<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Audit and intrusion tests Archives - KYOS</title>
	<atom:link href="https://www.kyos.ch/en/category/sec-en/sec_check-en/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.kyos.ch/en/category/sec-en/sec_check-en/</link>
	<description>Better safe than sorry</description>
	<lastBuildDate>Tue, 22 Oct 2024 14:18:45 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	

<image>
	<url>https://www.kyos.ch/wp-content/uploads/2021/04/cropped-Kyos_favicon_transparent-32x32.png</url>
	<title>Audit and intrusion tests Archives - KYOS</title>
	<link>https://www.kyos.ch/en/category/sec-en/sec_check-en/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>API in Danger: Underestimated Security Holes </title>
		<link>https://www.kyos.ch/en/in-the-news/api-in-danger/</link>
		
		<dc:creator><![CDATA[Etienne Maghakian]]></dc:creator>
		<pubDate>Tue, 22 Oct 2024 13:49:20 +0000</pubDate>
				<category><![CDATA[Audit and intrusion tests]]></category>
		<category><![CDATA[In the news]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://www.kyos.ch/?p=19944</guid>

					<description><![CDATA[<p>In recent years, API security has become a crucial issue for companies, with several significant leaks revealing the vulnerabilities of API integrations. For example, in June 2024, Authy (Twilio) suffered an attack resulting in the exfiltration of personal data of 33.4 million users [1]. This was caused by poor API authorization management, exposing phone numbers. [&#8230;]</p>
<p>The post <a href="https://www.kyos.ch/en/in-the-news/api-in-danger/">API in Danger: Underestimated Security Holes </a> appeared first on <a href="https://www.kyos.ch/en/">KYOS</a>.</p>
]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="19944" class="elementor elementor-19944" data-elementor-post-type="post">
						<section class="elementor-section elementor-top-section elementor-element elementor-element-292b490 elementor-section-full_width elementor-section-stretched elementor-section-height-default elementor-section-height-default" data-id="292b490" data-element_type="section" data-e-type="section" data-settings="{&quot;background_background&quot;:&quot;classic&quot;,&quot;stretch_section&quot;:&quot;section-stretched&quot;}">
							<div class="elementor-background-overlay"></div>
							<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-33 elementor-top-column elementor-element elementor-element-32582fd9  kyos-vertical-menu elementor-hidden-phone elementor-hidden-tablet" data-id="32582fd9" data-element_type="column" data-e-type="column">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-52caf52b kyos-fixed-item elementor-widget elementor-widget-template" data-id="52caf52b" data-element_type="widget" data-e-type="widget" data-widget_type="template.default">
				<div class="elementor-widget-container">
							<div class="elementor-template">
					<div data-elementor-type="section" data-elementor-id="8533" class="elementor elementor-8533" data-elementor-post-type="elementor_library">
					<section class="elementor-section elementor-top-section elementor-element elementor-element-a813e45 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="a813e45" data-element_type="section" data-e-type="section" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-d5af3eb" data-id="d5af3eb" data-element_type="column" data-e-type="column">
			<div class="elementor-widget-wrap elementor-element-populated">
						<section class="elementor-section elementor-inner-section elementor-element elementor-element-26058eb elementor-section-full_width elementor-section-height-default elementor-section-height-default" data-id="26058eb" data-element_type="section" data-e-type="section">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-33 elementor-inner-column elementor-element elementor-element-3e54c19" data-id="3e54c19" data-element_type="column" data-e-type="column">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-8cde3b2 kyos-fixed-item elementor-view-default elementor-widget elementor-widget-icon" data-id="8cde3b2" data-element_type="widget" data-e-type="widget" data-widget_type="icon.default">
				<div class="elementor-widget-container">
							<div class="elementor-icon-wrapper">
			<a class="elementor-icon" href="https://www.kyos.ch/kyos/">
			<svg xmlns="http://www.w3.org/2000/svg" width="19.432" height="44.834" viewBox="0 0 19.432 44.834"><path id="Trac&#xE9;_4373" data-name="Trac&#xE9; 4373" d="M7.771,22.432h0L19.432,0H11.687L0,22.432l11.687,22.4h7.745Z" fill="#2d2926"></path></svg>			</a>
		</div>
						</div>
				</div>
					</div>
		</div>
				<div class="elementor-column elementor-col-33 elementor-inner-column elementor-element elementor-element-48b921f" data-id="48b921f" data-element_type="column" data-e-type="column">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-390f19f kyos-fixed-item-black elementor-widget elementor-widget-text-editor" data-id="390f19f" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<a href="https://www.kyos.ch/kyos/" style="color:#2d2926">À propos</a>								</div>
				</div>
					</div>
		</div>
				<div class="elementor-column elementor-col-33 elementor-inner-column elementor-element elementor-element-6e00f63" data-id="6e00f63" data-element_type="column" data-e-type="column">
			<div class="elementor-widget-wrap">
							</div>
		</div>
					</div>
