Select your language

APIs: Between the Digital Business Engine and a Growing Attack Surface

 Application programming interfaces (APIs) play a crucial role in the operation of digital platforms, however, they have also become one of the most exploited attack focuses by cybercriminals, according to the report State of API and Application Security 2025: How Artificial Intelligence Transforms the Digital Landscape, disseminated by Akamai.

The paper notes that APIs enable communication between systems for real-time data exchange. "For example, when we access our bank's application to pay taxes, that transaction crosses information with APIs from the tax service, civil registry, banks and other systems. Everything happens in seconds and invisibly to the user, but each of these APIs can be vulnerable if it is not protected," explained Jairo Parra, Akamai's cybersecurity specialist for Latin America.

According to the report, organizations in Latin America face growing threats. The most vulnerable industries include digital commerce, payment processors, banks, insurers, fintechs, and cryptocurrency platforms.  Akamai recorded more than 311 billion attacks against APIs and web applications globally by 2024, an increase of 33% from the previous year.

The economic consequences are also evident in the study. It is estimated that security problems in APIs generate annual losses of about 87 billion dollars, a figure that could exceed 100 billion by 2026 if adequate measures are not adopted. Likewise, incidents associated with the top 10 risks detected by OWASP increased by 32%.

- Publicidad -

 Another crucial flaw identified by Akamai is the lack of visibility.  Despite the fact that 47% of security teams claim to have a full inventory of their APIs, many are unaware of which APIs handle private information.  In a test scenario, Akamai's research team managed to change the price of a product to zero pesos on an e-commerce platform through a flaw in its API, without either the system or the team identifying the irregularity.

Parra indicated that "companies do not measure the number of APIs they use or the risks they face by not managing them properly."

The report also exposes the limitations of traditional security solutions, which make it difficult for organizations to:

Know how many APIs are active.

Identify abuse or unusual behavior.

 Detect security bugs during the development process.

 Identify APIs that handle sensitive data without proper control.

- Publicidad -

 The report adds that these solutions are not designed to meet standards such as the OWASP Top 10, which records common vulnerabilities such as data exposure, authentication failures, and configuration errors.

"Does your company know how many APIs it uses, which ones communicate with third-party applications, if those institutions are regulated and if the information they traffic complies with security standards?" asked Parra.

To address these risks, Akamai recommends adopting technologies that offer end-to-end API visibility, real-time anomaly monitoring, access control, and compliance, as well as implementing practices aligned with OWASP guidelines.

"APIs are the backbone of digital business, but also its Achilles' heel if they are not managed with proper security," Parra concluded.

Andrea Ochoa Restrepo
Andrea Ochoa RestrepoEmail: [email protected]
Editora
Comunicadora Social- Periodista. MSC en Economía Aplicada con énfasis en Políticas Públicas. Diplomada en Emergencia Climática. Con más de 12 años en medios.

No comments

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Security industry in Mexico and Latin America continues its expansion and professionalization

Security industry in Mexico and Latin America continues its expansion and professionalization

International. The security industry in Mexico and Latin America maintains a growth trend driven by digital transformation, the increase in physical and cyber risks, as well as the need to protect...

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

United States. Veeam Software today announced the launch of Agent Commander, a solution aimed at helping organizations detect risks associated with artificial intelligence, protect AI-based systems...

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

In industries where every minute counts, efficient asset and resource management has become a strategic factor to ensure operational continuity, safety, and productivity. By: Héctor Meléndez,...

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Puerto Rico. A centralized monitoring operation developed by Genesis Security was able to significantly reduce the volume of false alarms in its security systems, thanks to the integration of...

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Türkiye. An open-ocean fish farming farm in Turkey implemented a smart surveillance system based on Dahua solar cameras, thermal monitoring, and wireless data transmission to improve safety and...

 The Hidden Security Gap in Data Centers

The Hidden Security Gap in Data Centers

Imagine the journey of an authorized technician inside a data center. When he arrives, he presents his credential and enters the premises, and before entering the server corridor he needs a key to...

Digital fraud increased at Christmas

Digital fraud increased at Christmas

Colombia. During the holiday season, as e-commerce and digital transactions intensified, online fraud attempts also increased. Fake promotions, impersonation of businesses and messages that...

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Mexico. Milestone Systems, a leading provider of open platform video management software (VMS), hosted the Milestone XPerience Days Mexico 2025 event, a gathering that brought together industry...

Hikvision Mexico launches the third edition of

Hikvision Mexico launches the third edition of "Hikvision Women"

Mexico. Hikvision Mexico announced the launch of the third edition of its "Hikvision Women" program, an initiative aimed at strengthening the participation and professional development of women in...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter