Webinars Upcoming and previously recorded API security-related webinars.

Gain valuable insights and advice from 42Crunch and external API security industry experts. Webinar topics cover API security topics such as common API breaches, API defense techniques, OWASP API Security Top 10, 42Crunch products and tools...

Upcoming Webinars

New Webinars coming soon!

On Demand Webinars

Webinar Series - Defending APIs with Jim Manico

Defending APIs with Jim Manico – Episode 1

Episode 1: Request Forgery on the Web – CSRF & SSRF

November 10, 2022 | 9am PST | 5pm BST

Join Jim Manico, CEO of Manicode and Colin Domoney from 42Crunch, as they deliver a 2-part webinar series to help developers better defend APIs.

42C Webinar FI HackingAPIsforFun

Hacking APIs for Fun & Profit

Join Colin Domoney, Developer Advocate at 42Crunch in discussion with Adrian and Bogdan Tiron, Managing Partners at FORTBRIDGE as they discuss their careers as pen testers, and in particular their recent experiences in testing and exploiting API-based products.

API-Breaches-2022-small-scaled-1-1024x585

Review of the Major API Breaches from H1 2022 – Episode 2

This is a two-part webinar series on the global API breaches from H1 2022 that made the news. The first session described the breaches at a high level (recording below) and the second describes how to defend against them.

AdobeStock_480886232 1024x585px

Benefits of a Positive Security Model for APIs

Positive Security is a model that enables access to known trusted resources rather than trying to determine what activity or entities have hostile intent. Applying a positive security model when protecting your APIs can offer direct benefits such as reduction in false negatives, lower reliance on constantly adding characteristics of hostile traffic, and others. It also has indirect benefits for the working groups on your DevSecOps team that allow them to focus and be more efficient in their individual roles.

Rest-API-Risk-Audit-Online-Demo-July-2022-social

REST API Risk Audit – Online Demo

In this session, 42Crunch technical expert, Andy Wright, walks through how to perform a Security Audit and a Conformance Scan of your API Contract. He immediately builds a security report and calculates an audit score for each API he analyzes based on the OpenAPI annotations in the API definition. This audit score reflects the risk associated with exposing the APIs, internally and externally.

API-Breaches-2022-small-scaled-1-1024x585

Review of the Major API Breaches from H1 2022 – Episode 1

This is a two-part webinar series on the global API breaches from H1 2022 that made the news. The second part of this webinar series explores how to defend against common API security breaches covered in the first part of the series. Join Colin Domoney (42Crunch security researcher and curator of the APISecurity.io newsletter) to understand how to use defensive techniques to protect APIs. This practical and interactive webinar will illuminate how APIs can be protected against common attack types and real-world exploits.

42C Webinar Hero CircleProtect FI

Actively Monitor and Defend Your APIs with 42Crunch and the Azure Sentinel Platform

In this webinar 42Crunch and CyberProof demonstrate how to proactively integrate API access logs into the Microsoft Azure Sentinel platform and actively defend APIs with the 42runch API Micro-Firewall

Webinar Thumb Preview-1024x585px copy

API Security for Global Enterprises – Successful and unsuccessful approaches to API Security

Join 42Crunch and special guest speaker Darren Shelcusky, Manager of Vehicle & Connectivity Cybersecurity at Ford Motor Company, as he takes us through their approach to API security and journey to enforce security compliance while ensuring productivity of their hundreds of developers managing thousands of APIs.

42C Webinar Hero RunnerLegs FI

OWASP API Security TOP 10 Challenges – Episode 3

In this 3-part webinar series Dr. Philippe De Ryck, Web Security Expert with Pragmatic Web Security and Colin Domoney of 42Crunch and APISecurity.io, take a deep dive into understanding and addressing the OWASP API Security Top 10 issues. Through detailed practical examples and use cases, they guide developers and security professionals through how to fix and secure their APIs in the face of these identified threats.