		</section>
				<div class="elementor-element elementor-element-d2a01b0 kyos-sidemenu-left-white uael-nav-menu__align-left uael-submenu-icon-arrow uael-link-redirect-child uael-nav-menu__breakpoint-tablet uael-nav-menu-toggle-label-no elementor-widget elementor-widget-uael-nav-menu" data-id="d2a01b0" data-element_type="widget" data-e-type="widget" data-settings="{&quot;sticky&quot;:&quot;top&quot;,&quot;_animation&quot;:&quot;none&quot;,&quot;sticky_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;,&quot;mobile&quot;],&quot;sticky_offset&quot;:0,&quot;sticky_effects_offset&quot;:0,&quot;sticky_anchor_link_offset&quot;:0}" data-widget_type="uael-nav-menu.default">
				<div class="elementor-widget-container">
							<div class="uael-nav-menu uael-layout-vertical uael-nav-menu-layout" data-layout="vertical">
				<div role="button" class="uael-nav-menu__toggle elementor-clickable">
					<span class="screen-reader-text">Main Menu</span>
					<div class="uael-nav-menu-icon">
						<i aria-hidden="true" class="fas fa-align-justify"></i>					</div>
									</div>
							<nav class="uael-nav-menu__layout-vertical uael-nav-menu__submenu-arrow" data-toggle-icon="&lt;i aria-hidden=&quot;true&quot; class=&quot;fas fa-align-justify&quot;&gt;&lt;/i&gt;" data-close-icon="&lt;i aria-hidden=&quot;true&quot; class=&quot;far fa-window-close&quot;&gt;&lt;/i&gt;" data-full-width="yes"><ul id="menu-1-d2a01b0" class="uael-nav-menu"><li id="menu-item-1599" class="menu-item menu-item-type-post_type menu-item-object-page parent uael-creative-menu"><a href="https://www.kyos.ch/en/kyos/approach/" class = "uael-menu-item">Approach</a></li>
<li id="menu-item-1588" class="menu-item menu-item-type-post_type menu-item-object-page parent uael-creative-menu"><a href="https://www.kyos.ch/en/kyos/our-team/" class = "uael-menu-item">Our Team</a></li>
<li id="menu-item-1589" class="menu-item menu-item-type-post_type menu-item-object-page parent uael-creative-menu"><a href="https://www.kyos.ch/en/kyos/ethics/" class = "uael-menu-item">Ethics</a></li>
<li id="menu-item-1602" class="menu-item menu-item-type-post_type menu-item-object-page parent uael-creative-menu"><a href="https://www.kyos.ch/en/kyos/partners/" class = "uael-menu-item">Partners</a></li>
<li id="menu-item-1603" class="menu-item menu-item-type-post_type menu-item-object-page parent uael-creative-menu"><a href="https://www.kyos.ch/en/kyos/references/" class = "uael-menu-item">References</a></li>
<li id="menu-item-1604" class="menu-item menu-item-type-post_type menu-item-object-page parent uael-creative-menu"><a href="https://www.kyos.ch/en/kyos/news/" class = "uael-menu-item">News</a></li>
<li id="menu-item-12447" class="menu-item menu-item-type-post_type menu-item-object-page parent uael-creative-menu"><a href="https://www.kyos.ch/en/kyos/join-us/" class = "uael-menu-item">Join us</a></li>
</ul></nav>
					</div>
							</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				</div>
				</div>
						</div>
				</div>
					</div>
		</div>
				<div class="elementor-column elementor-col-33 elementor-top-column elementor-element elementor-element-79c17d90" data-id="79c17d90" data-element_type="column" data-e-type="column">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-ecfb1a5 elementor-widget elementor-widget-heading" data-id="ecfb1a5" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h1 class="elementor-heading-title elementor-size-default">API in Danger: Underestimated Security Holes </h1>				</div>
				</div>
				<div class="elementor-element elementor-element-7d2d620d elementor-align-left elementor-widget elementor-widget-post-info" data-id="7d2d620d" data-element_type="widget" data-e-type="widget" data-widget_type="post-info.default">
				<div class="elementor-widget-container">
							<ul class="elementor-inline-items elementor-icon-list-items elementor-post-info">
								<li class="elementor-icon-list-item elementor-repeater-item-5934c6a elementor-inline-item" itemprop="datePublished">
						<a href="https://www.kyos.ch/en/2024/10/22/">
											<span class="elementor-icon-list-icon">
								<i aria-hidden="true" class="fas fa-calendar"></i>							</span>
									<span class="elementor-icon-list-text elementor-post-info__item elementor-post-info__item--type-date">
										<time>October 22, 2024</time>					</span>
									</a>
				</li>
				<li class="elementor-icon-list-item elementor-repeater-item-6d7e03c elementor-inline-item">
										<span class="elementor-icon-list-icon">
								<i aria-hidden="true" class="far fa-clock"></i>							</span>
									<span class="elementor-icon-list-text elementor-post-info__item elementor-post-info__item--type-time">
										<time>3:49 pm</time>					</span>
								</li>
				<li class="elementor-icon-list-item elementor-repeater-item-d6c49fb elementor-inline-item">
										<span class="elementor-icon-list-icon">
								<i aria-hidden="true" class="far fa-user-circle"></i>							</span>
									<span class="elementor-icon-list-text elementor-post-info__item elementor-post-info__item--type-custom">
										Security Team					</span>
								</li>
				</ul>
						</div>
				</div>
