APIsec University’s cover photo
APIsec University

APIsec University

Computer and Network Security

San Francisco, CA 43,817 followers

APIsec University provides free API Security training. Learn how to find API vulnerabilities and keep them secure.

About us

Become an API Security Expert. APIs power virtually every mobile and web application, enable integrations across organizations, and drive more rapid innovation and development. APIs have also become the primary target for attackers, resulting in thousands of breaches and billions of records stolen. APIsec University exists to help develop the next generation of API Defenders. Get started today.

Website
www.apisecuniversity.com
Industry
Computer and Network Security
Company size
11-50 employees
Headquarters
San Francisco, CA
Type
Privately Held
Founded
2022
Specialties
api security, application security, and cybersecurity training

Locations

Employees at APIsec University

Updates

  • 🚀 AU Chapters are officially live! We're excited to announce that APIsec University is expanding beyond the classroom, and beyond Discord. Local AU Chapters are student and professional-led communities built around one mission: making API(with or without a P!) security education accessible, hands-on, and local. Chapters host meetups, study groups, and events, giving members a way to learn together and build real connections in their own city or university. Want to find a chapter near you? Check out our growing list of active chapters, along with their socials and community links: 🔗 https://lnkd.in/gYzg7pCy Don't see one in your area? Start it. AU Chapters are led by our Ambassadors, who receive direct support, resources, and recognition from the AU team to help them grow a thriving local community from scratch. 🔗 Apply to become an Ambassador: https://lnkd.in/gkig9dXj This is just the beginning. If you care about API security and want to bring that passion to your community, we'd love to have you lead the charge. #APIsecurity #Cybersecurity #Community #Ambassadors #APIsecUniversity

    • No alternative text description for this image
  • APIsec University reposted this

    Summer Camp! I'm out in the dry heat 8/4 through 8/8. Where to find me: Wed 8/5, 10:30 AM - Black Hat lightning talk with PortSwigger: Instant API Hacker (Extra Instant) Wed 8/5, 6 PM - Vuln Vibes Thu 8/6, 3 to 6 PM - Clearly AI Happy Hacker Happy Hour Fri 8/7, 1 to 2 PM - Debut of my new talk, One Request to Rule Them All, at Red Team Village Fri 8/7, 7 PM - RTV DEF CON Party Two talks, one of them brand new. One Request to Rule Them All has never been on a stage before. Friday is its first run. Looking forward to seeing the APIsec University alumni and ambassadors, Chris Honda, the PortSwigger crew ( Amelia Coen, James Kettle, Dafydd Stuttard), fellow Burp Suite Ambassadors Katie Paxton-Fear, Tib3rius, 🎩 Alan L., 🎩 Alan L., and Ads Dawson, plus Tyler Ramsbey and Kevin Apolinario out at Noob Village. Hit me up for coffee, drinks, the latest API vulns, or to talk about how you've been burning the midnight tokens.

    • No alternative text description for this image
  • APIsec University reposted this

    Is AI red teaming a scam?🤨 does safety benchmark performance actually demonstrate relative safety? or do we just need realistic clarity on what AI safety evaluations can and cannot tell us? These are some of the questions behind my latest side quest. partly taking inspiration from the history of drug trials, the preprint titled "What AI Red-Team Evaluations Can and Cannot Prove" tries to answer the (very big) question: when a red-team evaluation finds no successful attacks, what exactly have we learned? this paper tries to formalise that problem and identify an evidential ceiling, defined as a point beyond which a given evaluation cannot provide strong evidence of safety, regardless of how clean the observed results are. Preprint: https://lnkd.in/g-2HFRAM Repo: https://lnkd.in/gM6wi2GS ...but then something happened that was definitely NOT on my bingo card before turning 19: seeing my own research leave my laptop and become part of conversations much outside my own little corner of the internet. I had so many brilliant researchers reach out to me asking thoughtful questions, challenging the premise and supporting my work. I’m incredibly grateful to everyone who took the time to read the paper, engage with it, and also to the media outlets that discussed my work for giving the research such a thoughtful and accessible feature, just days after preprint. and honestly, this is one of the many reasons why I love research. you put an idea out into the world, and suddenly it starts travelling places you never expected and reaching people you never could've reached otherwise. https://lnkd.in/gEqi9gq9 My next steps for this would be refining the framework further, validating it, and extending it to other forms of AI evaluation. I'm always open to super fun research collaborations!! lets make AI safety evals more reliable🩷 Always grateful to the researchers whose work i built on, and our team at APIsec Research Labs for their continued support José Haro Peralta Rajaram (Raj) Ramanathan Mohsin Niyazi Corey J. Ball as alwayyyssss, happy hacking!! <3 HackWitHer #aisafety #aisecurity #llms #research

