Top 10 API Bugs (and Where to Find Them)
In this video I go over the Top 10 API Bugs published by the OWASP API Security project. Although published for the blue team/security teams there's some great info for bug bounty hunters! So let's break it down, what are the bugs, where can we find them and how do we exploit them. Did you know this episode was sponsored by Intigriti? Sign up with my link http://go.intigriti.com/katie I'm so pleased with everyone's positive response to the Intigriti sponsorship and I'm so pleased you folks are finding bugs and even finding your first bugs! Thank you for being awesome! This episode is a companion to last week's video, hopefully you spend some time this week doing some recon, collecting some endpoints, now I'm going to show you how to exploit them :D! Also check out my demo where I show you these bugs in action, which is going to be live streamed later today! If you are watching this in the future, it'll be on my channel. Do you want to support me? Why not buy me a coffee? https://ko-fi.com/insiderphd Got questions? I have answers, Tweet at me / insiderphd Further Reading: OWASP API Top 10: https://owasp.org/www-project-api-sec... OWASP API Top 10 Explained: https://apisecurity.io/encyclopedia/c... Some possible misconfigurations: https://apisecurity.io/encyclopedia/c... Misconfiguration - CORS: https://blog.detectify.com/2018/04/26... Misconfiguration CSRF: • Finding Your First Bug: Cross-Site Request...

How to Take EFFECTIVE Bug Bounty Notes

New OWASP API Top 10 for Hackers

Why Your IDORs Get NA’d, Cookies Explained

Testing and Hacking APIs INON SHKEDY

Most Devs Get API Authentication Wrong ?

3 Real API Bugs I got a bounty for

Free Hacking API courses (And how to use AI to help you hack)

API Hacking 101, w/ Dr. Katie Paxton-Fear | by Traceable AI

OWASP Top 10 2025: Your complete guide to securing your applications

I Hacked This Temu Router. What I Found Should Be Illegal.

Zig 2026: No-AI Policy, $670K Foundation, Left GitHub & Why Zig Isn’t 1.0 - Andrew Kelley Explains

Finding Your First Bug: Finding Bugs Using APIs

Free API Hacking course!

OWASP Top 10 2021 - The List and How You Should Use It

Real Bugs - API Information Disclosure

World's Deadliest Computer Virus: WannaCry

How to Use Bug Bounty to Help Your Career!

Something is jamming GPS over Europe. Here's what we found

How to Disappear Online and Become Untraceable