				<div class="elementor-element elementor-element-5de69116 elementor-widget elementor-widget-text-editor" data-id="5de69116" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><span data-contrast="auto">In recent years, API security has become a crucial issue for companies, with several significant leaks revealing the vulnerabilities of API integrations. For example, in June 2024, Authy (Twilio) suffered an attack resulting in the exfiltration of personal data of 33.4 million users <a href="https://x.com/DarkWebInformer/status/1806436700870287682" target="_blank" rel="noopener">[1]</a>. This was caused by poor API authorization management, exposing phone numbers. Another major breach hit Ivanti, where cyber attackers exploited an API authentication bypass flaw, allowing unauthorized access to endpoints and indirectly compromising 12 Norwegian ministries <a href="https://www.scworld.com/news/ivanti-bug-exploited-in-attack-on-norwegian-government" target="_blank" rel="noopener">[2]</a>.</span><span data-ccp-props="{}"> </span></p><p><span data-contrast="auto">These incidents are just the tip of the iceberg. They illustrate a growing trend of API attacks, which have exploded in recent years. Yet, many companies are unaware of the number of APIs they use. APIs are now ubiquitous, even on showcase sites with third-party extensions, making every interface a potential door for cybercriminals.</span><span data-ccp-props="{}"> </span></p>								</div>
				</div>
				<div class="elementor-element elementor-element-702fef49 elementor-widget elementor-widget-theme-post-featured-image elementor-widget-image" data-id="702fef49" data-element_type="widget" data-e-type="widget" data-widget_type="theme-post-featured-image.default">
				<div class="elementor-widget-container">
															<img fetchpriority="high" decoding="async" width="640" height="427" src="https://www.kyos.ch/wp-content/uploads/2024/10/KYOS_news_API_Pentest_web.jpg" class="attachment-full size-full wp-image-19932" alt="" srcset="https://www.kyos.ch/wp-content/uploads/2024/10/KYOS_news_API_Pentest_web.jpg 640w, https://www.kyos.ch/wp-content/uploads/2024/10/KYOS_news_API_Pentest_web-300x200.jpg 300w" sizes="(max-width: 640px) 100vw, 640px" />															</div>
				</div>
				<div class="elementor-element elementor-element-bdd00e9 elementor-widget elementor-widget-heading" data-id="bdd00e9" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">What is an API? </h2>				</div>
				</div>
				<div class="elementor-element elementor-element-93b4552 elementor-widget elementor-widget-text-editor" data-id="93b4552" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><span data-contrast="auto">An API (Application Programming Interface) is a set of rules and protocols that allow different applications to communicate with each other. The most commonly used APIs are REST, SOAP, and GraphQL. </span><span data-contrast="auto">Here are their main differences:</span><span data-ccp-props="{}"> </span></p><ul><li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="1" data-aria-level="1"><b><span data-contrast="auto">REST (Representational State Transfer):</span></b><span data-contrast="auto"> An architectural style using the HTTP protocol to interact with resources via URLs. It returns data in various formats (JSON, XML, etc.), with JSON being the most used for its lightness. REST is stateless, meaning each request must contain all the information needed for its processing.</span><span data-ccp-props="{}"> </span></li></ul><ul><li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="2" data-aria-level="1"><b><span data-contrast="auto">SOAP (Simple Object Access Protocol):</span></b><span data-contrast="auto"> A standard protocol for exchanging XML messages. It is more complex than REST but offers robust security standards (WS-Security). SOAP can operate in a stateless or stateful manner, allowing session management.</span><span data-ccp-props="{}"> </span></li></ul><ul><li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="3" data-aria-level="1"><b><span data-contrast="auto">GraphQL (Graph Query Language):</span></b><span data-contrast="auto"> Designed by Facebook, GraphQL allows clients to request exactly the data they need. Unlike REST, which relies on distinct resources, GraphQL uses a single endpoint to return the information specified by the client in JSON format.</span><span data-ccp-props="{}"> </span></li></ul><p><span data-contrast="auto">The choice of API type depends on the specific needs of the application. REST is often preferred for modern web applications, SOAP for environments requiring high security standards, and GraphQL for complex applications with precise data needs.</span><span data-ccp-props="{}"> </span></p>								</div>
				</div>
				<div class="elementor-element elementor-element-ed23bcd elementor-widget elementor-widget-heading" data-id="ed23bcd" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Securing APIs: A Top Priority </h2>				</div>
				</div>
				<div class="elementor-element elementor-element-6c0a8da elementor-widget elementor-widget-text-editor" data-id="6c0a8da" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><span data-contrast="auto">A single flaw can be very costly and permanently tarnish a company&#8217;s image, with significant financial and reputational consequences. One solution for organizations is to regularly conduct security audits and penetration tests on their APIs. These actions help detect and correct vulnerabilities before they are exploited by cybercriminals.</span><span data-ccp-props="{}"> </span></p><p><span data-contrast="auto">Recent examples of breaches clearly show why API security must be a priority for any company. Even showcase sites integrating third-party extensions can expose flaws.</span><span data-ccp-props="{}"> </span></p><p><span data-contrast="auto">API-targeted attacks are becoming increasingly sophisticated and frequent. Protecting these interfaces is therefore essential to ensure the security of your data and the continuity of your operations. Don&#8217;t let a flaw jeopardize your business.</span><span data-ccp-props="{}"> </span></p>								</div>
