<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Api-Security on CuraSec</title><link>https://curasec.metacog.co.kr/tags/api-security/</link><description>Recent content in Api-Security on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 24 Aug 2026 13:10:29 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/api-security/index.xml" rel="self" type="application/rss+xml"/><item><title>Prefix-Cache Side Channel Exposes Hidden LLM API Reseller Dependencies</title><link>https://curasec.metacog.co.kr/insights/2026-08-24-uncovering-and-understanding-hidden-dependencies-in-the-llm/</link><pubDate>Mon, 24 Aug 2026 13:10:29 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-24-uncovering-and-understanding-hidden-dependencies-in-the-llm/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> CacheTracer demonstrates that LLM API reseller chains are often multi-layer and opaque — prompts may traverse undisclosed intermediaries who can inspect or alter them. No patch exists; the takeaway is to audit which LLM API endpoints you use and prefer direct provider access or contractually disclosed routing for sensitive workloads.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> This research surfaces a concrete vendor-risk gap: LLM API resellers may introduce undisclosed intermediaries with access to prompt and response content, creating confidentiality exposure. Add LLM API supply chain transparency (direct vs. reseller routing, data-handling attestations) to your AI vendor risk review criteria this quarter.&lt;/li>
&lt;/ul></description></item><item><title>TraceSurface: Frontend API Discovery &amp; Unauth Access Testing Tool</title><link>https://curasec.metacog.co.kr/insights/2026-08-13-pis10-tracesurface-53/</link><pubDate>Thu, 13 Aug 2026 11:57:16 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-13-pis10-tracesurface-53/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Learn:&lt;/strong> New open-source tool combining dynamic browser tracing with JS static analysis to surface hidden API endpoints and test for unauthorized access — worth evaluating in AppSec review workflows, but early-stage (53 stars) with no production signals yet.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;/ul></description></item><item><title>AI API Key Theft Fuels Gray-Market Token Resale Operations</title><link>https://curasec.metacog.co.kr/insights/2026-08-06-token-jacking-cybercriminals-could-be-stealing-your-ai-resou/</link><pubDate>Thu, 06 Aug 2026 13:03:19 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-06-token-jacking-cybercriminals-could-be-stealing-your-ai-resou/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> AI API keys (OpenAI, Anthropic, etc.) exposed in source code, CI/CD env vars, or container images are being harvested and resold; audit your repositories and secrets management for exposed AI provider keys and rotate any that touched public surfaces.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Learn:&lt;/strong> Unit 42 describes the gray-market resale pipeline for stolen AI tokens — useful for understanding attacker motivation when investigating anomalous AI API usage spikes, but no IOCs or TTPs provided in the summary to act on now.&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Emerging threat to AI development budgets and data exposure via stolen API credentials; worth noting for AI governance policy development, but no breach event or deadline requiring immediate action.&lt;/li>
&lt;/ul></description></item></channel></rss>