Modern applications are much different from those we built just a few years back. As an example, today’s web, mobile and IoT applications are much more reliant on APIs to enable functionality, extensibility and integrations with other applications.  The increased usage of APIs by developers combined with the uniqueness of each API is forcing us to rethink how we approach penetration testing for modern applications.

As APIs have proliferated across SaaS, web, mobile, microservices and IoT applications environments – and the quantity and sensitivity of the data transmitted have increased – API attacks have become more frequent and more complex, making them the number one threat for any company.

The Open Web Application Security Project (OWASP) recognized API security as a primary concern, with nine of the top 10 vulnerabilities in their current OWASP Top 10 report including an API component.