Safeguard
Tag

api-security

Safeguard articles tagged "api-security" — guides, analysis, and best practices for software supply chain and application security.

100 articles

Application Security

Your API Returns More Than Your Interface Shows

The interface filters. The API does not. Serialising a model directly makes your API contract your database schema, so a column added for an internal feature is exposed the moment it is added.

Sep 18, 20265 min read
Application Security

GraphQL Moved Your Authorisation Checks and Most Teams Left Them Behind

In REST an operation has one endpoint, so the check has one place to live. In a graph a field can be reached by many paths, and a check on the top-level query does not protect the same data reached as a nested field.

Sep 18, 20265 min read
Application Security

Five Ways a Webhook Receiver Goes Wrong

It is a public, unauthenticated endpoint that performs privileged actions on a JSON body from the internet. Everyone knows this, and most implementations still get one of five things wrong in ways that pass every test.

Sep 18, 20265 min read
Application Security

Your API Inventory Is Smaller Than Your API

The spec says one number, the gateway serves a larger one, and the difference is your unprotected surface: undecommissioned v1 routes, framework-generated handlers, and the debug endpoint added during an incident.

Sep 18, 20266 min read
Application Security

Permission Models Are Not Designed, They Accumulate

An is_admin boolean, then a role column, then a special case for one customer. Three years later nobody can say what a given user can do without reading the code, and an auditor is asking.

Sep 17, 20266 min read
Application Security

Four Silent Ways a Rate Limiter Permits Everything

A forgeable key, a per-instance counter, a fail-open catch block and a fixed window all produce a limiter that runs, logs, appears on the architecture diagram, and blocks nothing. None shows up in the usual test.

Sep 17, 20266 min read
Application Security

Your App Issues Two Kinds of Token and One Verifier Only Knows One

An SSO user carries your auth service's token, not your identity provider's. A verifier that accepts only the provider's tokens rejects exactly the users it was built for, and the symptom is a button that does nothing.

Sep 17, 20266 min read
AI Security

Writing an MCP Server That Holds No Credentials

Give a model a tool that writes and you have added a route into whatever sits behind it. The design that keeps it a new shape rather than a new privilege, and the four things that were not obvious.

Sep 17, 20267 min read
Vulnerability Analysis

A Read-Only API Key Was Enough to Overwrite Files on Cisco SD-WAN Manager

CVE-2026-20122, an additional Cisco Catalyst SD-WAN Manager finding beyond this series' earlier coverage, shows how a low-privilege API credential can still enable a file-write escalation.

Sep 16, 20264 min read
Industry Analysis

Third-party risk assessment for insurtech SaaS platforms

A practical playbook for running an insurtech third-party risk assessment across vendors, APIs, and integrations before they touch policyholder data.

Aug 10, 20268 min read
Application Security

Your DAST Scanner Was Built to Crawl Links. Your Application Doesn't Have Any.

Classic DAST discovers attack surface by following hyperlinks. In an estate of APIs and serverless functions there is nothing to crawl, so the scan completes, reports clean, and covers little.

Aug 9, 20266 min read
Application Security

The Average Enterprise Runs 900 APIs. It Can List Maybe 600 of Them.

API attacks are climbing steeply and 87% of organisations reported an incident last year. The root cause is not weak authentication — it is that many production endpoints are on nobody's list.

Aug 8, 20266 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.