efficiently create consistent, feature-rich applications. APIs have become the connective tissue of data exchange, but this raises important security questions. One of the most significant of these questions is: What is the extent of my organization’s API usage? This isn’t as straightforward […]
RSOCKs takedown
CQ Prime Threat Research

RSOCKS Takedown Means One Less Bulletproof Proxy Vendor

June 28, 2022

5

Read Blog
The recent takedown of the RSOCKS botnet by the DOJ represents a small, but significant step in reigning in the use of high quality residential proxies for malicious purposes. Commonly referred to as a Bulletproof Proxy, these commercially available services market their database of compromised devices to cybercriminals as a pre-built infrastructure to execute large-scale […]
IOCs in your APIs
CQ Prime Threat Research

IOCs in your APIs

June 8, 2022

5

Read Blog
When our customers engage the CQ Prime Threat Research Team for help, it is typically driven by some sort of compelling event. It may have been a potential compliance issue from an exposed API, an aggressive Account Take Over or Shopping Bot attack. In all of these cases our process is the same. We get […]
API Spyder
Product News

Discover Public API Attack Surface with new API Spyder

June 7, 2022

4

Read Blog
Today, we are proud to announce the availability of API Spyder, the newest addition to the Cequence Unified API Protection (UAP) solution. The Cequence UAP is the only offering on the market today that protects your APIs from attackers and eliminates unknown and unmitigated API security risks that can lead to data loss, fraud, and […]
End-to-End API Security
Industry Reports

New Research Confirms Need for End-to-End API Security

May 26, 2022

6

Read Blog
Up until just a few years ago, web applications were the dominant platform for all things digital and APIs were tools used to address development corner cases. Driven by mobile device ubiquity, the adoption of the cloud, and the move towards agile, more iterative microservices-based development methodologies, APIs are now the connective tissue for everything […]
API Security Activity
API Security

State of API Security Activity

May 19, 2022

6

Read Blog
A recap of API threat statistics and unique threat patterns observed by the Cequence CQ Prime Threat Research Team. Summary of Key Findings Unusual uptick in traffic from China spiking at a 200% increase User-experience business logic was abused to commit fraudulent purchases on stolen cards Pop in traffic from a holding company for scraping […]
How BOLA leads to enumeration and ATO attacks
CQ Prime Threat Research

How BOLA Leads to Enumeration and ATO Attacks

May 10, 2022

6

Read Blog
Imagine it’s a Friday night and you are out with your friends to the club. At the door, the bouncer asks you for your ID and lets all of you in. You go to the bar and order some drinks – it’s a busy bar, so the bartender gives you a receipt with the number […]
Long4j
API Security

Threat Advisory: New Log4j Exploit Demonstrates a Hidden Blind Spot in the Global Digital Supply Chain

May 5, 2022

8

Read Blog
While helping our customers validate their patching efforts, the CQ Prime Threat Research team found additional unpatched servers with the Log4j vulnerability hidden within their digital supply chain, dubbed LoNg4j. The Risks The Log4j vulnerability is more widespread than we thought, spread across the digital software supply chain. Testing reveals that LoNg4j discovery can take […]
Whats New
Product News

What’s New: Cequence API Security Platform Further Advances End-to-End Vulnerability and Automated Attack Mitigation

May 2, 2022

4

Read Blog
The Cequence Unified API Protection solution v5.1 release combines the API Spartan and API Sentinel capabilities into a single integrated release and adds new capabilities to streamline administration and enhance API vulnerability and automated bot attack mitigations. Following are the key new features in v. 5.1: Enhanced Role-based Access Control Administrators can now delegate access […]
About Cequence

Cequence Named a Strong Performer in The Forrester Wave™: Bot Management

April 12, 2022

6

Read Blog
As a Co-founder and Chief Product Officer, I am happy to read the latest Forrester WaveTM Bot Management, Q2 2022, where Cequence is named as a strong performer. Highlights from the report write up include “strong go-to-market and execution roadmap” and an “API-first strategy.” Reading positive words from a respected analyst is great, but there […]
Product News

Cequence and Software AG Partner to Deliver End-to-End API Security

April 7, 2022

3

Read Blog
Today, application programming interfaces (APIs) act as the connective tissue for everything we do digitally. Designed for machine-to-machine interaction, APIs are the tool of choice for developers because each API includes all necessary commands, payload, and data to produce engaging user interactions. The most recent Cequence Security API Usage and Threat Report found that 14.4 […]
Light blue wavy lines on a dark background representing the Gartner Hype Cycle for API Security report highlighting Cequence.
API Security

