APIsec University’s cover photo
APIsec University

APIsec University

Computer and Network Security

San Francisco, CA 42,768 followers

APIsec University provides free API Security training. Learn how to find API vulnerabilities and keep them secure.

About us

Become an API Security Expert. APIs power virtually every mobile and web application, enable integrations across organizations, and drive more rapid innovation and development. APIs have also become the primary target for attackers, resulting in thousands of breaches and billions of records stolen. APIsec University exists to help develop the next generation of API Defenders. Get started today.

Website
www.apisecuniversity.com
Industry
Computer and Network Security
Company size
11-50 employees
Headquarters
San Francisco, CA
Type
Privately Held
Founded
2022
Specialties
api security, application security, and cybersecurity training

Locations

Employees at APIsec University

Updates

  • APIsec University reposted this

    This has been a question I've received numerous times after posting a blog about the ASCP certification from APIsec University/APIsec. The biggest question I get is, "How do I prepare for this certification? Any help?" Well, let's learn something together! Today, at 5:30 PM EST on the MRE Security YouTube Channel, I will be showcasing the ASCP, what to expect, and how to prepare for this difficult exam. Our example application will be VulnBank by Al-Amir Badmus. This is an intentionally vulnerable application that has a TON of API vulnerabilities to play with. The APISEC Certified Professional is one of the most challenging API certifications on the market. Created by Corey J. Ball, it makes you think outside the box and helps you understand how to read documentation. This is BY FAR one of the most interesting and realistic exams I've ever taken. Come hang out with me tonight at 5:30 PM EST and learn how to pass! Livestream Link is in the description. Have you taken the ASCP exam? Let me know your thoughts in the comments section. #cyber #apisec #pentesting #methodology

    • No alternative text description for this image
  • APIsec University reposted this

    Yesterday, I presented at APIsec University Bug Bounty Wednesday, covering how forgotten subdomains become potential attack vectors, and how exposed secrets like #API keys, tokens or #Cpanel credentials left in public repositories or misconfigured cloud assets quietly hand attackers the keys to entire infrastructures. Two major vulnerabilities that individually look basic, but in the wrong hands are dangerous to business operations. It was indeed a great session. The engagement was solid and the questions I got from the community were really incisive. Grateful to Dan Barahona, Jess Freeman and Affan Ali for the platform and the warm reception. More to come! #BugBounty #APISecurity #SubdomainTakeover #EthicalHacking #ThreatIntelligence #Cybersecurity

    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
  • APIsec University reposted this

    I wrote the CASA exam yesterday. After finishing the CyberSafe Foundation API program, I just wanted to see if what I learned actually stayed with me. So I took the exam. And I passed. I’m glad I did it. Not even just because I passed, but because of what it showed me. It’s one thing to go through a course. It’s another thing to sit down, think through questions, and realize you actually understand what’s going on. That part matters to me. Because that’s the real work. Still learning. Still exploring. Still trying to get better at API security one step at a time. (And yes… you can say congratulations 😊) 𝗧𝗛𝗜𝗦 𝗜𝗦𝗡’𝗧 𝗝𝗨𝗦𝗧 𝗖𝗢𝗡𝗧𝗘𝗡𝗧 𝗜𝗧’𝗦 𝗛𝗢𝗪 𝗜 𝗟𝗘𝗔𝗩𝗘 𝗣𝗥𝗢𝗢𝗙 𝗢𝗙 𝗧𝗥𝗨𝗦𝗧 𝗕𝗘𝗛𝗜𝗡𝗗 — 𝗚𝗟𝗢𝗥𝗬 𝗢𝗗𝗘𝗟𝗜