42C Webinar Hero CitySunset FI

OWASP API Security Top 10: Comprendre les menaces qui ciblent les APIs

Ce webinaire, dédié à la sécurité des APIs, traite des menaces listées par l’OWASP API Security top 10. Vous assisterez à l’explication détaillée de chaque menace, son exploitation possible, des exemples d’attaques réussies et comment, grâce à la technologie 42crunch il est possible de s’en prémunir.

42C Webinar Hero API Phone FI

How to Extend Protection of your Data from API to Mobile Application

This webinar presents the new integration of 42Crunch with comprehensive mobile app protection from Approov. A joint solution that delivers shift-left API protection as well as run-time shielding that extends all the way to your mobile apps and the environments they run in.

42C Webinar Hero RunnerLegs FI

OWASP API Security TOP 10 Challenges – Episode 2

THREE-PART WEBINAR SERIES May 4th, 2022 | 8am PST | 4pm BST In this first episode in the webinar series, Dr Philippe de Ryck and Colin Domoney discuss API security today and the challenges presented by the OWASP API security top 10. Questions from attendees were addressed throughout the webinar. Episode 2: Address the OWASP …

OWASP API Security TOP 10 Challenges – Episode 2 Read More »

42C Webinar Hero RunnerLegs FI

OWASP API Security TOP 10 Challenges – Episode 1

In this first episode in the webinar series, Dr Philippe de Ryck and Colin Domoney discuss API security today and the challenges presented by the OWASP API security top 10. Questions from attendees were addressed throughout the webinar.

Webinar Thumb Preview-1024x585px copy

Automate your API security with Security as Code

Traditionally developers like to focus on the data and functionality of their APIs while the security team is concerned with the enforcement of API security controls and policies. This siloed approach has led to inefficiencies and bottlenecks in the DevSecOps’ cycle that are delaying the release of APIs and creating cost over runs.

Webinar Thumb Preview-1024x585px copy

Protección efectiva de sus APIs y Microservicios

Tus APIs están en riesgo, punto! Muchas organizaciones tienen la epifanía de que tener los componentes tradicionales como WAF y las capacidades tradicionales de los API Gateways son suficientes para que estén protegidas, pero no lo están.

Webinar Thumb Preview-1024x585px copy

Diseñando API seguras usando la plataforma 42Crunch con Postman

Diseñando APIs seguras usando la plataforma 42Crunch con Postman

Webinar Thumb Preview-1024x585px copy

Why Continuous API Security is key to protecting your Digital Business

Join these experts as they discuss the benefits of an integrated, continuous, and proactive approach to API security that combines proactive application security measures with continuous activity monitoring, API-specific threat analysis, and runtime policy enforcement.

Webinar Thumb Preview-1024x585px copy

Integrating 42Crunch API Contract Security Testing within Postman

Kin Lane, chief Evangelist with Postman recently joined Isabelle Mauny, Field CTO at 42Crunch for a webinar to demonstrate how enterprises are automating the testing of API security for all their APIs.

Webinar Thumb Preview-1024x585px copy

Dissecting the Biggest API Breaches from Q1 2021

API Security can be hard and confusing, but learning from someone else’s mistakes is the best way to learn!

Webinar Thumb Preview-1024x585px copy

API Security in a Kubernetes World

Securing APIs deployed in Kubernetes implies securing the infrastructure, but also the APIs themselves. Having a perfectly setup cluster, with all possible protections in place, is only ONE aspect of the measures you need to take to prevent the vulnerabilities listed in the OWASP API Security Top 10. Other issues such as data leakage, mass assignment or broken authentication must be handled at the application level.

Webinar Thumb Preview-1024x585px copy

How to Best Leverage JWTs for API Security

JSON Web tokens (JWTs) are used massively in API-based applications as access tokens or to transport information across services. Unfortunately, JWT standards are quite complex and it’s very easy to get the implementation wrong. As a result, data breaches and API vulnerabilities due to poor JWT implementation, token leakage, and lack of proper validation remain widespread.

