Testing and Hacking APIs INON SHKEDY
OWASP Global AppSec Tel Aviv https://telaviv.appsecglobal.org/ Most of the modern applications that have been developed in the last years deeply rely on APIs, including web, mobile and IOT apps. APIs are different than traditional web servers in many ways. This change might be confusing and challenging for pentesters and security researches. Come to learn how to leverage the new battleground to your advantage and: 1. Understand the underlying implementation of the application from the API traffic 2. Detect potential vulnerable points in APIs 3. Perform a successful and effective pen test in modern applications Inon Shkedy Head of Research, Salt Security The speaker has 7 years of experience in application security. He started his career in a red team in a government organization for 5 years, and then moved to the Silicon Valley to learn more about startups, modern applications and APIs. - Managed by the official OWASP Media Project https://www.owasp.org/index.php/OWASP...

API Hacking 101, w/ Dr. Katie Paxton-Fear | by Traceable AI

Attacking AI - Jason Haddix - NDC Security 2026

Trusted Types: End to end injection safety at scale KRZYSZTOF KOTOWICZ MIKE SAMUEL

Mateusz Olejarka - REST API, pentester's perspective

Hacking APIs: Fuzzing 101

Analyzing The OWASP API Security Top 10 For Pen Testers

Free API Hacking course!

The Nuts and Bolts of API Security: Protecting Your Data at All Times
![Nicholas Carlini - Black-hat LLMs | [un]prompted 2026](https://i.ytimg.com/vi/1sd26pWhfmg/hqdefault.jpg?sqp=-oaymwE9CNACELwBSFryq4qpAy8IARUAAAAAGAElAADIQj0AgKJDeAHwAQH4Af4JgALQBYoCDAgAEAEYciBmKDYwDw==&rs=AOn4CLBn1sRfbeYcMnkqD2mtRZhq1TO6JQ)
Nicholas Carlini - Black-hat LLMs | [un]prompted 2026

BOLA, IDOR, MA, BFLA. Welcome to the OWASP API Top 10!

How Hackers Actually Chain Tools Together (Nmap, Dirb, Wireshark)

HakByte: How to use Postman to Reverse Engineer Private APIs

Most Devs Get API Authentication Wrong ?

Finding Bugs in Mobile APIs

The Most Prevalent Code Flaws in API Development and How Hackers Exploit Them

5 Best Practices for Securing Your APIs

Hacking cell phones like Mr Robot

Hacking/Reverse Engineering a PRIVATE api

Hack JWT using JSON Web Tokens Attacker BurpSuite extensions