Are API Threat Protection and Bot Management Related? Gartner Hype Cycle Recognition

March 22, 2022

7

Read Blog
Gartner Hype Cycle for Application Security: Recognition Confirms Cequence’s Leadership Cequence is the only vendor to be recognized in both API Threat Protection and Bot Management segments, a recognition that we believe confirms our belief that a comprehensive API security platform MUST be able to detect API threats and natively mitigate them in real-time while […]
API Security

Ten Things Your API Security Solution Must Do: Part II

March 9, 2022

7

Read Blog
In my previous blog, I talked about the need to strike a Shield Right While Shifting Left approach to protect your APIs while continuously discovering and tracking APIs while assessing and remediating risks associated with coding errors before they are published. With the Shift Left while Shielding Right approach in mind, here are the remaining […]
API Security

Ten Things Your API Security Solution Must Do: Part I

March 3, 2022

8

Read Blog
API security is ranked as a top priority in 2022 for enterprises and security leaders worldwide, but in a market crowded with vendors, how can you find the right fit for your organization? With new API security startups showing up on the horizon seemingly every third week, all with different messaging, it can be a […]
API Security

New API Research Shows 62% Growth in ATOs Targeting Login APIs

February 10, 2022

5

Read Blog
APIs are the Developer Tool of Choice and #1 Target for Malicious Use Today, everything is an app. A Tesla isn’t really a car – it’s a four-wheeled app. Every one of the 142B+ device app downloads including your money management or a favorite shopping or fitness app are all built on application programming interfaces […]
API Security - Proxy Service Mesh Integration
API Security

Complete API Security Coverage with Proxy and Service Mesh Integration

February 6, 2022

5

Read Blog
Cequence Unified API Protection integrates with Istio Service Mesh, Tetrate Service Bridge and NGINx and Envoy Proxies to ensure all APIs are discovered, analyzed and protected, regardless of location. The integrations help customers address one of the most critical API security challenges the face: API visibility. The API visibility challenge is brought on by the […]
What is Account Takeover (ATO)
API Security

What is Account Takeover (ATO)?

February 4, 2022

7

Read Blog
Account Takeover (ATO) happens when an attacker takes over a user’s financial, airline miles, retail, streaming, mobile device, or other password-protected accounts. Attackers that successfully bypass API security can then make wholesale changes to compromised accounts or use them as part of another attack. Compromised accounts can be used in phishing campaigns, wherein the recipients […]
About Cequence

Working at Cequence in 2022: World’s Most Comprehensive API Security Platform

January 27, 2022

4

Read Blog
With our recent round of funding, we have opened up numerous API security career opportunities around the world, both in-office (Sunnyvale, CA and Cincinnati OH) and remote. You can review the available API security openings here. But before you do, I thought I would update my 2018 blog on what it’s like to work here. […]
API Security

A Defender’s View of Log4j in Automated Attacks

January 10, 2022

4

Read Blog
When Log4j was first exposed to the public, it was only a matter of time before exploits would be developed and fired at any unsuspecting web server with the chance of getting Remote Code Execution. But to get from “we know there is a problem” to “we know that server has a problem” to getting […]
A person stacking blocks with arrows pointing up in a format that looks like a stock chart.
About Cequence

Series C Funding: Bigger, Better, Faster

December 15, 2021

5

Read Blog
Today, we’re excited to announce that Cequence Security has raised $60 million in series C funding, beginning our next phase of significant growth as a leader and innovator in the API Security category. Menlo Ventures led this most recent funding round, with partner Venky Ganesan joining our board of directors. Our relationship with Menlo Ventures […]
API Security

2022 Predictions: Protecting an API-Centric World

December 3, 2021

5

Read Blog
It’s that time of year where we review the past year with an eye towards the coming year. With that in mind, I wanted to look back at our 2021 predictions while looking forward to the new year. Last year, we predicted that API security would mature. We were somewhat correct here, but not in […]
API Security

Are These 13 Scary Security Gaps in Your APIs?