    • No alternative text description for this image
  • Most people learn bug bounty from theory. Very few get to see how real targets are approached — from recon to exploitation. This Wednesday, we’re hosting a live session with Rere Ayodele on: “Discovery & Exploitation of Vulnerabilities in Real Bounty Programs” You’ll see: - How attackers approach real targets (asset discovery → attack surface) - Where vulnerabilities like BOLA/IDOR, BFLA, exposed keys, and subdomain takeovers actually show up - A live walkthrough of an active finding from discovery to proof of concept This isn’t a slide-based session — it’s a real attacker workflow. If you’re getting into bug bounty or API security, this session is for you! 📅 Join us: April 22, 2026 at 12 PM ET 🔗 Event link: https//https://lnkd.in/gsbeHbbw Have you ever attended any of the Bugbounty Wednesday sessions before? Let us know your experience in the comments! #BugBounty #APISecurity #CyberSecurity #EthicalHacking #OWASP

    • No alternative text description for this image
  • APIsec University reposted this

    Yesterday, I had a conversation with Jess Freeman and Affan Ali from APIsec University/APIsec, and it reminded me of something. Our conversation consisted of posting on LinkedIn and breaking into the field. As many of you know, I’ve grown my LinkedIn by posting different concepts I’ve learned during my time as a penetration tester. But what makes a post good? How does it go “viral”? That’s when I thought, why don’t I share my methodology for branding and how you can begin growing your own personal brand. You see, the idea behind MRE Security is to give back as much as possible to the community. Not just through penetration testing, but also professional concepts that can eventually land you a job! So tonight, at 6:30 PM EST, I will be live streaming my journey into the field of cybersecurity, and how to grow a PERSONAL brand from the ground up. This isn’t just talking and you listening, this will be an INTERACTIVE session, where we dive into my methodology and thought process when building a brand. My story is unique and I’m excited to share it with you all tonight!! If you’re interested, make sure to join! Hope to see you all there! Livestream link is in the comments section. Have you started building your personal brand? If so, what have you done so far? Let me know in the comments! #cybersecurity #pentesting #personal #branding

  • APIsec University reposted this

    APIs power nearly every web and mobile application today, and they now account for more than 80% of internet traffic. They have also become one of the most attractive targets for attackers. We are excited to share our upcoming session on API Security tomorrow, where we have guest speaker Dan Barahona discuss why attackers love APIs, walk through real-world breaches and how they map to the OWASP API Security Top 10, and cover practical best practices organizations can use to reduce risk and prevent breaches. If your team builds, manages, or secures APIs, this will be a valuable conversation. #APISecurity #Cybersecurity #InfoSec #ApplicationSecurity #OWASP #CloudSecurity #SecurityAwareness #ISC2 #Houstonevents #Houstonnetworking

    • No alternative text description for this image
  • APIsec University reposted this

    Houston-based folks - I’m doing an API security workshop for the Houston ISC2 Chapter tomorrow. It’s virtual, so please join if you can. Nick Pawelczyk is building a great chapter and I recommend getting involved if you’re in the area.

    View organization page for Houston ISC2 Chapter

    815 followers

    APIs power nearly every web and mobile application today, and they now account for more than 80% of internet traffic. They have also become one of the most attractive targets for attackers. We are excited to share our upcoming session on API Security tomorrow, where we have guest speaker Dan Barahona discuss why attackers love APIs, walk through real-world breaches and how they map to the OWASP API Security Top 10, and cover practical best practices organizations can use to reduce risk and prevent breaches. If your team builds, manages, or secures APIs, this will be a valuable conversation. #APISecurity #Cybersecurity #InfoSec #ApplicationSecurity #OWASP #CloudSecurity #SecurityAwareness #ISC2 #Houstonevents #Houstonnetworking

    • No alternative text description for this image
  • APIsec University reposted this

