API Abuse – Lessons from the Duolingo Data Scraping Attack

API Abuse – Lessons from the Duolingo Data Scraping Attack

It’s been reported that 2.6 million user records sourced from the Duolingo app are for sale. The attacker apparently obtained them from an open API provided by the company. There’s a more ...

The LinkedIn Data Scraping Verdict — and Its Reversal

In October of last year, a ruling against LinkedIn by The United States Court of Appeals for the Ninth District in San Francisco left many confused. How could the court rule in ...

Client-Side Security: A Win, Win, Win in Cyber Security Risk Mitigation 

By Source Defense Cyber security is about risk mitigation. With headlines about ransomware attacks dominating media headlines over the past couple of years – and over the past few days – it ...
Facebook Instagram social media Siemplify SOC 2

Facebook Vs. NYU and Transparency

On August 3, 2021, Facebook, showed off its full 800-pound gorilla physique by attempting to crush the work of two New York University (NYU) researchers, Laura Edelson and Damon McCoy and their ...
Security Boulevard
NetApp data broker FTC location data

After Van Buren, are Data Scraping Cases Barred?

The federal computer crime law makes it both a criminal offense and a civil offense (you can sue for damages or loss) for someone to “access a computer without authorization” or to ...
Security Boulevard
Data Breaches vs. Data Leaks, FBI Exchange Server Controversy

Data Breaches vs. Data Leaks, FBI Exchange Server Controversy

This week Tom and Kevin are back with an all new episode! Data breaches vs. recent data leaks, and the controversy over the FBI operation conducted to remove web shells from compromised ...
API, ChatGPT, exfiltration API security Salt Security APIs social media

California Federal Court Weighs In (Again) on Social Media Scraping

Social media sites such as Facebook and LinkedIn have collected personal information on hundreds of millions of subscribers. They have also promised those subscribers that their data will only be shared or ...
Security Boulevard
web application DataSecOps

Scraping Attacks: Compromising Web Security, Impacting Business Continuity

We often see businesses devising ingenious ways to pull ahead of competitors in the hyper-competitive online business industry. From tiny startups to business giants such as Amazon and Walmart, companies today have ...
Security Boulevard
Oracle Fixes Critical Vulnerabilities in Business Applications

Oracle Fixes Critical Vulnerabilities in Business Applications

Oracle has released a new quarterly critical patch update (CPU) for its product portfolio, fixing 254 vulnerabilities across 20 product families. More than two-thirds of those flaws are located in business-critical applications ...
Security Boulevard