October 27, 2021

5

Read Blog
Today, bad actors are increasingly exploiting API security gaps, allowing them to exfiltrate data, commit fraud or take other actions that can come back to haunt your organization. With the spooky season upon us, I wanted to cover some of the more chilling real-world API attack scenarios I’ve spotted in both Cequence customer environments and […]
cybersecurity tips
About Cequence

Avoid Tricks With These Tips — Cybersecurity Awareness 2021

October 8, 2021

6

Read Blog
It is somewhat apt that October is cybersecurity awareness month, given the spooky nature of Halloween and the actions of malicious actors hiding in the shadows. We asked some of our team members battling ATO attacks for our customers for tips they might provide friends and loved ones. Here are the top ten tips for […]
CQ Prime Threat Research

How Shadow APIs Simplify Automated Attacks

October 1, 2021

6

Read Blog
The term shadow API can convey a sense of a complicated, nebulous object, which doesn’t necessarily convey the security risks when they are discovered in the wild. The reason attacks on shadow APIs are so effective is that they exploit seemingly innocuous mistakes in development and asset management control. These mistakes are frequently abused by […]
API Security

SINET16 Innovators Award Validates API Security and Bot Management Belong Together

September 28, 2021

4

Read Blog
I am very pleased to see Cequence Security chosen from a field of 190 different vendors as one of the sixteen SINET16 Innovators award winners. The stringent selection process involves an in-depth application that is then put through two rounds of analysis by 100+ tech-savvy judges who look at how the applicant security innovations are […]
API Security

“The Analyst Perspective – Observations from Cequence’s 2021 API Specification Survey”

September 28, 2021

5

Read Blog
This is the last of my three guest blogs as part of our collaboration with Cequence. In the first blog on August 30, I wrote about how we’ve seen the level of API security knowledge increase since our initial research in 2019 but more must be done to secure the use of APIs in today’s […]
API Security

Multi-Tenant SaaS Authentication Bypass or Works-as-Designed?

September 22, 2021

7

Read Blog
Four months ago, researchers at Cequence discovered an authentication vulnerability in the Lithium community forum platform (now part of Khoros), that warranted a responsible disclosure submission. The vulnerability impacts Khoros customers using the Lithium platform to host public communities and forums, exposing their customer data to unauthenticated users. Khoros has been made aware of our […]
API Security
API Security

Some Recent API Security Related Gaffes, And How They Might Have Been Avoided

September 13, 2021

4

Read Blog
This is the second of three guest blogs as part of our collaboration with Cequence. In the first blog on August 30, I wrote about how we’ve seen the level of API security knowledge increase since our initial research in 2019 but more must be done to secure the use of APIs in today’s hyperconnected […]
Customer Case Studies

Tales from the Frontlines: API Sentinel Drives Security Collaboration

September 2, 2021

3

Read Blog
According to Gartner, there are as many as 40 vendors in the (fragmented) API security space. Many take the approach of targeting development with new variations of testing tools or ways to fix/augment shift left efforts. API Sentinel takes a different approach, beginning on the “right” with complete visibility of all APIs at runtime. Once […]
API Security Progress
API Security

Guest Blog: API Security – Off to a Booming Start, But We’re Not Done Yet

August 30, 2021

3

Read Blog
I am very excited to partner with Cequence for a three-part blog series and webinar on the top-of-mind subject of API security in financial services companies, fintechs and insurtechs. At Aite-Novarica Group, we initiated coverage of the API security space in 2019. At that time, we learned very quickly that API security knowledge was extremely […]
Warning sign representing gift card fraud
CQ Prime Threat Research

Threat Advisory: Recent High Volume Bot Traffic from IPVanish VPN Against Retailers

August 26, 2021

5

Read Blog
TL;DR A spike in malicious bot traffic with similar characteristics across more than 20 customers emanating from the same VPN vendor and its affiliated companies. Between July 21st and August 4th, average daily bot traffic from IP addresses owned by IPVanish, Highwinds Network Group, StackPath Data Center, Netprotect, Reliable Hosting, Inc. and Overplay.com increased 28X […]
API Security Gartner Recognition
About Cequence

Gartner Recognition: When it Rains, it Pours…

August 4, 2021

5

Read Blog
As a co-founder of Cequence, I get the pleasure of seeing firsthand how our products help our customers protect their APIs from malicious attacks that can lead to fraud and data loss. However, the challenge any small company has is getting the word out to the market at large, particularly in the crowded API Security […]
Silver Tail Replacement
Bot Management

Looking for a Silver Tail Replacement?