				</div>
				<div class="elementor-element elementor-element-0532638 elementor-widget elementor-widget-heading" data-id="0532638" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h2 class="elementor-heading-title elementor-size-default">Protect your web applications today! </h2>				</div>
				</div>
				<div class="elementor-element elementor-element-d636106 elementor-widget elementor-widget-text-editor" data-id="d636106" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><span data-contrast="auto">An undetected security flaw can compromise the security of your web applications and damage the trust of your customers. At KYOS, we offer comprehensive penetration testing of your interfaces, including REST APIs and web applications, to identify and correct critical vulnerabilities.</span><span data-ccp-props="{}"> </span></p><p><span data-contrast="auto">Our Pentest Web Essential offer includes:</span><span data-ccp-props="{}"> </span></p><ul><li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="4" data-aria-level="1"><span data-contrast="auto">A kick-off meeting</span><span data-ccp-props="{}"> </span></li></ul><ul><li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="5" data-aria-level="1"><span data-contrast="auto">Definition of prerequisites</span><span data-ccp-props="{}"> </span></li></ul><ul><li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="6" data-aria-level="1"><span data-contrast="auto">Analysis of 20 endpoints (web pages or API functions)</span><span data-ccp-props="{}"> </span></li></ul><ul><li data-leveltext="" data-font="Symbol" data-listid="1" data-list-defn-props="{&quot;335552541&quot;:1,&quot;335559685&quot;:720,&quot;335559991&quot;:360,&quot;469769226&quot;:&quot;Symbol&quot;,&quot;469769242&quot;:[8226],&quot;469777803&quot;:&quot;left&quot;,&quot;469777804&quot;:&quot;&quot;,&quot;469777815&quot;:&quot;multilevel&quot;}" aria-setsize="-1" data-aria-posinset="7" data-aria-level="1"><span data-contrast="auto">Full report with findings and recommendations</span><span data-ccp-props="{}"> </span></li></ul><p><span data-contrast="auto">Additional options are available, such as analysis of a further 20 endpoints or a review session of the results.</span><span data-ccp-props="{}"> </span></p><p><a href="https://www.kyos.ch/wp-admin/post.php?post=19944&amp;action=elementor#kyos-footer-bloc" target="_blank" rel="noopener"><b><span data-contrast="auto">Contact us today</span></b></a><span data-contrast="auto"> to secure your applications and guarantee your customers&#8217; trust!</span><span data-ccp-props="{}"> </span></p>								</div>
				</div>
				<div class="elementor-element elementor-element-58ba0d0 elementor-share-buttons--view-icon elementor-share-buttons--shape-circle elementor-share-buttons--color-custom elementor-share-buttons--skin-gradient elementor-grid-0 elementor-widget elementor-widget-share-buttons" data-id="58ba0d0" data-element_type="widget" data-e-type="widget" data-widget_type="share-buttons.default">
				<div class="elementor-widget-container">
							<div class="elementor-grid" role="list">
								<div class="elementor-grid-item" role="listitem">
						<div class="elementor-share-btn elementor-share-btn_facebook" role="button" tabindex="0" aria-label="Share on facebook">
															<span class="elementor-share-btn__icon">
								<i class="fab fa-facebook" aria-hidden="true"></i>							</span>
																				</div>
					</div>
									<div class="elementor-grid-item" role="listitem">
						<div class="elementor-share-btn elementor-share-btn_twitter" role="button" tabindex="0" aria-label="Share on twitter">
															<span class="elementor-share-btn__icon">
								<i class="fab fa-twitter" aria-hidden="true"></i>							</span>
																				</div>
					</div>
									<div class="elementor-grid-item" role="listitem">
						<div class="elementor-share-btn elementor-share-btn_linkedin" role="button" tabindex="0" aria-label="Share on linkedin">
															<span class="elementor-share-btn__icon">
								<i class="fab fa-linkedin" aria-hidden="true"></i>							</span>
																				</div>
					</div>
						</div>
						</div>
				</div>
					</div>
		</div>
				<div class="elementor-column elementor-col-33 elementor-top-column elementor-element elementor-element-2ea61615 elementor-hidden-tablet elementor-hidden-phone" data-id="2ea61615" data-element_type="column" data-e-type="column">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-56b93158 kyos-fixed-item elementor-widget elementor-widget-template" data-id="56b93158" data-element_type="widget" data-e-type="widget" data-widget_type="template.default">
				<div class="elementor-widget-container">
							<div class="elementor-template">
