Attackers are bypassing JWT authentication in WSO2 middleware that banks, telcos, and governments rely on to broker API traffic.