Menu

  • Alerts
  • Incidents
  • News
  • APTs
  • Cyber Decoded
  • Cyber Hygiene
  • Cyber Review
  • Cyber Tips
  • Definitions
  • Malware
  • Threat Actors
  • Tutorials

Useful Tools

  • Password generator
  • Report an incident
  • Report to authorities
No Result
View All Result
CTF Hack Havoc
CyberMaterial
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
Hall of Hacks
  • Education
    • Cyber Decoded
    • Definitions
  • Information
    • Alerts
    • Incidents
    • News
  • Insights
    • Cyber Hygiene
    • Cyber Review
    • Tips
    • Tutorials
  • Support
    • Contact Us
    • Report an incident
  • About
    • About Us
    • Advertise with us
Get Help
No Result
View All Result
Hall of Hacks
CyberMaterial
No Result
View All Result
Home News

69% of APIs Vulnerable to DoS Attacks

July 22, 2024
Reading Time: 3 mins read
in News
69% of APIs Vulnerable to DoS Attacks

A recent report titled “The State of GraphQL Security 2024” has unveiled alarming security concerns regarding GraphQL APIs, revealing that a significant 69% of API services are susceptible to Denial of Service (DoS) attacks. The report, which analyzed over 13,000 GraphQL API issues, highlights a notable increase in security vulnerabilities, emphasizing that the adoption of GraphQL, projected to rise substantially in the coming years, necessitates immediate attention to these risks. The findings reflect a broader trend of growing security challenges as enterprises increasingly deploy GraphQL for its flexibility and efficiency in API management.

According to the report, a considerable proportion of API services face high-severity issues, with 33% of services affected by critical vulnerabilities. Medium-severity issues were found in 72% of services, while 78% encountered low-severity problems. These vulnerabilities stem from several factors, including unrestricted resource consumption due to inadequate rate limiting and resource allocation mechanisms, which leave APIs vulnerable to DoS attacks. Security misconfigurations and exposed secrets, such as access tokens and passwords, further compound these risks, underscoring the need for more stringent security protocols.

The report identifies key attack vectors that contribute to these vulnerabilities. Among the most significant issues are unrestricted resource consumption, which affects 69% of API services, and security misconfigurations affecting about 11.1% of services. Furthermore, over 4,000 exposed secrets were detected in GraphQL API responses, highlighting a critical area of concern. The financial services and technology sectors are particularly impacted, facing heightened risks due to the sensitive nature of the data they handle. The report notes that despite the critical role of APIs in driving innovation, many organizations still lack proactive security measures, leaving them open to breaches.

To mitigate these vulnerabilities, the report recommends several best practices for securing GraphQL APIs. Key strategies include implementing robust authorization and authentication mechanisms, validating all incoming requests to prevent injection attacks, and applying rate and depth limiting to block brute-force attacks and DoS threats. Schema whitelisting and cost limiting are also advised to manage resource consumption and reduce the attack surface. As GraphQL adoption continues to rise, organizations must adopt these security measures to protect their APIs and ensure the confidentiality and integrity of their data.

Reference:

  • New Security Report Finds 69% of GraphQL API Services Vulnerable to DoS Attacks
Tags: APICyber NewsCyber News 2024Cyber threatsCybersecurityGraphQLJuly 2024Vulnerabilities
ADVERTISEMENT

Related Posts

UK Cyber Talent Demand High With Skills Gap

Japan enacts a new Cyberdefense Law

May 19, 2025
UK Cyber Talent Demand High With Skills Gap

Hackers Net $1M For ZeroDay Flaws at Pwn2Own

May 19, 2025
UK Cyber Talent Demand High With Skills Gap

UK Cyber Talent Demand High With Skills Gap

May 19, 2025
Lawmakers Urge Cyber Bill Renewal Soon

Lawmakers Urge Cyber Bill Renewal Soon

May 16, 2025
Lawmakers Urge Cyber Bill Renewal Soon

US Charges 12 More in $230M Crypto Theft

May 16, 2025
Lawmakers Urge Cyber Bill Renewal Soon

Proofpoint to Acquire Hornetsecurity

May 16, 2025

Latest Alerts

Mozilla Urgent Firefox Patch Fixes RCE Flaws

ModiLoader Malware Targets Windows Users

Glibc Flaw Gives Linux Root Access Risk

Fileless Remcos RAT Delivery Via LNK Files

FBI Warns of AI Voice Phishing Scams

APT28 RoundPress Webmail Hack Steals Emails

Subscribe to our newsletter

    Latest Incidents

    Massive DDoS Hits Poland’s Civic Platform

    Arla Plant Cyberattack Halts Operations

    Georgia’s Harbin Clinic Hit by Data Breach

    Hackers Target Swiss Reserve Power Plant

    Coinbase Insider Attack Exposed User Data

    Cyberattack Hits J Batista Group

    CyberMaterial Logo
    • About Us
    • Contact Us
    • Jobs
    • Legal and Privacy Policy
    • Site Map

    © 2025 | CyberMaterial | All rights reserved

    Welcome Back!

    Login to your account below

    Forgotten Password?

    Retrieve your password

    Please enter your username or email address to reset your password.

    Log In

    Add New Playlist

    No Result
    View All Result
    • Alerts
    • Incidents
    • News
    • Cyber Decoded
    • Cyber Hygiene
    • Cyber Review
    • Definitions
    • Malware
    • Cyber Tips
    • Tutorials
    • Advanced Persistent Threats
    • Threat Actors
    • Report an incident
    • Password Generator
    • About Us
    • Contact Us
    • Advertise with us

    Copyright © 2025 CyberMaterial