					<div data-elementor-type="section" data-elementor-id="8782" class="elementor elementor-8782" data-elementor-post-type="elementor_library">
					<section class="elementor-section elementor-top-section elementor-element elementor-element-e7758e7 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="e7758e7" data-element_type="section" data-e-type="section" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2b28947" data-id="2b28947" data-element_type="column" data-e-type="column">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-69ae174 elementor-widget elementor-widget-text-editor" data-id="69ae174" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>More information on this subject?</p><p>We are at your disposal!</p>								</div>
				</div>
				<div class="elementor-element elementor-element-991947b elementor-widget elementor-widget-button" data-id="991947b" data-element_type="widget" data-e-type="widget" data-widget_type="button.default">
				<div class="elementor-widget-container">
									<div class="elementor-button-wrapper">
					<a class="elementor-button elementor-button-link elementor-size-sm" href="#kyos-footer-bloc">
						<span class="elementor-button-content-wrapper">
									<span class="elementor-button-text">Contact us</span>
					</span>
					</a>
				</div>
								</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				</div>
				</div>
						</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				</div>
		<p>The post <a href="https://www.kyos.ch/en/in-the-news/api-in-danger/">API in Danger: Underestimated Security Holes </a> appeared first on <a href="https://www.kyos.ch/en/">KYOS</a>.</p>
]]></content:encoded>
					
		
		
			</item>
		<item>
		<title>We successfully renewed our Crest Membership</title>
		<link>https://www.kyos.ch/en/sec-en/sec_check-en/we-successfully-renewed-our-crest-membership/</link>
					<comments>https://www.kyos.ch/en/sec-en/sec_check-en/we-successfully-renewed-our-crest-membership/#respond</comments>
		
		<dc:creator><![CDATA[Etienne Maghakian]]></dc:creator>
		<pubDate>Mon, 18 Oct 2021 11:52:11 +0000</pubDate>
				<category><![CDATA[Audit and intrusion tests]]></category>
		<category><![CDATA[Security]]></category>
		<guid isPermaLink="false">https://www.kyos.ch/?p=13748</guid>

					<description><![CDATA[<p>Kyos team is proud to announce that we successfully renewed our Crest Membership. This accreditation allows our clients to get CREST Certified penetration testings directly from Kyos. This standard ensures clients that they can get high-quality services from Kyos and entrusted professional ethical hackers. ‘CREST is pleased to welcome Kyos as an accredited member company’, [&#8230;]</p>
<p>The post <a href="https://www.kyos.ch/en/sec-en/sec_check-en/we-successfully-renewed-our-crest-membership/">We successfully renewed our Crest Membership</a> appeared first on <a href="https://www.kyos.ch/en/">KYOS</a>.</p>
]]></description>
										<content:encoded><![CDATA[		<div data-elementor-type="wp-post" data-elementor-id="13748" class="elementor elementor-13748" data-elementor-post-type="post">
						<section class="elementor-section elementor-top-section elementor-element elementor-element-4d143694 elementor-section-full_width elementor-section-stretched elementor-section-height-default elementor-section-height-default" data-id="4d143694" data-element_type="section" data-e-type="section" data-settings="{&quot;background_background&quot;:&quot;classic&quot;,&quot;stretch_section&quot;:&quot;section-stretched&quot;}">
							<div class="elementor-background-overlay"></div>
							<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-33 elementor-top-column elementor-element elementor-element-35e62ca1  kyos-vertical-menu elementor-hidden-phone" data-id="35e62ca1" data-element_type="column" data-e-type="column">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-2fd0a87a kyos-fixed-item elementor-widget elementor-widget-template" data-id="2fd0a87a" data-element_type="widget" data-e-type="widget" data-widget_type="template.default">
				<div class="elementor-widget-container">
							<div class="elementor-template">
					<div data-elementor-type="section" data-elementor-id="8783" class="elementor elementor-8783" data-elementor-post-type="elementor_library">
					<section class="elementor-section elementor-top-section elementor-element elementor-element-a813e45 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="a813e45" data-element_type="section" data-e-type="section" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-d5af3eb" data-id="d5af3eb" data-element_type="column" data-e-type="column">
			<div class="elementor-widget-wrap elementor-element-populated">
						<section class="elementor-section elementor-inner-section elementor-element elementor-element-26058eb elementor-section-full_width elementor-section-height-default elementor-section-height-default" data-id="26058eb" data-element_type="section" data-e-type="section">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-33 elementor-inner-column elementor-element elementor-element-3e54c19" data-id="3e54c19" data-element_type="column" data-e-type="column">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-8cde3b2 kyos-fixed-item elementor-view-default elementor-widget elementor-widget-icon" data-id="8cde3b2" data-element_type="widget" data-e-type="widget" data-widget_type="icon.default">
				<div class="elementor-widget-container">
