Home
Categories
EXPLORE
True Crime
Comedy
Business
Society & Culture
History
Sports
Health & Fitness
About Us
Contact Us
Copyright
© 2024 PodJoint
00:00 / 00:00
Sign in

or

Don't have an account?
Sign up
Forgot password
https://is1-ssl.mzstatic.com/image/thumb/Podcasts211/v4/e6/d4/f8/e6d4f8f2-2745-2206-73db-f1c595e6920a/mza_15332271287132926665.jpg/600x600bb.jpg
The API Hour
Christine Bevilacqua
3 episodes
2 months ago
The API Hour is your front-row seat to where APIs meet InfoSec. Hosted by Dan Barahona and brought to you by APIsec University, each episode dives into real-world breaches, testing tactics, and the tools shaping AppSec. Whether you're building, breaking, or securing APIs, you'll get practical insights from the experts redefining API security. Plug in, lock down, and decode what’s really going on behind the APIs—because in a connected world, security is everything.
Show more...
Technology
RSS
All content for The API Hour is the property of Christine Bevilacqua and is served directly from their servers with no modification, redirects, or rehosting. The podcast is not affiliated with or endorsed by Podjoint in any way.
The API Hour is your front-row seat to where APIs meet InfoSec. Hosted by Dan Barahona and brought to you by APIsec University, each episode dives into real-world breaches, testing tactics, and the tools shaping AppSec. Whether you're building, breaking, or securing APIs, you'll get practical insights from the experts redefining API security. Plug in, lock down, and decode what’s really going on behind the APIs—because in a connected world, security is everything.
Show more...
Technology
Episodes (3/3)
The API Hour
Hacking AI and Retraining LLMs
2 months ago
1 hour 1 minute 37 seconds

The API Hour
Inside this Year's Biggest API breaches: Real Stories, Real Lessons
In this episode of The Appi Hour, Dan is joined by Dave, Head of Products at APIsec, to unpack some of the most eye-opening API breaches making waves. From leaked API keys at xAI, to McDonald’s exposing 64 million job applications, to logic flaws in Base44’s vibe-coding platform, and even a Volkswagen app that let attackers brute-force their way into cars—the stories are as shocking as they are instructive. Dave brings frontline experience from working with customers on API security, highlighting how seemingly small oversights—like hardcoded keys, weak authentication, or unchecked authorization—can snowball into massive vulnerabilities. Together, they connect each case to the OWASP API Security Top 10 and share practical steps to avoid these same pitfalls. Whether you’re a developer, security engineer, or simply curious about how everyday apps get hacked, this conversation offers valuable insights (and a reminder of how critical APIs are in today’s digital world). What you’ll learn: Why API keys remain one of the most common—and preventable—security leaks How researchers accessed 64 million McDonald’s job applications via a simple IDOR flaw The hidden risks of convenience-driven platforms like Base44 How a used Volkswagen exposed its owner’s data through predictable APIs Best practices for preventing brute force, excessive data exposure, and broken authorization Tune in, take notes, and walk away with actionable tactics to strengthen your own API security posture.
Show more...
2 months ago
33 minutes 43 seconds

The API Hour
Breaking your Build Before Hackers Do
🎙️ API Security Meets DevSecOps with Scott Bly In this episode of The API Hour, cybersecurity expert Scott Bly joins host Dan Barahona to explore how integrating security into the DevOps lifecycle—aka DevSecOps—transforms API protection. From threat modeling and security metrics to the role of AI and gamification, this is a must-listen for teams aiming to balance speed with security. Learn how to embed security culture across development teams and build smarter, safer APIs.
Show more...
3 months ago
42 minutes 45 seconds

The API Hour
The API Hour is your front-row seat to where APIs meet InfoSec. Hosted by Dan Barahona and brought to you by APIsec University, each episode dives into real-world breaches, testing tactics, and the tools shaping AppSec. Whether you're building, breaking, or securing APIs, you'll get practical insights from the experts redefining API security. Plug in, lock down, and decode what’s really going on behind the APIs—because in a connected world, security is everything.