Synack Expands Security Platform with Adversarial API Pentesting
Synack, the premier security testing platform, has launched an API pentesting capability powered by its global community of elite security researchers. Organizations can now rely on the Synack platform for continuous pentesting coverage across βheadlessβ API endpoints that lack a user interface and are increasingly exposed to attackers.
βSynackβs human-led, adversarial approach is ideal for testing APIs that form the backbone of societyβs digital transformation,β said Synack CTO and co-founder Mark Kuhr, a former National Security Agency cybersecurity expert. βWe are thrilled to offer customers a unique, scalable way to secure this growing area of their attack surfaces.β
Gartner estimates API abuses will be the most common source of data breaches in enterprise web applications this year. Synack enables organizations to verify exploitable API vulnerabilities like broken authorization and authenticationβnoted in the OWASP API top 10βcanβt be abused by malicious hackers.
βMany organizations are struggling to find the top-tier cyber talent needed to root out API-specific vulnerabilities,β said Peter Blanks, Chief Product Officer at Synack. βWeβre excited to extend our Synack platform to provide human-powered offensive security testing on APIs.β
Synackβs headless API capability builds on years of API pentesting experience through web and mobile applications. The new platform features allow customers to enter API documentation to guide testing scope and coverage. Next, researchers with the Synack Red Team attempt to exploit API endpoints in the way a real external adversary would.
Of the Synack Red Teamβs over 1,500 global members, only those with proven API testing skills are activated on API requests, reducing noise. Synackβs Special Projects division led over 100 successful pentests against headless APIs in 2022, providing customers with critical proof-of-coverage reports while validating researchersβ API expertise.
Vulnerability submissions and testing reports are routed through Synackβs Vulnerability Operations team for a rigorous vetting process before being displayed in the platform, minimizing false positives and ensuring high-quality results.
For more information about Synackβs API security testing, visit our Solutions page.
The post Synack Expands Security Platform with Adversarial API Pentesting appeared first on Synack.