							<div class="elementor-icon-wrapper">
			<a class="elementor-icon" href="https://www.kyos.ch/kyos/">
			<svg xmlns="http://www.w3.org/2000/svg" width="19.432" height="44.834" viewBox="0 0 19.432 44.834"><path id="Trac&#xE9;_4373" data-name="Trac&#xE9; 4373" d="M7.771,22.432h0L19.432,0H11.687L0,22.432l11.687,22.4h7.745Z" fill="#2d2926"></path></svg>			</a>
		</div>
						</div>
				</div>
					</div>
		</div>
				<div class="elementor-column elementor-col-33 elementor-inner-column elementor-element elementor-element-48b921f" data-id="48b921f" data-element_type="column" data-e-type="column">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-390f19f kyos-fixed-item-black elementor-widget elementor-widget-text-editor" data-id="390f19f" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p><a style="color: #2d2926!important;" href="/en/kyos/">About</a></p>								</div>
				</div>
					</div>
		</div>
				<div class="elementor-column elementor-col-33 elementor-inner-column elementor-element elementor-element-6e00f63" data-id="6e00f63" data-element_type="column" data-e-type="column">
			<div class="elementor-widget-wrap">
							</div>
		</div>
					</div>
		</section>
				<div class="elementor-element elementor-element-d2a01b0 kyos-sidemenu-left-white uael-nav-menu__align-left uael-submenu-icon-arrow uael-link-redirect-child uael-nav-menu__breakpoint-tablet uael-nav-menu-toggle-label-no elementor-widget elementor-widget-uael-nav-menu" data-id="d2a01b0" data-element_type="widget" data-e-type="widget" data-settings="{&quot;sticky&quot;:&quot;top&quot;,&quot;_animation&quot;:&quot;none&quot;,&quot;sticky_on&quot;:[&quot;desktop&quot;,&quot;tablet&quot;,&quot;mobile&quot;],&quot;sticky_offset&quot;:0,&quot;sticky_effects_offset&quot;:0,&quot;sticky_anchor_link_offset&quot;:0}" data-widget_type="uael-nav-menu.default">
				<div class="elementor-widget-container">
							<div class="uael-nav-menu uael-layout-vertical uael-nav-menu-layout" data-layout="vertical">
				<div role="button" class="uael-nav-menu__toggle elementor-clickable">
					<span class="screen-reader-text">Main Menu</span>
					<div class="uael-nav-menu-icon">
						<i aria-hidden="true" class="fas fa-align-justify"></i>					</div>
									</div>
							<nav class="uael-nav-menu__layout-vertical uael-nav-menu__submenu-arrow" data-toggle-icon="&lt;i aria-hidden=&quot;true&quot; class=&quot;fas fa-align-justify&quot;&gt;&lt;/i&gt;" data-close-icon="&lt;i aria-hidden=&quot;true&quot; class=&quot;far fa-window-close&quot;&gt;&lt;/i&gt;" data-full-width="yes"><ul id="menu-1-d2a01b0" class="uael-nav-menu"><li id="menu-item-1599" class="menu-item menu-item-type-post_type menu-item-object-page parent uael-creative-menu"><a href="https://www.kyos.ch/en/kyos/approach/" class = "uael-menu-item">Approach</a></li>
<li id="menu-item-1588" class="menu-item menu-item-type-post_type menu-item-object-page parent uael-creative-menu"><a href="https://www.kyos.ch/en/kyos/our-team/" class = "uael-menu-item">Our Team</a></li>
<li id="menu-item-1589" class="menu-item menu-item-type-post_type menu-item-object-page parent uael-creative-menu"><a href="https://www.kyos.ch/en/kyos/ethics/" class = "uael-menu-item">Ethics</a></li>
<li id="menu-item-1602" class="menu-item menu-item-type-post_type menu-item-object-page parent uael-creative-menu"><a href="https://www.kyos.ch/en/kyos/partners/" class = "uael-menu-item">Partners</a></li>
<li id="menu-item-1603" class="menu-item menu-item-type-post_type menu-item-object-page parent uael-creative-menu"><a href="https://www.kyos.ch/en/kyos/references/" class = "uael-menu-item">References</a></li>
<li id="menu-item-1604" class="menu-item menu-item-type-post_type menu-item-object-page parent uael-creative-menu"><a href="https://www.kyos.ch/en/kyos/news/" class = "uael-menu-item">News</a></li>
<li id="menu-item-12447" class="menu-item menu-item-type-post_type menu-item-object-page parent uael-creative-menu"><a href="https://www.kyos.ch/en/kyos/join-us/" class = "uael-menu-item">Join us</a></li>
</ul></nav>
					</div>
							</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				</div>
				</div>
						</div>
				</div>
					</div>
		</div>
				<div class="elementor-column elementor-col-33 elementor-top-column elementor-element elementor-element-223a68e8" data-id="223a68e8" data-element_type="column" data-e-type="column">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-6e2f307e elementor-widget elementor-widget-heading" data-id="6e2f307e" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h1 class="elementor-heading-title elementor-size-default">We successfully renewed our Crest Membership</h1>				</div>
				</div>
				<div class="elementor-element elementor-element-3f8620a2 elementor-align-left elementor-widget elementor-widget-post-info" data-id="3f8620a2" data-element_type="widget" data-e-type="widget" data-widget_type="post-info.default">
				<div class="elementor-widget-container">
							<ul class="elementor-inline-items elementor-icon-list-items elementor-post-info">
								<li class="elementor-icon-list-item elementor-repeater-item-5934c6a elementor-inline-item" itemprop="datePublished">
						<a href="https://www.kyos.ch/en/2021/10/18/">
											<span class="elementor-icon-list-icon">
								<i aria-hidden="true" class="fas fa-calendar"></i>							</span>