Webinar Thumb Preview-1024x585px copy

OWASP API Security Top 10 Webinar Series (Part 2)

By now, you should know that APIs are special and deserve their own OWASP Top 10 list, but do you know how these common attacks happen and why?

Webinar Thumb Preview-1024x585px copy

OWASP API Security Top 10 Webinar Series (Part 1)

By now, you should know that APIs are special and deserve their own OWASP Top 10 list, but do you know how these common attacks happen and why?

Webinar Thumb Preview-1024x585px copy

OAuth, OWASP, Gateways and Meshes – Oh my!

To consider and apply API security effectively, we need to understand where we are and where we need to go. We need to know the tools we have available and who our allies are. Finally, we need a clear path and priorities on what we can accomplish and how. In this webinar, we’ll lay out a reference architecture to ensure we understand the scope, challenges, and approach to secure your APIs and organization as a whole.

Webinar Thumb Preview-1024x585px copy

OpenAPI for API Security (Why Guess when you know?)

According to the State of the APIs report released by Smartbear in 2019, 80% of developers use OpenAPI to describe their APIs (you may still call it Swagger, but you really should call it OpenAPI now!)

Webinar Thumb Preview-1024x585px copy

Let’s shift API Security Left! Sure, but how?

API security flaws are injected at many different levels of the API lifecycle: in requirements, development and deployment. It is proven that detecting and fixing vulnerabilities during production or post-release time is up to 30 times more difficult than earlier in the API lifecycle.

Webinar Thumb Preview-1024x585px copy

42Crunch Security Audit for WSO2 API Manager 3.1

WSO2 API Manager 3.1 brings a lot of interesting features including the ability to run 42Crunch’s audit tool directly from the API Publishing portal.

Webinar Thumb Preview-1024x585px copy

Top API Security Issues Found During POCs

Over the past 6 months, we have discovered many similarities across APIs from companies from very different industries. “This is an eye opener” is the most recurring comment from our prospects. We thought it would be worth sharing our findings in this webinar.

Webinar Thumb Preview-1024x585px copy

The Anatomy of API Breaches

Securing APIs implies securing the infrastructure but also the APIs themselves. Unfortunately, having all possible infrastructure protections in place is only one aspect of the recent OWASP Top10 for API Security. Other issues such as data leakage, mass assignment or broken authentication/authorization must be handled at the application level.

Webinar Thumb Preview-1024x585px copy

REST API Security for Microsoft Azure Pipelines

Security is an important topic in software development. Unfortunately, security is usually considered too late in software development, and especially in the API lifecycle. Waiting until software and APIs are in production before addressing security concerns can be a severe risk to your organization. Did you know that vulnerabilities found in production cost up to 30x time and money more to fix?

Webinar Thumb Preview-1024x585px copy

Protecting Microservices APIs with 42Crunch API Firewall

In loosely coupled architectures, we must put in place application level security, should it be for client traffic (North-South) or intra-microservices traffic (East-West).

Webinar Thumb Preview-1024x585px copy

Are You Properly Using JWTs?

JSON Web tokens (JWTs) are used massively in API-based applications as access tokens or to transport information across services. Unfortunately, JWT are often mis-used and incorrectly handled. Massive data breaches have occurred in the last 18 months due to token leakage and lack of proper of validation.

Webinar Thumb Preview-1024x585px copy

Positive API Security Model, and Why You Need It!

Many of the issues on the OWASP API Security Top 10 are triggered by the lack of input or output validation.

Webinar Thumb Preview-1024x585px copy

OWASP API Security Top 10

In recent years, large reputable companies such as Facebook, Google and Equifax have suffered major data breaches that combined exposed the personal information of hundreds of millions of people worldwide. The common vector linking these breaches – APIs. The scale and magnitude of these breaches are the reason API security has been launched into the forefront of enterprise security concerns – now forcing us to rethink the way we approach API security as a whole.

Ready to Learn More?

Developer-first solution for delivering API security as code.