July 22, 2021

5

Read Blog
When RSA Security announced an end-of-life (EOL) for Silver Tail, a popular fraud analytics and prevention product, they left a lot of customers scrambling to find an alternative. If you find yourself in that very situation, read on. The Cequence Application Security Platform (ASP) was designed to solve the same use cases as Silver Tail, […]
Momentum Train representing business momentum
About Cequence

A Year in Review in One Word: Momentum

June 22, 2021

2

Read Blog
We recently wrapped up our fiscal year and while it was a challenging year in many respects, our business thrived. Even though we had instituted weekly (virtual) company all-hands to keep everyone abreast of the business (and connected), we had not realized the range of milestones achieved until we looked back collectively during our annual […]
Conveyer with boxes representing shopping bots
Bot Management

Enabling Retail Deals and Repelling the “Steals”

June 17, 2021

4

Read Blog
Retailers, shoppers and threat actors alike are preparing for the big day: Amazon Prime Day, when there are retail sales opportunities to be had as retailers run their own sale event to compete with, or leverage the public visibility of the day. There will be deals and (figuratively speaking) there will be steals. As the […]
Wooden blocks with shopping carts on them representing a shopping bot attack
Bot Management

Anatomy of a Retail Shopping Bot

June 14, 2021

4

Read Blog
Whether they are participating in it or competing against it, retailers worldwide are preparing for Amazon Prime Day. No doubt threat actors are doing the same, choosing their targets, assembling the tools and infrastructure to execute their automated shopping bot attacks. Threat actors have taken note of the money to be made in the resale […]
A hand holding a stopwatch representing block bots fast
Customer Case Studies

Tales From the Front Lines: New Applications Protected in Just 33 Minutes

June 8, 2021

4

Read Blog
In this week’s blog, we will talk about two recent customer scenarios where the value of our no JavaScript or SDK approach became evident in minutes: when customers needed to prevent an attack on a new application. As a reminder, Cequence uncovers malicious transactions hiding in plain sight with CQAI, a patented, multi-dimensional analytics engine. […]
A puzzle with a missing piece and a toy business man standing in the missing piece looking down representing API Security
API Security

The API Security Conversation that the Verizon Data Breach Report Missed

June 4, 2021

4

Read Blog
It’s out. The annual Verizon Data Breach Incident Report. 115 pages. Thousands and thousands of words. Eye-popping graphics. Zero mentions of API. No mentions of the term Application Programming Interface. One mention of the word programming, deep within an industry-specific section. Why no discussion on APIs as an Incident Classification alongside web application attacks? My […]
Post-it note stacks with Lessons Learned printed on them representing the Peloton security breach
CQ Prime Threat Research

API Security Need to Know: Lessons Learned From the Peloton Security Incident

May 6, 2021

5

Read Blog
By now most have heard about the Peloton data breach incident and no doubt the security team at Peloton is working long, hard hours to pull themselves out of this horrible situation. The damage is done but there are lessons we can, and should, learn from the incident. Peloton was one of the many different […]
Fashion shoe representing sneaker bots
Bot Management

How This Cool Sneakerhead Mom Beat the Bots

May 6, 2021

6

Read Blog
If you grew up in the 80s like I did, you probably remember watching Michael Jordan dominate the basketball court for the Chicago Bulls. I spent many evenings with my family watching him fly high through the air, hanging from the rim and winning countless games for his team. Michael Jordan is not only one […]
Old style standing microphone representing API Sentinel 2.0
Product News

Announcing General Availability of Cequence API Sentinel 2.0

May 5, 2021

4

Read Blog
Today we are happy to announce the general availability of version 2.0 of Cequence API Sentinel. This release brings to market several exciting new capabilities requested by our customers, enabling Cequence to continuously discover, monitor and protect their APIs. Below is a summary of the major new features in this release. Sensitive Data Exposure Dashboard […]
Man in a business suite holding a silver shield representing shield right shift left api security
API Security

3 Steps to Shielding Right While Shifting Left for API Protection

April 30, 2021

7

Read Blog
Most organizations have seen exponential growth in API usage in the last few years, driven by a rapid increase in mobile applications, containers, serverless computing, microservices architectures, and cloud adoption. However, APIs are a double-edged sword – bringing the benefits of rapid development and ease of integration to both the developer and the bad actor […]
Business men looking at a paper and holding a pen representing API Security KuppingerCole
API Security

Industry Recognition for API Sentinel: KuppingerCole

April 26, 2021

3

Read Blog
The seemingly weekly announcement of new API security offerings highlights the importance of protecting your APIs from security gaps that can lead to fraud and data loss. The wide range of offerings is confusing, even for those of us in the space! Where should you begin? Most security professionals would agree that you cannot protect […]
Stacks of blocks with an open space and a hand placing a red block representing FDX API Security
API Security

