api-security
Safeguard articles tagged "api-security" — guides, analysis, and best practices for software supply chain and application security.
100 articles
Your API Returns More Than Your Interface Shows
The interface filters. The API does not. Serialising a model directly makes your API contract your database schema, so a column added for an internal feature is exposed the moment it is added.
GraphQL Moved Your Authorisation Checks and Most Teams Left Them Behind
In REST an operation has one endpoint, so the check has one place to live. In a graph a field can be reached by many paths, and a check on the top-level query does not protect the same data reached as a nested field.
Five Ways a Webhook Receiver Goes Wrong
It is a public, unauthenticated endpoint that performs privileged actions on a JSON body from the internet. Everyone knows this, and most implementations still get one of five things wrong in ways that pass every test.
Your API Inventory Is Smaller Than Your API
The spec says one number, the gateway serves a larger one, and the difference is your unprotected surface: undecommissioned v1 routes, framework-generated handlers, and the debug endpoint added during an incident.
Permission Models Are Not Designed, They Accumulate
An is_admin boolean, then a role column, then a special case for one customer. Three years later nobody can say what a given user can do without reading the code, and an auditor is asking.
Four Silent Ways a Rate Limiter Permits Everything
A forgeable key, a per-instance counter, a fail-open catch block and a fixed window all produce a limiter that runs, logs, appears on the architecture diagram, and blocks nothing. None shows up in the usual test.
Your App Issues Two Kinds of Token and One Verifier Only Knows One
An SSO user carries your auth service's token, not your identity provider's. A verifier that accepts only the provider's tokens rejects exactly the users it was built for, and the symptom is a button that does nothing.
Writing an MCP Server That Holds No Credentials
Give a model a tool that writes and you have added a route into whatever sits behind it. The design that keeps it a new shape rather than a new privilege, and the four things that were not obvious.
A Read-Only API Key Was Enough to Overwrite Files on Cisco SD-WAN Manager
CVE-2026-20122, an additional Cisco Catalyst SD-WAN Manager finding beyond this series' earlier coverage, shows how a low-privilege API credential can still enable a file-write escalation.
Third-party risk assessment for insurtech SaaS platforms
A practical playbook for running an insurtech third-party risk assessment across vendors, APIs, and integrations before they touch policyholder data.
Your DAST Scanner Was Built to Crawl Links. Your Application Doesn't Have Any.
Classic DAST discovers attack surface by following hyperlinks. In an estate of APIs and serverless functions there is nothing to crawl, so the scan completes, reports clean, and covers little.
The Average Enterprise Runs 900 APIs. It Can List Maybe 600 of Them.
API attacks are climbing steeply and 87% of organisations reported an incident last year. The root cause is not weak authentication — it is that many production endpoints are on nobody's list.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.