									<span class="elementor-icon-list-text elementor-post-info__item elementor-post-info__item--type-date">
										<time>October 18, 2021</time>					</span>
									</a>
				</li>
				<li class="elementor-icon-list-item elementor-repeater-item-6d7e03c elementor-inline-item">
										<span class="elementor-icon-list-icon">
								<i aria-hidden="true" class="far fa-clock"></i>							</span>
									<span class="elementor-icon-list-text elementor-post-info__item elementor-post-info__item--type-time">
										<time>1:52 pm</time>					</span>
								</li>
				<li class="elementor-icon-list-item elementor-repeater-item-d6c49fb elementor-inline-item" itemprop="author">
						<a href="https://www.kyos.ch/en/author/etienne-maghakian/">
											<span class="elementor-icon-list-icon">
								<i aria-hidden="true" class="far fa-user-circle"></i>							</span>
									<span class="elementor-icon-list-text elementor-post-info__item elementor-post-info__item--type-author">
										Etienne Maghakian					</span>
									</a>
				</li>
				</ul>
						</div>
				</div>
				<div class="elementor-element elementor-element-10b739eb elementor-widget elementor-widget-text-editor" data-id="10b739eb" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>Kyos team is proud to announce that we successfully renewed our Crest Membership. This accreditation allows our clients to get CREST Certified penetration testings directly from Kyos. This standard ensures clients that they can get high-quality services from Kyos and entrusted professional ethical hackers.</p><p>‘CREST is pleased to welcome Kyos as an accredited member company’, said Ian Glover a year ago, president of CREST, ‘Kyos has been through a demanding assessment process that examined test methodologies, legal and regulatory requirements, data protection standards, logging and auditing, internal and external communications with stakeholders, as well as how test data security is maintained. Awarding Kyos membership for its penetration testing services means that we are formally recognizing that the company consistently delivers the highest professional security services standards to its customers’.</p>								</div>
				</div>
				<div class="elementor-element elementor-element-9f91387 elementor-widget elementor-widget-image" data-id="9f91387" data-element_type="widget" data-e-type="widget" data-widget_type="image.default">
				<div class="elementor-widget-container">
																<a href="https://service-selection-platform.crest-approved.org/member_companies/kyos-sa/" target="_blank">
							<img decoding="async" width="300" height="140" src="https://www.kyos.ch/wp-content/uploads/2021/10/crest_pentest-300x140.jpg" class="attachment-medium size-medium wp-image-13756" alt="" srcset="https://www.kyos.ch/wp-content/uploads/2021/10/crest_pentest-300x140.jpg 300w, https://www.kyos.ch/wp-content/uploads/2021/10/crest_pentest.jpg 450w" sizes="(max-width: 300px) 100vw, 300px" />								</a>
															</div>
				</div>
				<div class="elementor-element elementor-element-261317b elementor-widget elementor-widget-text-editor" data-id="261317b" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>In fact, CREST provides clients with a clear indication of the quality of the organization and the technical capability of staff they have access to, including:</p>								</div>
				</div>
				<div class="elementor-element elementor-element-4749868 elementor-icon-list--layout-traditional elementor-list-item-link-full_width elementor-widget elementor-widget-icon-list" data-id="4749868" data-element_type="widget" data-e-type="widget" data-widget_type="icon-list.default">
				<div class="elementor-widget-container">
							<ul class="elementor-icon-list-items">
							<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<svg xmlns="http://www.w3.org/2000/svg" width="5.216" height="12.035" viewBox="0 0 5.216 12.035"><path id="Trac&#xE9;_4048" data-name="Trac&#xE9; 4048" d="M2.086,6.022h0L5.216,0H3.137L0,6.022l3.137,6.013H5.216Z" transform="translate(5.216 12.035) rotate(180)" fill="#541dff"></path></svg>						</span>
										<span class="elementor-icon-list-text">Access to trusted service organizations utilizing highly skilled, knowledgeable and competent individuals</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<svg xmlns="http://www.w3.org/2000/svg" width="5.216" height="12.035" viewBox="0 0 5.216 12.035"><path id="Trac&#xE9;_4048" data-name="Trac&#xE9; 4048" d="M2.086,6.022h0L5.216,0H3.137L0,6.022l3.137,6.013H5.216Z" transform="translate(5.216 12.035) rotate(180)" fill="#541dff"></path></svg>						</span>
										<span class="elementor-icon-list-text">Procurement support</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<svg xmlns="http://www.w3.org/2000/svg" width="5.216" height="12.035" viewBox="0 0 5.216 12.035"><path id="Trac&#xE9;_4048" data-name="Trac&#xE9; 4048" d="M2.086,6.022h0L5.216,0H3.137L0,6.022l3.137,6.013H5.216Z" transform="translate(5.216 12.035) rotate(180)" fill="#541dff"></path></svg>						</span>
										<span class="elementor-icon-list-text">Industry benchmarks</span>
									</li>
								<li class="elementor-icon-list-item">
											<span class="elementor-icon-list-icon">
							<svg xmlns="http://www.w3.org/2000/svg" width="5.216" height="12.035" viewBox="0 0 5.216 12.035"><path id="Trac&#xE9;_4048" data-name="Trac&#xE9; 4048" d="M2.086,6.022h0L5.216,0H3.137L0,6.022l3.137,6.013H5.216Z" transform="translate(5.216 12.035) rotate(180)" fill="#541dff"></path></svg>						</span>
