OWASP adds unprotected APIs, insufficient attack protection to its 2017 release | Hacker News Reader