Shield Right While Shifting Left to Eliminate FDX API Security Gaps at Runtime

April 21, 2021

4

Read Blog
As a member of the FDX (Financial Data Exchange) working group, I recently participated in a panel discussion at the FDX Spring Summit. The topic was how you should shield right as you shift left to protect data transmitted across the FDX API. To add more context to the discussion, FDX is inherently designed with […]
Wooden blocks stacked with a magnifying glass on them and a hand removing one block that has API printed on it representing excessive data exposure
API Security

API Security Need to Know: Excessive Data Exposure

March 10, 2021

4

Read Blog
In today’s online world, privacy is more than concealing what you’re up to. Privacy begins with an expectation, that is maintained in an ongoing manner. When you use an application that sets a privacy expectation with words like “secure”, the maintenance falls to the provider of the application. Clubhouse App Security Flaws: Excessive Data Exposure […]
Woman holding a gold star representing application security award
About Cequence

Industry Recognition for Runtime Application Security: Omdia Research

February 19, 2021

2

Read Blog
With ever-increasing cyber threats, it’s important that organizations continually assess the effectiveness of their application security. One of the areas often left under protected is runtime, which is where the Cequence Application Security Platform shines (you don’t have to just take our word for it, either). We’re proud to be recognized by Omdia Research as […]
Shopping carts lined up on a black background representing automated shopping bots
Bot Management

Reality Check: Automated Shopping Bots are a Business Problem

February 11, 2021

6

Read Blog
Last week, I had the pleasure of participating in a webinar on automated shopping bots with Sandy Carielli, Security and Risk Analyst at Forrester Research. The webinar highlighted two things for me: automated shopping bots are a complex problem and they impact the entire business – not just security, or fraud or marketing. Shopping Bots […]
A man with dress shoes standing on the pavement with two arrows on the ground pointing in different directions representing bot prevention
Bot Management

Build vs. Buy — Bot Prevention Decision

January 29, 2021

5

Read Blog
Recently, we had several prospective customers tell us that they have created their own bot mitigation solution and it was working for them. Without an opportunity to see their solution in operation and the results, we have to believe them. Building your own security solution has always existed with the use of Snort for IDS […]
A blue brick wall with an white arrow on it pointing to the right representing account breach
About Cequence

Your Personal Information Was Stolen, What Now?

January 21, 2021

9

Read Blog
Recommendations for end users concerned about account breach and fraud You’ve received an email, a text, or even a message on social media that someone’s hacked your account, or your credit card has been exposed, or that your computer is under active attack. It’s scary and enough to make your stomach hurt, and you want […]
API Discovery best practices
API Security

API Security Best Practices: API Discovery Insights

January 5, 2021

6

Read Blog
API security best practices dictate that you first need to discover all of your APIs – managed, unmanaged, third-party, shadow and zombie – both external and internal. With the understanding that you cannot protect what you cannot see, most security professionals are often surprised by both the number of APIs actually found and the associated […]
Gift cards on a table representing gift card fraud
Bot Management

Tales From the Front Lines: Retail Customer Stops $200k Gift Card Fraud Scheme

January 4, 2021

4

Read Blog
Our standard customer engagement process is to deploy API Spartan into a customer environment to prove our value. We are often deployed alongside an existing general-purpose bot mitigation solution, with the customer not expecting us to find an attack of any significance. Once deployed, our CQ Prime threat research team works with the customer to […]
A chess board with a pawn taking out a knight representing shopping bots
Bot Management

Technology & Collaboration: The Winning Formula to Defeat Shopping Bots

December 28, 2020

5

Read Blog
As an innovator, software is always the first thing I think about when addressing a problem. But, in a recent blog about shopping bots and the holiday season, Sandy Carielli at Forrester reminded me that you’ve got to think about holistic solutions – comprised of software/technology, people and process – in order to best address […]
Looking up at the trellises of a bridge representing API security and OWASP
OWASP

OWASP API Security Top 10: A Framework for Improving Your API Security Efforts

December 24, 2020

6

Read Blog
OWASP API Security and the OWASP API Top Ten During a recent API Security conversation with a customer, I asked if they had seen the OWASP API Security Top 10 list. They had not heard about it yet, a response that is consistent with other customers as well as from industry analysts including Gartner, Forrester […]
A sunset and a gazing ball with a reflection representing predictions and api security bots
Bot Management

Predictions 2021: Getting an Edge Against the Bots

December 22, 2020

5

Read Blog
In more than one way, the year 2020 was different. The COVID-19 pandemic made us change our plans for the year, and it will have a lasting impact on 2021 and beyond. Let’s look to the future and see if we can predict what 2021 will hold for web application and API security. As API […]
Toy robots marching in a line with shopping bags representing shopping bots
Bot Management

