Code Platoon, a nonprofit coding bootcamp for Veterans, active duty Servicemembers, and military families, is proud to announce the launch of its newly revamped AI Cloud and DevOps Engineering program.
The majority of companies surveyed are running some form of an API management platform, either developed in-house or from a commercial provider, according to a survey on Application Programming Interface (API) security, API Security: A Disjointed Affair, conducted by Ovum for Distil Networks.
However, the security features included in these API management platforms are inconsistent, with many lacking basic rate limiting functionality. Also of note is the lack of responsibility for API security. There is nearly an even split between those that give responsibility for API Security to their developers and those that allocate it to the IT Security team.
"The use of APIs to enable applications to interact across single and multiple infrastructures is skyrocketing and innovation is being fueled by companies finding new ways to monetize their software assets by exposing APIs to outside developers," said Rik Turner, Senior Analyst at Ovum. "However, exposing APIs to developers outside the company creates significant risk and APIs are becoming a growing target for cyber criminals. This study highlights an alarming lack of consistency and ownership in how API security is addressed."
APIs impact business and the world around us more than most people realize. The fact that API security is flying under the radar and not being adequately addressed should be a red flag prompting organizations to examine their own practices. CIOs and CISOs need to get a handle on how responsibility is addressed within their organizations and decide whether the process is sufficiently robust.
Key findings of the survey include:
The purpose behind APIs
■ 51 percent of respondents said that their rationale for API deployment was to enable their external developer ecosystem
■ 67 percent said partner connectivity was the main goal while 62 percent cited mobility and 57 percent cited cloud integration
API security woes
■ 83 percent of those surveyed were concerned with API security
■ 87 percent of respondents were running an API Management platform, with 63 percent using a platform developed in-house
API management platforms lack critical features and automation
■ Rate limiting, considered to be a basic API security practice, was employed by less than half of respondents
■ Over two-thirds of respondents were spending over 20 hours a month managing API rate limiting
■ Only 21.9 percent of respondents had protection from API malicious usage, API developer errors, automated API scraping, and web and mobile API hijacking
Who is responsible for API security?
■ 53 percent of respondents feel security teams should be responsible for API security, while 47 percent believe the developer teams should hold responsibility
■ 30 percent of APIs are spec'd out without any input from the IT security team and 27 percent of APIs proceed through the development stage without the IT security team weighing in
■ 21 percent of APIs go live without any input from security professionals
Rami Essaid is CEO and Co-Founder of Distil Networks.
Industry News
Salt Security announced the launch of Salt Cloud Connect for AWS, an API security solution to deliver full API visibility and posture governance without the need for traffic data or agents.
CoreWeave announced the launch of three new AI cloud software products and capabilities to help customers develop, deploy, and iterate AI faster.
BrowserStack announced support for Playwright tests on real iOS devices with Safari.
JFrog announced a partnership with TL Consulting, an Australian-based professional services organization specializing in cloud-native, GitHub and Microsoft DevSecOps implementations.
Kusari unveiled Kusari Inspector, an artificial intelligence (AI)-based pull request security tool that brings cutting-edge security risk analysis directly into developers’ daily workflows.
Secure Code Warrior announced the availability of AI Security Rules on GitHub – a free resource to help developers generate more secure code when working with AI coding tools like GitHub Copilot, Cline, Roo, Cursor, Aider and Windsurf.
Mirantis announced a comprehensive reference architecture for IT infrastructure to support AI workloads.
Operant AI announced the launch of MCP Gateway, an expansion of its flagship AI Gatekeeper™ platform, that delivers comprehensive security for Model Context Protocol (MCP) applications.
Oracle has expanded its collaboration with NVIDIA to help customers streamline the development and deployment of production-ready AI, develop and run next-generation reasoning models and AI agents, and access the computing resources needed to further accelerate AI innovation.
Datadog launched its Internal Developer Portal (IDP) built on live observability data.
Azul and Chainguard announced a strategic partnership that will unite Azul’s commercial support and curated OpenJDK distributions with Chainguard’s Linux distro, software factory and container images.
SmartBear launched Reflect Mobile featuring HaloAI, expanding its no-code, GenAI-powered test automation platform to include native mobile apps.
ArmorCode announced the launch of AI Code Insights.
Codiac announced the release of Codiac 2.5, a major update to its unified automation platform for container orchestration and Kubernetes management.