    I joined a webinar hosted by the team behind APIsec BOLT, where they demonstrated how the tool can be used to discover and map API endpoints in modern web applications. During the session, they walked us through testing APIs using OpenVaultBank, a deliberately vulnerable app for API security training, showing how API traffic can be captured and structured automatically as you interact with an application. It was a great look into how quickly you can understand an application's API surface when the right tooling is in place. Right after the webinar, I decided to apply what I had just learned. I ran APIsec BOLT against VulnBank by Al-Amir Badmus, a deliberately vulnerable banking application designed for practicing application security testing of Web, APIs and LLMs, secure code review and implementing security in CI/CD pipelines. As I navigated through the application, the extension captured the API requests being made between the frontend and backend, helping reveal the endpoints, request methods, and parameters being used. Having this kind of visibility is extremely useful when performing API security testing because many vulnerabilities - such as Broken Object Level Authorization (BOLA/IDOR), authentication flaws, or excessive data exposure - often exist behind API endpoints that aren’t immediately obvious. It’s always valuable learning directly from the people building the tools and then immediately putting that knowledge into practice. Big thanks to Dan Barahona, Jesse Freeman for the insightful webinar today. #CyberSecurity #APISecurity #EthicalHacking #SecurityTesting #BugBounty #APIsecBOLT#APIsec.ai#APIsec University

    • No alternative text description for this image
    • No alternative text description for this image
  • APIsec University reposted this

    Yesterday we celebrated 5 years of Maltek Solutions, and I’m still processing it. 5 years feels like forever and no time at all simultaneously. I’ve learned more in this stretch than I could have anticipated, about security, about business, about people. Somehow the more I learn, the longer the list of things I still don’t know gets. What I do know is that none of this happens without an incredible team. Watching these people grow, problem-solve, and show up for our clients and community every single day has been the highlight of this whole ride. I’m grateful for every opportunity this journey has brought: the partnerships, the challenges that made us better, and the work that actually matters. I have to thank CenterState CEO for their ambassador committee presenting us with a 5 year certificate, the INSPYRE Innovation Hub by CenterState for allowing us to take over the space for a few hours, and everyone else that showed up to congratulate us, celebrate with us, and show us how important it is to support the local community in whatever ways you can. Year 6 and beyond? I’m genuinely excited. The best is still ahead.

    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
  • APIsec University reposted this

    I am pleased to share MRE Security is sponsoring the CTF@CIT competition happening April 17-19. We have created a few challenges for all of you and I’m excited to see how people solve them!! Come sign up and join!!

    View organization page for CTF@CIT

    318 followers

    🚩 We’re excited to officially kick off CTF@CIT 2026, the third annual CTF@CIT competition. This year’s event runs from April 17 to 19, 2026, and will feature challenges in forensics, OSINT, reverse engineering, cryptography, misc, and more, with additional challenges released throughout the weekend. We’re also excited to share that we currently have around $60,000 in prizes, with support from BINARY NINJA LLC/Vector 35, Electronic Frontier Foundation (EFF), OffSec, Hex-Rays, Hexordia, Trail of Bits, Microsoft, Caido, Altered Security, Zellic, The Tor Project, ANY.RUN, RET2 Systems, Inc., Epiq, MRE Security, IZT Cloud, Inc., and Digital Defenders Inc. We may still have more sponsors and prizes on the way, so stay tuned for updates. For anyone willing to commute in person, we’ll also be hosting an in-person networking event on April 18 with free food, swag, prizes, and space to work on the CTF with your team. We strongly encourage anyone planning to attend in person to fill out our interest form so we can share important updates if needed and get a rough headcount, though it will not be required to attend. Please help us spread the word by sharing this post and inviting your friends, teammates, and classmates. You can learn more and register at https://lnkd.in/eRx5X7Bq, view our CTFTime event at https://lnkd.in/eNq7bh7q, join our Discord at https://lnkd.in/eYhG83Mx, and fill out the in-person interest form. We’re looking forward to making this our biggest CTF@CIT yet. #CTF #Cybersecurity #CaptureTheFlag #InfoSec #ReverseEngineering #OSINT #DigitalForensics #StudentCybersecurity

Similar pages

Browse jobs