Bot-as-a-Service: The Consumerization of Botting

December 11, 2020

9

Read Blog
We are fast approaching the end of 2020. A year that was different in many ways due to the COVID-19 pandemic, and the impacts on retail were no exception. There has been widespread coverage of retail strategies to survive as physical stores remain closed. Black Friday was not a day but several months this year. […]
Rows of safety deposit boxes with doors open representing FinTech api security
API Security

The Open Banking API Security Imperative

December 8, 2020

5

Read Blog
The second Payment Services Directive (PSD2) in Europe, which requires banks to open their payment services to third parties via a series of APIs, has enabled a range of new FinTech products that make it easier for consumers and businesses to manage their finances. Meanwhile, in North America, there is a drive to adopt a […]
Pink wrapped boxes on a pink background representing retail bot attack
Customer Case Studies

Tales from the Front Lines: Retailer Prepares for Holiday Bot Battle in a Matter of Weeks

December 7, 2020

3

Read Blog
Following on the retail win posted previously, this week’s win is a clothing and home décor retailer that had an account takeover/credential validation challenge that their incumbent solution was unable to address. Bad actors were targeting APIs supporting both their web and mobile logins, successfully executing ATOs. Once the account was taken over, they were […]
A man holding a fishing reel, representing the shift from threat hunting to threat catching.
Bot Management

Moving from Threat Hunting to Threat Catching

December 2, 2020

5

Read Blog
The goal of a Threat Hunter is to find an attacker in the middle of an attack before they can cause damage. This entails hunting through thousands of requests trying to pick out the malicious telemetry emanating from thousands of endpoints that looks like hundreds of different users. The task becomes exponentially more difficult as […]
A clipboard with a piece of paper, pen and laptop computer on a table representing top posts and API security
About Cequence

The Cequence Security Blog – Top 5 Posts of 2020

November 25, 2020

3

Read Blog
As we transition into the last month of 2020, it’s time for my team and I to look back over what we covered this year in the blog and start giving some thought to 2021’s editorial calendar. I know that I definitely have favorite content pieces, but there is something probably even more interesting to […]
A horizon view representing value
Customer Case Studies

Tales from the Front Lines: Large Retailer Achieves Near Immediate Time-to-Value

November 11, 2020

4

Read Blog
One of our newest customers is a large, community-based retailer that had a mobile application and API account takeover problem. Roughly 12 months ago, they selected a JavaScript and SDK-based bot mitigation solution to address their ATO challenges. The initial focus was to protect the mobile applications and associated APIs – and that’s where the […]
Man on laptop, looking at credit card representing enumeration attack
API Security

Tales from the Front Lines: How Third-Party APIs Simplify Enumeration Attacks

November 4, 2020

4

Read Blog
As a mechanism to offload PCI risks, many retailers are now using third-party credit card processing for their online transactions. The retailer’s benefit is they are no longer handling the credit card data, thereby reducing the cardholder footprint (and PCI exposure). The potential drawback to this approach is that now a third-party controls that data. […]
A door with a padlock open representing whitelist attack
Bot Management

Tales from the Front Lines: Whitelist and Forget, A Cautionary Tale

September 28, 2020

3

Read Blog
Stopping attackers and their malicious intent is every security practitioners’ goal. But there are times when we need to grant unfettered access to network resources for day-to-day operations. Better known as whitelisting, I have seen scenarios where an over-zealous whitelist granted from-anywhere to-anywhere access to a database. Security best practices dictate that this level of […]
TAG Cyber Distinguished Vendor
API Security

Cequence Security Named a 2021 TAG Cyber Distinguished Vendor

September 22, 2020

2

Read Blog
Research and advisory firm TAG Cyber has been publishing its seminal Security Annual report since 2016. Thousands of leaders and decision-makers across the cybersecurity ecosystem have come to rely on this report for expert guidance, analysis and education. The organization published this year’s Security Annual today and Cequence Security is proud to be named one […]
Looking up from a cavern and seeing the sky representing api security gaps
API Security

Aite Group Research Validates API Security Gaps

September 2, 2020

2

Read Blog
2020 is moving into the final quarter and it appears to be the year of the API security incident with MGM, Starbucks, Data Viper and Docker as just a few examples of API security incidents. The reasons are obvious – API use has exploded for both developers and bad actors. The same developer benefits of […]
A pair of sunglasses sitting on the beach, representing detection efficacy in the summer heat.
Customer Case Studies

Tales from the Front Lines: Maintaining Detection Efficacy (and Your Cool) in the Summer Heat

