Microsoft has fixed three vulnerabilities in its Azure API Management service , two of which enabled server-side request forgery (SSRF) attacks that could have allowed hackers to access internal Azure assets.
The exploits highlight the disadvantages of using blacklisting techniques as a defence against such attacks, say security researchers.
In fact, APIs are easy to interact with and are standardized, resulting in their widespread adoption but their development for production at a rapid pace has produced a corresponding increase in cyber attacks, with the number of SSRF attack attempts rising steadily in the past two years, according to one security firm.
















