Unknown & Shadow APIs
Uncatalogued endpoints or forgotten versions
Outside gateway policies and specs
Unmanaged exposure → breaches, downtime and audit pain
Business-Logic Abuse
Valid-looking requests abusing role/object access
Signature-based tools lack user-object context
Account/data overreach, material incidents, brand damage
Sensitive Data Leakage
Fields drift into responses and logs
Chatty microservices; schema vs. runtime mismatch
Regulatory fines, legal cost, customer distrust
API Drift & Contract Mismatch
Undocumented params/methods after fast ships
Specs lag code; reviews miss runtime
Breaking clients, outages, compliance gaps
Automated Abuse & Fraud
Credential stuffing, scraping, carding
IP/rate rules are blunt; bots adapt
Revenue leakage, SLO hits, inflated ops spend
Over-Privileged Access
Weak scoping across tenants/roles/objects
Static authZ checks lack entity context
Excess data exposure, lateral movement, insider risk
Operational Drag & Noise
Alerts without payload/identity context
Generic logs; low-fidelity signals.
High MTTR, burned engineering cycles, missed real threats
Third-Party & Partner API Risk
Dependents and egress paths you still own
Limited visibility beyond your perimeter
Downstream outages, data handling violations, blame