August 14, 2020

4

Read Blog
In a previous blog, I talked about how the Covid-19 pandemic lockdown had corresponded to an increase in attack intensity. Since then, different parts of the country have begun to reopen, and in some cases reclosing, yet the attackers have maintained their intensity. So, what is the difference now that we are rounding the corner […]
A post-it note on a bulletin board with a light bulb on it representing api risk
API Security

API Security Need to Know: Questions Every Executive Should Ask About Their APIs

August 4, 2020

4

Read Blog
Using NIST CSF to Reign in your API Footprint As your digital transformation accelerates, it’s API volume and usage has accelerated in tandem. It is also very likely that your API security efforts have lagged behind your increase in API usage. Unlike other more mature areas of cybersecurity, the API security market is still relatively […]
A safe with a key in it representing weak api authentication
API Security

API Security Need-to-Know: Ramifications of Weak API Authentication

July 17, 2020

5

Read Blog
In today’s blog, we will discuss the ramifications of unauthenticated APIs using the recently published ZIPNet vulnerability. ZIPNet is an online application operated by Law Enforcement Authorities in India to share Crime and Criminal information in real time. This includes a registry of reported crimes, wanted criminals, and proclaimed offenders, amongst others. This application was […]
A pay telescope representing api visibility
API Security

I’ve Got 99 Problems and API Visibility Ain’t One of ‘Em

July 13, 2020

5

Read Blog
Getting a handle on API Proliferation for the benefit of the broader organization API proliferation is an issue we hear about from our enterprise customers more and more. For security teams, this is a real problem. Without visibility and access to the APIs developed and deployed across the organization, it is impossible to ensure the […]
A Ground Hog hiding in the woods representing Kasa camera vulnerability
CQ Prime Threat Research

Kasa Camera Vulnerability Discovery: Responsible Disclosures

July 9, 2020

7

Read Blog
When APIs Say Too Much: Discovering the Security Vulnerability As a Midwesterner and hobby farmer I spend a lot of time solving problems. A few months ago I encountered a problem where a live 2-month-old cucumber plant just suddenly had no leaves. A wander around my greenhouse helped me discover that something was knocking things […]
OWASP API Top 10
OWASP

OWASP AppSec Training Day: API Attacks Beyond the OWASP API Top 10

July 2, 2020

3

Read Blog
There still time to register for the upcoming OWASP Training Day: API Attacks Beyond the OWASP API Top 10 led by hacker-in-residence Jason Kent. This class is ideally suited for those who are faced with protecting APIs from attacks as well as those developers looking to learn how their APIs can be compromised and used […]
api gateway security
API Security

Advance Your API Security with Amazon API Gateway & API Sentinel

June 24, 2020

4

Read Blog
API gateways are increasingly used to help accelerate new ventures or transform existing businesses. However, the People and Process components are not as mature, and as a result, some organizations have had to deal with attackers targeting their API endpoints. Cequence Security has recently released a new product, API Sentinel, to help organizations monitor traffic […]
api sentinel
Product News

Announcing Cequence API Sentinel

June 17, 2020

5

Read Blog
We are excited to announce the general availability of Cequence API Sentinel, a new API security service designed to give you continuous run-time visibility, shadow API discovery, risk analysis, and conformance assessment for all your APIs hosted on-premises and in public clouds. If your organization delivers APIs to external parties, such as your customers or […]
protect api's from bot attacks - API attack
API Security

APIs: The Next-Frontier in Cyber-Crime

June 11, 2020

2

Read Blog
This year is turning out to be the year that kicks every company’s digital transformation into high gear in order to support work-from-home and shelter-in-place restrictions. With such a quick shift to and expansion of API-based architectures, it’s important to note the security vulnerabilities and expanded attack surface that are now interesting targets for bad […]
A bullseye representing GET-based attack
Customer Case Studies

Tales from the Front Lines: Attackers Target APIs with GET-Based ATOs

June 8, 2020

5

Read Blog
This blog will describe how account takeovers (ATO) can be executed against APIs using GET methods, as opposed to POST. It’s an excellent example of how bad actors will analyze an application to uncover potential attack vectors. A Brief Primer on GET and POST The GET method allows you to fetch information from a website […]
A cat playing with a mouse representing API attacker behavior
Customer Case Studies

Tales from the Frontlines: Increasingly Sophisticated Cat and Mouse Games

June 4, 2020

5

Read Blog
The last Tales from the Frontlines post focused on a single customer and the attack volume increase they experienced following the COVID-19 lockdown. In this installment, we will look at the increasingly sophisticated game of cat and mouse defenders are playing with attackers, including high-volume diversionary tactics commonly used as distractions from the real attacks. […]
Streaks of lights representing api security
API Security

Moving Fast Without API Guardrails?