										<span class="elementor-icon-list-text">Rigorous application process for added assurance</span>
									</li>
						</ul>
						</div>
				</div>
				<div class="elementor-element elementor-element-42c6d69 elementor-widget elementor-widget-text-editor" data-id="42c6d69" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>In order to become certified, Kyos has submitted policies, processes and procedures relating to our service provision to CREST providing added assurance for our clients. These policies, processes and procedures have been assessed by CREST and have been deemed fit for purpose and include:</p><ul><li>Certified individuals</li><li>Language capability</li><li>Assignment preparation &amp; scope</li><li>Assignment execution</li><li>Technical Methodology</li><li>Tools &amp; resources</li><li>Event analysis &amp; response</li><li>Data Storage and Transmission Controls</li><li>Information sharing</li><li>Reporting</li><li>Deliverables</li><li>Post technical delivery</li><li>Asset/Information/Document Storage, Retention and Destruction</li></ul>								</div>
				</div>
				<div class="elementor-element elementor-element-deeeb35 elementor-widget elementor-widget-heading" data-id="deeeb35" data-element_type="widget" data-e-type="widget" data-widget_type="heading.default">
				<div class="elementor-widget-container">
					<h4 class="elementor-heading-title elementor-size-default">About CREST</h4>				</div>
				</div>
				<div class="elementor-element elementor-element-421585a elementor-widget elementor-widget-text-editor" data-id="421585a" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>CREST is a not-for-profit accreditation and certification body representing the technical information security industry. CREST provides internationally recognized accreditations for organizations providing technical security services and professional level certifications for individuals providing vulnerability assessment, penetration testing, cyber incident response, threat intelligence and security operations center (SOC) services. CREST Member companies undergo regular and stringent assessment, whilst CREST certified individuals undertake rigorous examinations to demonstrate the highest levels of knowledge, skill and competence. To ensure currency of knowledge in fast-changing technical security environments, the certification process is repeated every three years.</p>								</div>
				</div>
					</div>
		</div>
				<div class="elementor-column elementor-col-33 elementor-top-column elementor-element elementor-element-6e6cf008" data-id="6e6cf008" data-element_type="column" data-e-type="column">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-3d25af6e kyos-fixed-item elementor-widget elementor-widget-template" data-id="3d25af6e" data-element_type="widget" data-e-type="widget" data-widget_type="template.default">
				<div class="elementor-widget-container">
							<div class="elementor-template">
					<div data-elementor-type="section" data-elementor-id="8782" class="elementor elementor-8782" data-elementor-post-type="elementor_library">
					<section class="elementor-section elementor-top-section elementor-element elementor-element-e7758e7 elementor-section-boxed elementor-section-height-default elementor-section-height-default" data-id="e7758e7" data-element_type="section" data-e-type="section" data-settings="{&quot;background_background&quot;:&quot;classic&quot;}">
						<div class="elementor-container elementor-column-gap-default">
					<div class="elementor-column elementor-col-100 elementor-top-column elementor-element elementor-element-2b28947" data-id="2b28947" data-element_type="column" data-e-type="column">
			<div class="elementor-widget-wrap elementor-element-populated">
						<div class="elementor-element elementor-element-69ae174 elementor-widget elementor-widget-text-editor" data-id="69ae174" data-element_type="widget" data-e-type="widget" data-widget_type="text-editor.default">
				<div class="elementor-widget-container">
									<p>More information on this subject?</p><p>We are at your disposal!</p>								</div>
				</div>
				<div class="elementor-element elementor-element-991947b elementor-widget elementor-widget-button" data-id="991947b" data-element_type="widget" data-e-type="widget" data-widget_type="button.default">
				<div class="elementor-widget-container">
									<div class="elementor-button-wrapper">
					<a class="elementor-button elementor-button-link elementor-size-sm" href="#kyos-footer-bloc">
						<span class="elementor-button-content-wrapper">
									<span class="elementor-button-text">Contact us</span>
					</span>
					</a>
				</div>
								</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				</div>
				</div>
						</div>
				</div>
					</div>
		</div>
					</div>
		</section>
				</div>
		<p>The post <a href="https://www.kyos.ch/en/sec-en/sec_check-en/we-successfully-renewed-our-crest-membership/">We successfully renewed our Crest Membership</a> appeared first on <a href="https://www.kyos.ch/en/">KYOS</a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://www.kyos.ch/en/sec-en/sec_check-en/we-successfully-renewed-our-crest-membership/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
