Issue 274: Authorization nightmares, API security case studies, 23andMe fined £2.3M, OAuth for Cloud Native APIs
Brief
This week, the theme is API authorization gone wrong. Guest contributor Rob Spectre kicks off a new interview series exploring real-world authorization failures. We also dive into case studies with key lessons for API security teams, including a look at the missteps that led to a £2. 3M fine for 23andMe, and data exposure from the Asana MCP.
Finally, we highlight a new resource on securing OAuth for cloud native APIs.
Case Study: True Nightmares of Authorization
By guest contributor Rob Spectre , DevRel at Oso.
It’s 5:45pm on a Friday. A small uptick in HTTP 400s and 500s pops up on an internal customer management tool. Within the hour, the entire engineering team at a hypergrowth startup scrambles to respond to a security intrusion – one that this technical leader will never forget.