June 2, 2020

4

Read Blog
In 1999, Bruce Schneier wrote, “complexity is the worst enemy of security.” Today, I’d argue that speed may be overtaking that top spot or coming darned close. There were two stories published recently about security and privacy issues arising out of apps deployed too quickly. The first disclosure involved North and South Dakota’s COVID-19 contact […]
A pile of puzzle pieces representing API Visibility
API Security

New Survey Highlights Need for API Visibility

May 22, 2020

4

Read Blog
There’s an old saying “you don’t know what you don’t know.” While there are many ways that we can go about filling the gaps in our knowledge – more reading and education, hands-on-investigations and experiment, or maybe even using AI and machine learning – in cyber security I’ve found that if you want to know […]
A magnifying glass on a blue background representing api attack
Customer Case Studies

Tales from the Front Lines: Attackers on Lockdown Focus on APIs

May 15, 2020

4

Read Blog
While the world is battling a Pandemic, our customers are battling an increase in bot activity, as evidenced by traffic and attack patterns over the last four weeks. To an attacker, being in lockdown means they may have more time to focus on their malicious actions. API endpoints seem to be taking more of the […]
A wasp representing OWASP API Security Top 10
OWASP

The OWASP API Security Top 10 From a Real-World Perspective

May 11, 2020

8

Read Blog
The OWASP API Security Top 10 (December 2019) highlights how APIs have become the target du jour for attackers. As someone who is both a longstanding OWASP member and who works at a company that sees attacks against customers’ APIs daily, I think publishing this was a significant first step. It’s not uncommon that, within […]
An illustration depicting the scraping of content being blocked
Customer Case Studies

Tales from the Front Lines: Why Simple Attacks Like Content Scraping are the Hardest to Block

May 6, 2020

7

Read Blog
Of all of the automated business logic abuse attacks, the simple act of copying and pasting content from one web page to another is the most difficult for any technology to stop. Content scraping was one of the problems we designed Cequence Security API Spartan to address, and we purposely avoided relying on agent-based techniques […]
PCI DSS 3.2 compliance and SOC 2 Compliance
About Cequence

Cequence Achieves PCI DSS 3.2 and SOC 2 Compliance

May 1, 2020

3

Read Blog
We are happy to announce that the SaaS deployment of our Application Security Platform has attained both PCI DSS 3.2 Level 2 for Service Providers and SOC 2 Type I compliance. Achieving both of these attestations is an important milestone for the whole Cequence Security team. Compliance matters to us because it matters to our […]
Roads representing CDN Integration bot prevention
Product News

Simplifying Bot Prevention with CDN Integration

April 20, 2020

3

Read Blog
Nearly every customer we speak with is in the process of executing a cloud migration initiative. In many cases, the cloud means first looking into SaaS as the deployment option for a new application. If SaaS cannot address the need, the public cloud is often used to build a custom application. In either case, a […]
diagrams of a phone on a table representing credential stuffing
CQ Prime Threat Research

Creating Credential Stuffing Resistant Applications

April 7, 2020

5

Read Blog
Recently, the amount of coverage on credential stuffing attacks in the news has grown. Organizations that haven’t yet been hit by this type of attack can sometimes overlook the potential risk and cite that it’s an end user’s responsibility to use more secure credentials. However, following a successful attack, many the same organizations find themselves […]
residential proxy threat
CQ Prime Threat Research

Bulletproof Proxy Market Update

April 2, 2020

5

Read Blog
When a hot product hits the market, it’s not uncommon to see multiple vendors follow the first market mover, selling the same or a very similar product. The 2019 research done by Brian Krebs and the CQ Prime Bulletproof Proxies research report both noted a few vendors who were marketing residential proxies (IP addresses) to the public. As the […]
RSA api security 2020
API Security

Hand Sanitizer Samples, Face Masks and API Security: An RSA 2020 Recap

March 2, 2020

3

Read Blog
RSA 2020 wrapped up last week, bringing to an end countless networking events, customer and prospect meetings, and a series of great sessions and keynotes on cybersecurity. Outside of the meetings we had, RSA 2020 will be remembered for the ubiquitous face masks in the city and hand sanitizer samples given away at almost every […]

Get an Attacker’s View
into Your Organization


Schedule A Demo