    • No alternative text description for this image
    • No alternative text description for this image
  • APIsec University reposted this

    Cascading Effects of Repackaged APIs: Research on a security surface most AppSec conversations miss. Most API security work focuses on a single provider–consumer relationship. But what happens when a service (Web1) buys legitimate bulk access to a Parent API and resells it downstream to Web2, Web3, etc.? My paper maps what breaks in that chain: → Compounding latency -- each hop re-serializes the payload; a 3-hop chain can add 40-50%+ delay over a direct connection → The Auditability Vacuum -- Provider A only sees Web1's traffic fingerprint, masking thousands of end users and defeating IP/behavioral bans → Middleware Risk -- each layer injecting its own system prompts/headers can mutate requests enough to bypass content filters or cause hallucinated outputs blamed on the original provider → The CFAA gray zone -- Web1 uses valid credentials, so this is a ToS breach, not a CFAA violation, leaving providers stuck with slow civil litigation. I propose a zero-trust mitigation: recursive JWT signatures binding each layer's identity, so Provider A can reject any request missing a verifiable signature chain, plus behavioral fingerprinting (request burstiness, timing patterns) as a backstop. Read the full paper here: https://lnkd.in/dPx8aCv9 Shoutout to Corey J. Ball and APIsec for their work advancing API security research! Would love to hear thoughts and feedback from the AppSec and vulnerability research community. #Cybersecurity #APISecurity #AppSec #CloudSecurity #InformationSecurity #VulnerabilityResearch

  • APIsec University reposted this

    What happens when developers prioritize speed, security teams focus on risk, and GRC insists on compliance? Too often, they pull in different directions. But what if they could work together to build secure, resilient, and trusted digital products without sacrificing innovation? Join us for API Shield Summit 1.0, an engaging X Spaces conversation hosted by APIsec University Nigeria in partnership with Cybarik, where we’ll explore one of the biggest challenges in modern software development: “Building, Breaking & Governing: Can Developers, Security Researchers & GRC Ever Truly Align?” This isn’t just another cybersecurity discussion. It’s a conversation designed to bridge the gap between the people who build applications, those who test and break them to make them stronger, and those responsible for governance, risk, and compliance. What to expect: 🔹 Diverse perspectives from industry professionals 🔹 Practical insights and real-world experiences 🔹 Interactive discussions and audience engagement 🔹 Actionable ideas for improving collaboration across teams I’m excited to be hosting this conversation alongside Kosisochukwu Eneh , with an amazing lineup of speakers: * Jess Freeman Freeman – Deployment Success Manager * Joseph Adewunmi – Software Engineer * Vivian Nesiama – GRC Analyst * Robert Leyba – AI Engineer Date: Saturday, 1st August Time: 7:00 PM – 8:00 PM (WAT) Venue: X Spaces. https://lnkd.in/eDh33wAY Whether you’re a developer, security engineer, penetration tester, GRC professional, product manager, student, or technology enthusiast, this conversation is for you. Save the date, invite a colleague, and let’s explore how collaboration, not conflict,can become the foundation of secure digital innovation. See you on X Spaces! Dr Iretioluwa Akerele APIsec U Nigeria Affan Ali #APIShieldSummit #APISecurity #CyberSecurity #DevSecOps #GRC #SecureByDesign #Developers #EthicalHacking #APIsecUniversity #Cybarik #DigitalTrust #InfoSec #XSpaces

    • No alternative text description for this image
  • APIsec University reposted this

    We figured what better way to launch our brand new newsletter than to give you a window into some phenomenal new open source offerings that Corey J. Ball, Bandana Kaur, Rajaram (Raj) Ramanathan, José Haro Peralta, Mohsin Niyazi, Dave Piskai, and the rest of the crew over here at apisec have been working on. Check it out and let us know what you think in the comments (and over on our GitHub repo).

  • We figured what better way to launch our brand new newsletter than to give you a window into some phenomenal new open source offerings that Corey J. Ball, Bandana Kaur, Rajaram (Raj) Ramanathan, José Haro Peralta, Mohsin Niyazi, Dave Piskai, and the rest of the crew over here at apisec have been working on. Check it out and let us know what you think in the comments (and over on our GitHub repo).

