← Back to feed
Vulnerabilities & PatchesEmerging1 sourceJun 19, 2025 · 15:14via API Security News

Issue 274: Authorization nightmares, API security case studies, 23andMe fined £2.3M, OAuth for Cloud Native APIs

Brief

This week, the theme is API authorization gone wrong. Guest contributor Rob Spectre kicks off a new interview series exploring real-world authorization failures. We also dive into case studies with key lessons for API security teams, including a look at the missteps that led to a £2. 3M fine for 23andMe, and data exposure from the Asana MCP.

Finally, we highlight a new resource on securing OAuth for cloud native APIs.

Case Study: True Nightmares of Authorization

By guest contributor Rob Spectre , DevRel at Oso.

It’s 5:45pm on a Friday. A small uptick in HTTP 400s and 500s pops up on an internal customer management tool. Within the hour, the entire engineering team at a hypergrowth startup scrambles to respond to a security intrusion – one that this technical leader will never forget.

Read more on API Security News