⤷ Title: How API Pen-Testers Approach Systems: Tools, Mindset, and Methodology
════════════════════════
𐀪 Author: Peace Dennis
════════════════════════
ⴵ Time: Wed, 25 Feb 2026 10:20:16 GMT
════════════════════════
⌗ Tags: #api_penetration_testing #crapi #burpsuite #api_testing #penetration_testing
════════════════════════
𐀪 Author: Peace Dennis
════════════════════════
ⴵ Time: Wed, 25 Feb 2026 10:20:16 GMT
════════════════════════
⌗ Tags: #api_penetration_testing #crapi #burpsuite #api_testing #penetration_testing
Medium
How API Pen-Testers Approach Systems: Tools, Mindset, and Methodology
When most people think about penetration testing, they imagine someone aggressively firing payloads at a system until something breaks.
⤷ Title: API TESTING
════════════════════════
𐀪 Author: Abdulnafayk
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 05:59:17 GMT
════════════════════════
⌗ Tags: #red_team #cybersecurity #penetration_testing #vulnerability_management #api_testing
════════════════════════
𐀪 Author: Abdulnafayk
════════════════════════
ⴵ Time: Tue, 10 Mar 2026 05:59:17 GMT
════════════════════════
⌗ Tags: #red_team #cybersecurity #penetration_testing #vulnerability_management #api_testing
Medium
API TESTING
So, what is an API?
⤷ Title: We’re Testing API Security Wrong, Data from 1.4 Million Tests
════════════════════════
𐀪 Author: Akshat Virmani
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 09:01:56 GMT
════════════════════════
⌗ Tags: #owasp #api #api_testing #software_testing #api_security
════════════════════════
𐀪 Author: Akshat Virmani
════════════════════════
ⴵ Time: Fri, 10 Apr 2026 09:01:56 GMT
════════════════════════
⌗ Tags: #owasp #api #api_testing #software_testing #api_security
Medium
We’re Testing API Security Wrong, Data from 1.4 Million Tests
I’ve read enough security reports to know how they usually go. Big numbers, familiar vulnerabilities and lightly repackaged advice.
⤷ Title: Why BOLA is the #1 Threat and How to Automate the “Token Swap” with RoleRival
════════════════════════
𐀪 Author: Role Rival
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 12:07:49 GMT
════════════════════════
⌗ Tags: #idor #api_security #api_testing #owasp_api_security_top_10 #bola
════════════════════════
𐀪 Author: Role Rival
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 12:07:49 GMT
════════════════════════
⌗ Tags: #idor #api_security #api_testing #owasp_api_security_top_10 #bola
Medium
Why BOLA is the #1 Threat and How to Automate the “Token Swap” with RoleRival
In the world of API security, one vulnerability consistently sits at the top of the OWASP Top 10 list: BOLA (Broken Object Level…
⤷ Title: Understanding BOLA — The #1 API Security Risk You Can’t Ignore
════════════════════════
𐀪 Author: Sana Jalil
════════════════════════
ⴵ Time: Sat, 09 May 2026 13:24:36 GMT
════════════════════════
⌗ Tags: #owasp_api_top_10 #bola #api_testing #bug_bounty #api_penetration_testing
════════════════════════
𐀪 Author: Sana Jalil
════════════════════════
ⴵ Time: Sat, 09 May 2026 13:24:36 GMT
════════════════════════
⌗ Tags: #owasp_api_top_10 #bola #api_testing #bug_bounty #api_penetration_testing
Medium
Understanding BOLA — The #1 API Security Risk You Can’t Ignore
Welcome back to my API pentesting series! In this third blog, we’re diving into BOLA (Broken Object Level Authorization) — the #1 API…
⤷ Title: API Pentesting Walkthrough Notes | TryHackMe
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Thu, 28 May 2026 17:10:59 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme #api_testing #penetration_testing #tryhackme_walkthrough
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Thu, 28 May 2026 17:10:59 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme #api_testing #penetration_testing #tryhackme_walkthrough
Medium
API Pentesting Walkthrough Notes | TryHackMe
Chaining API weaknesses to gain deeper access and expose data
⤷ Title: Lab 1#: Exploiting an API endpoint using documentation | Api Testing
════════════════════════
𐀪 Author: mohamed
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 10:54:51 GMT
════════════════════════
⌗ Tags: #api_testing #penetration_testing #bug_bounty #cybersecurity #portswigger_academy_labs
════════════════════════
𐀪 Author: mohamed
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 10:54:51 GMT
════════════════════════
⌗ Tags: #api_testing #penetration_testing #bug_bounty #cybersecurity #portswigger_academy_labs
Medium
Lab 1#: Exploiting an API endpoint using documentation | Api Testing
Hello readers! I’m Mohamed Reda, and today we will walk through how to solve the first lab in PortSwigger’s API testing academy…
⤷ Title: How to Create an APISEC University Account: A Complete Step-by-Step Guide
════════════════════════
𐀪 Author: Neion Chowdhury
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 17:04:15 GMT
════════════════════════
⌗ Tags: #penetration_testing #infosec #api_testing #cybersecurity #api_security
════════════════════════
𐀪 Author: Neion Chowdhury
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 17:04:15 GMT
════════════════════════
⌗ Tags: #penetration_testing #infosec #api_testing #cybersecurity #api_security
Medium
How to Create an APISEC University Account: A Complete Step-by-Step Guide
Introduction
⤷ Title: You’ve Been Using APIs Your Entire Life — Now Let’s Learn How to Break Them
════════════════════════
𐀪 Author: Jijo Shibu
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 07:50:36 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #api #api_testing #api_security
════════════════════════
𐀪 Author: Jijo Shibu
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 07:50:36 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #api #api_testing #api_security
Medium
You’ve Been Using APIs Your Entire Life — Now Let’s Learn How to Break Them
A beginner’s guide to API testing with zero assumed knowledge
⤷ Title: Accessing Private GraphQL Posts — Lab Walkthrough — Portswigger
════════════════════════
𐀪 Author: Cybernerddd
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 19:48:44 GMT
════════════════════════
⌗ Tags: #cybernerddd #cybersecurity #graphql #hacking #api_testing
════════════════════════
𐀪 Author: Cybernerddd
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 19:48:44 GMT
════════════════════════
⌗ Tags: #cybernerddd #cybersecurity #graphql #hacking #api_testing
Medium
Accessing Private GraphQL Posts — Lab Walkthrough — Portswigger
In this lab from PortSwigger’s Web Security Academy, the goal was simple: find the hidden private blog post and extract its secret…
⤷ Title: From Public Key to Admin Access: An RS256-to-HS256 JWT Confusion Attack on crAPI
════════════════════════
𐀪 Author: David Banjo
════════════════════════
ⴵ Time: Sun, 12 Jul 2026 00:38:07 GMT
════════════════════════
⌗ Tags: #api_testing #api_security #cybersecurity #api #crapi
════════════════════════
𐀪 Author: David Banjo
════════════════════════
ⴵ Time: Sun, 12 Jul 2026 00:38:07 GMT
════════════════════════
⌗ Tags: #api_testing #api_security #cybersecurity #api #crapi
Medium
From Public Key to Admin Access: An RS256-to-HS256 JWT Confusion Attack on crAPI
Part 2 of a 2-part series on JWT attacks against crAPI — [catch up on Part 1 here]
⤷ Title: Broken Authentication: Insufficient Session Invalidation on Password Change
════════════════════════
𐀪 Author: Liban Abdisalan
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 20:04:33 GMT
════════════════════════
⌗ Tags: #ethical_hacking #api_testing #cybersecurity #mobile_testing #web_penetration_testing
════════════════════════
𐀪 Author: Liban Abdisalan
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 20:04:33 GMT
════════════════════════
⌗ Tags: #ethical_hacking #api_testing #cybersecurity #mobile_testing #web_penetration_testing
Medium
Broken Authentication: Insufficient Session Invalidation on Password Change
Author: LibanTheHckr63
⤷ Title: When Does an API Become a Security Vulnerability?
════════════════════════
𐀪 Author: @dsfglobal
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 13:22:34 GMT
════════════════════════
⌗ Tags: #api #api_security #api_testing
════════════════════════
𐀪 Author: @dsfglobal
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 13:22:34 GMT
════════════════════════
⌗ Tags: #api #api_security #api_testing
Medium
When Does an API Become a Security Vulnerability?
We use dozens of APIs every day without even realizing it. Whether we are ordering food, checking our bank accounts, or booking a hotel…