⤷ Title: Why BOLA is the #1 Threat and How to Automate the “Token Swap” with RoleRival
════════════════════════
𐀪 Author: Role Rival
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 12:07:49 GMT
════════════════════════
⌗ Tags: #idor #api_security #api_testing #owasp_api_security_top_10 #bola
════════════════════════
𐀪 Author: Role Rival
════════════════════════
ⴵ Time: Thu, 23 Apr 2026 12:07:49 GMT
════════════════════════
⌗ Tags: #idor #api_security #api_testing #owasp_api_security_top_10 #bola
Medium
Why BOLA is the #1 Threat and How to Automate the “Token Swap” with RoleRival
In the world of API security, one vulnerability consistently sits at the top of the OWASP Top 10 list: BOLA (Broken Object Level…
⤷ Title: Understanding BOLA — The #1 API Security Risk You Can’t Ignore
════════════════════════
𐀪 Author: Sana Jalil
════════════════════════
ⴵ Time: Sat, 09 May 2026 13:24:36 GMT
════════════════════════
⌗ Tags: #owasp_api_top_10 #bola #api_testing #bug_bounty #api_penetration_testing
════════════════════════
𐀪 Author: Sana Jalil
════════════════════════
ⴵ Time: Sat, 09 May 2026 13:24:36 GMT
════════════════════════
⌗ Tags: #owasp_api_top_10 #bola #api_testing #bug_bounty #api_penetration_testing
Medium
Understanding BOLA — The #1 API Security Risk You Can’t Ignore
Welcome back to my API pentesting series! In this third blog, we’re diving into BOLA (Broken Object Level Authorization) — the #1 API…
⤷ Title: API Pentesting Walkthrough Notes | TryHackMe
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Thu, 28 May 2026 17:10:59 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme #api_testing #penetration_testing #tryhackme_walkthrough
════════════════════════
𐀪 Author: Sle3pyHead
════════════════════════
ⴵ Time: Thu, 28 May 2026 17:10:59 GMT
════════════════════════
⌗ Tags: #tryhackme_writeup #tryhackme #api_testing #penetration_testing #tryhackme_walkthrough
Medium
API Pentesting Walkthrough Notes | TryHackMe
Chaining API weaknesses to gain deeper access and expose data
⤷ Title: Lab 1#: Exploiting an API endpoint using documentation | Api Testing
════════════════════════
𐀪 Author: mohamed
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 10:54:51 GMT
════════════════════════
⌗ Tags: #api_testing #penetration_testing #bug_bounty #cybersecurity #portswigger_academy_labs
════════════════════════
𐀪 Author: mohamed
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 10:54:51 GMT
════════════════════════
⌗ Tags: #api_testing #penetration_testing #bug_bounty #cybersecurity #portswigger_academy_labs
Medium
Lab 1#: Exploiting an API endpoint using documentation | Api Testing
Hello readers! I’m Mohamed Reda, and today we will walk through how to solve the first lab in PortSwigger’s API testing academy…
⤷ Title: How to Create an APISEC University Account: A Complete Step-by-Step Guide
════════════════════════
𐀪 Author: Neion Chowdhury
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 17:04:15 GMT
════════════════════════
⌗ Tags: #penetration_testing #infosec #api_testing #cybersecurity #api_security
════════════════════════
𐀪 Author: Neion Chowdhury
════════════════════════
ⴵ Time: Wed, 03 Jun 2026 17:04:15 GMT
════════════════════════
⌗ Tags: #penetration_testing #infosec #api_testing #cybersecurity #api_security
Medium
How to Create an APISEC University Account: A Complete Step-by-Step Guide
Introduction
⤷ Title: You’ve Been Using APIs Your Entire Life — Now Let’s Learn How to Break Them
════════════════════════
𐀪 Author: Jijo Shibu
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 07:50:36 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #api #api_testing #api_security
════════════════════════
𐀪 Author: Jijo Shibu
════════════════════════
ⴵ Time: Fri, 05 Jun 2026 07:50:36 GMT
════════════════════════
⌗ Tags: #web_security #cybersecurity #api #api_testing #api_security
Medium
You’ve Been Using APIs Your Entire Life — Now Let’s Learn How to Break Them
A beginner’s guide to API testing with zero assumed knowledge
⤷ Title: Accessing Private GraphQL Posts — Lab Walkthrough — Portswigger
════════════════════════
𐀪 Author: Cybernerddd
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 19:48:44 GMT
════════════════════════
⌗ Tags: #cybernerddd #cybersecurity #graphql #hacking #api_testing
════════════════════════
𐀪 Author: Cybernerddd
════════════════════════
ⴵ Time: Tue, 30 Jun 2026 19:48:44 GMT
════════════════════════
⌗ Tags: #cybernerddd #cybersecurity #graphql #hacking #api_testing
Medium
Accessing Private GraphQL Posts — Lab Walkthrough — Portswigger
In this lab from PortSwigger’s Web Security Academy, the goal was simple: find the hidden private blog post and extract its secret…
⤷ Title: From Public Key to Admin Access: An RS256-to-HS256 JWT Confusion Attack on crAPI
════════════════════════
𐀪 Author: David Banjo
════════════════════════
ⴵ Time: Sun, 12 Jul 2026 00:38:07 GMT
════════════════════════
⌗ Tags: #api_testing #api_security #cybersecurity #api #crapi
════════════════════════
𐀪 Author: David Banjo
════════════════════════
ⴵ Time: Sun, 12 Jul 2026 00:38:07 GMT
════════════════════════
⌗ Tags: #api_testing #api_security #cybersecurity #api #crapi
Medium
From Public Key to Admin Access: An RS256-to-HS256 JWT Confusion Attack on crAPI
Part 2 of a 2-part series on JWT attacks against crAPI — [catch up on Part 1 here]
⤷ Title: Broken Authentication: Insufficient Session Invalidation on Password Change
════════════════════════
𐀪 Author: Liban Abdisalan
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 20:04:33 GMT
════════════════════════
⌗ Tags: #ethical_hacking #api_testing #cybersecurity #mobile_testing #web_penetration_testing
════════════════════════
𐀪 Author: Liban Abdisalan
════════════════════════
ⴵ Time: Wed, 15 Jul 2026 20:04:33 GMT
════════════════════════
⌗ Tags: #ethical_hacking #api_testing #cybersecurity #mobile_testing #web_penetration_testing
Medium
Broken Authentication: Insufficient Session Invalidation on Password Change
Author: LibanTheHckr63
⤷ Title: When Does an API Become a Security Vulnerability?
════════════════════════
𐀪 Author: @dsfglobal
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 13:22:34 GMT
════════════════════════
⌗ Tags: #api #api_security #api_testing
════════════════════════
𐀪 Author: @dsfglobal
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 13:22:34 GMT
════════════════════════
⌗ Tags: #api #api_security #api_testing
Medium
When Does an API Become a Security Vulnerability?
We use dozens of APIs every day without even realizing it. Whether we are ordering food, checking our bank accounts, or booking a hotel…