Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home News

69% of APIs Vulnerable to DoS Attacks

July 22, 2024
Reading Time: 3 mins read
in News
69% of APIs Vulnerable to DoS Attacks

A recent report titled “The State of GraphQL Security 2024” has unveiled alarming security concerns regarding GraphQL APIs, revealing that a significant 69% of API services are susceptible to Denial of Service (DoS) attacks. The report, which analyzed over 13,000 GraphQL API issues, highlights a notable increase in security vulnerabilities, emphasizing that the adoption of GraphQL, projected to rise substantially in the coming years, necessitates immediate attention to these risks. The findings reflect a broader trend of growing security challenges as enterprises increasingly deploy GraphQL for its flexibility and efficiency in API management.

According to the report, a considerable proportion of API services face high-severity issues, with 33% of services affected by critical vulnerabilities. Medium-severity issues were found in 72% of services, while 78% encountered low-severity problems. These vulnerabilities stem from several factors, including unrestricted resource consumption due to inadequate rate limiting and resource allocation mechanisms, which leave APIs vulnerable to DoS attacks. Security misconfigurations and exposed secrets, such as access tokens and passwords, further compound these risks, underscoring the need for more stringent security protocols.

The report identifies key attack vectors that contribute to these vulnerabilities. Among the most significant issues are unrestricted resource consumption, which affects 69% of API services, and security misconfigurations affecting about 11.1% of services. Furthermore, over 4,000 exposed secrets were detected in GraphQL API responses, highlighting a critical area of concern. The financial services and technology sectors are particularly impacted, facing heightened risks due to the sensitive nature of the data they handle. The report notes that despite the critical role of APIs in driving innovation, many organizations still lack proactive security measures, leaving them open to breaches.

To mitigate these vulnerabilities, the report recommends several best practices for securing GraphQL APIs. Key strategies include implementing robust authorization and authentication mechanisms, validating all incoming requests to prevent injection attacks, and applying rate and depth limiting to block brute-force attacks and DoS threats. Schema whitelisting and cost limiting are also advised to manage resource consumption and reduce the attack surface. As GraphQL adoption continues to rise, organizations must adopt these security measures to protect their APIs and ensure the confidentiality and integrity of their data.

Reference:

  • New Security Report Finds 69% of GraphQL API Services Vulnerable to DoS Attacks
Tags: APICyber NewsCyber News 2024Cyber threatsCybersecurityGraphQLJuly 2024Vulnerabilities
ADVERTISEMENT

Related Posts

Google Maps Adds Extortion Reporting

Cybersecurity Talent Gap Hits 50 Percent

November 10, 2025
Google Maps Adds Extortion Reporting

FBI Demands Data From Tucows

November 10, 2025
Google Maps Adds Extortion Reporting

Google Maps Adds Extortion Reporting

November 10, 2025

Google Warns AI Will Boost Cybercrime

November 7, 2025
Singapore Law Imposes Caning For Scams

UK Carriers To Block Spoofed Calls

November 7, 2025
French Police Seize Millions In Crypto

French Police Seize Millions In Crypto

November 7, 2025

Latest Alerts

Samsung Flaw Used To Install Landfall

ClickFix Phishing Targets Hotel Systems

Lost iPhone Beware Fake Text Claims

Malicious VS Code Extension Found

CISA Warns Of CentOS Panel Exploit

Gootloader Returns With New Tricks

Subscribe to our newsletter

    Latest Incidents

    Oracle EBS Hack Hits Nearly 30 Victims

    China Hackers Target US Nonprofit

    Hackers Steal Sonicwall Cloud Backups

    US Budget Office Hit By Cyberattack

    Hyundai AutoEver Reports Data Breach

    Clop Claims Washington Post Breach

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial