Community Short Facts - June 2022


Critical API security vulnerability
Salt Security published the new API vulnerability report from Salt Labs, in which a server-side request forgery (SSRF) flaw was discovered in the digital platform of a US fintech company. The fintech platform offers a wide range of digital banking services to hundreds of banks and millions of customers. The API vulnerability enables the administrative takeover of accounts (account takeover, ATO). Malicious actors could have used the vulnerability to launch attacks and gain administrative access to the banking system.