  • APIsec University reposted this

    ASCP, ACP and CASA Certifications Review This year I did a full review of my API exploitation knowledge, validating it with APIsec University's 3 certification exams: CASA, ACP, and ASCP. Studying happened in May and June; exams were between late June and early July. Sharing this experience for anyone considering these certs. APIsec University is a major reference in API security — proof of that: its ASCP is one of the Synack Red Team's SRT Pathways, granting a resume review bypass and a technical review bypass for SRT applicants. SRT is the group of security researchers selected for Synack's bug bounty and pentest programs. CASA and ACP cover the theory: OWASP API Top 10, core concepts and fundamentals. 100 questions each — CASA more conceptual, ACP more scenario-based. ACP is the evolution of CASA, but I'd call both entry-level. ASCP is where it gets real: 12 hours testing two API apps that simulate production systems, going through every phase of a pentest — mapping the attack surface, exploiting Broken Authentication, BOLA, Mass Assignment, then post-exploiting to increase impact. What stood out most: you must escalate impact to get proof of exploitation, which means chaining vulnerabilities together. A heads-up: the spec mentions 8 flags, 4 per app, and you might assume it's CTF-style — one vuln per flag. It's not. You need pentester reasoning, because each flag is evidence of a full compromise of part of the API. That was clearest with the last secret I captured. Unlike anything I'd seen in a CTF before — the way the data was hidden broke completely from any pattern I knew, and it made me rethink how information can leak inside an organization. Pros: practical, current content close to real environments; great value (all courses are free and includes a free retake); chaining demands real pentester reasoning, not memorization; you get a digital badge, physical certificate, and challenge coin. Cons: market recognition is still limited — not common as a job requirement; and CASA's 100 questions feel like a lot for an entry-level cert, especially since ACP (one tier up, requiring 5 courses) uses the same count. Advice for the ASCP: study the fundamentals, train in crAPI/vAPI and beyond, but above all train your mind to chain exploits and amplify impact. API pentesting is about understanding the system, not collecting flags. Recommended for anyone in API security, pentesting, or dev — it tests real knowledge, not just a certificate for the wall. #APIsecUniversity #ASCP #APISecurity #CyberSecurity #ApplicationSecurity #PenetrationTesting #DevSecOps #APISecurityCertified

  • APIsec University reposted this

    i'm not entirely convinced "AI makes slop" is the most productive way to think about what's happening to bug bounty programs. to me, it's an interesting collision between the changing economics of vulnerability disclosure and measurement theory(specifically, goodhart's law making yet another appearance) this is a concept that gets brought up a lot in economics and AI alignment, but i think it also gives us a surprisingly useful lens for understanding what's happening to bug bounty programs in the absolute tsunami of llm-generated reports. now theres two dynamics at play here(a "double Goodhart", if you will): for years, things like polished writeups, detailed reproduction steps, and technically convincing reports were good proxies for genuine security research. but what happens when those proxies become almost free to generate? suddenly, the thing we were measuring isn't necessarily the thing we care about anymore. at the same time, the some participants themselves started optimising for their own metrics, resulting in an adversarial Goodhart effect, and the combination of these factors may help explain the overall degradation of many bug bounty programs for all researchers. we published an article at APIsec Research Labs recently, drawing inferences based on curl report data published by Daniel Stenberg in his blog posts, as well as other sources like H1. our goal with this article was to give the industry a fresh lens to think about these shifts in bug bounty platforms and vuln disclosure practices. we break down what happens when the economics of producing a signal change and why that matters for security, evaluation, and the way we design incentives. link in the comments!! would love to hear whether people think Goodhart's Law is the right framework here, or if there's a better way to think about what's happening. as always, happy hacking!! HackWitHer 🩷 Rajaram (Raj) Ramanathan José Haro Peralta Mohsin Niyazi Corey J. Ball Jess Freeman #CyberSecurity #AISecurity #BugBounty #LLMs #GoodhartsLaw

    • No alternative text description for this image
  • APIsec University reposted this

    It's been a great day for APIsec U Pakistan!! Yesterday, we successfully hosted our first Technical Session, and it was an amazing experience to see our community come together to learn, discuss, and explore one of the most critical API security vulnerabilities: 🔐 BOLA (Broken Object Level Authorization) A huge thank you to Huzaifah Tahir for delivering an insightful session that covered: ✅ What BOLA is and why it remains the #1 vulnerability in the OWASP API Security Top 10. ✅ How BOLA vulnerabilities occur, explained through both theory and practical demonstrations. ✅ Best practices and effective prevention techniques to build more secure APIs. The engaging discussions, practical examples, and active participation from the community made this session a great success. We're excited to see API security enthusiasts, students, and professionals learning together and strengthening their offensive and defensive API security skills. This is just the beginning... Over the coming weeks, we'll be diving into many more API vulnerabilities and some exciting stuff, understanding how they work, practically exploiting them in a safe learning environment, and discussing effective mitigation strategies. If you haven't joined our community yet, we'd love to have you with us! 🔗 Join our Discord Community: https://lnkd.in/dVr9wQ2W See you at the next Technical Saturday Session! 🚀 #APISecurity #OWASP #OWASPAPI #BOLA #CyberSecurity #EthicalHacking #ApplicationSecurity #APIsecUniversity #APIsecUPakistan #InfoSec #Learning #Pakistan

    • No alternative text description for this image

Similar pages

Browse jobs