Safeguard
Tag

rate-limiting

Safeguard articles tagged "rate-limiting" — guides, analysis, and best practices for software supply chain and application security.

16 articles

Application Security

GraphQL Moved Your Authorisation Checks and Most Teams Left Them Behind

In REST an operation has one endpoint, so the check has one place to live. In a graph a field can be reached by many paths, and a check on the top-level query does not protect the same data reached as a nested field.

Sep 18, 20265 min read
Application Security

Inbound Email Is an Unauthenticated API You Forgot You Built

Reply to a notification and it appears in the ticket. Forward a document and it imports. The From header is a string the sender chooses, and it is what most implementations key on.

Sep 18, 20265 min read
Cloud Security

Autoscaling Turned the Attack Into an Invoice

Every request was served, no alerts fired, the dashboards stayed green. The properties that made your infrastructure resilient are what made the attack work, and the only symptom arrives weeks later on a bill.

Sep 18, 20266 min read
Application Security

Four Silent Ways a Rate Limiter Permits Everything

A forgeable key, a per-instance counter, a fail-open catch block and a fixed window all produce a limiter that runs, logs, appears on the architecture diagram, and blocks nothing. None shows up in the usual test.

Sep 17, 20266 min read
Application Security

Your Edge Appends to X-Forwarded-For, So the First Hop Is Whatever the Caller Typed

Reading the first entry of X-Forwarded-For is reading user input. We captured what our load balancer actually sends, and it explains why a rate limiter can run for months without limiting anything.

Sep 17, 20267 min read
Application Security

Designing a secure Node.js API gateway: auth, rate limits, validation, and signing

CVE-2020-15084 let attackers forge JWTs against express-jwt because one algorithm check was missing — a case study in why gateways need four defense layers, not one.

Jul 15, 20266 min read
Application Security

API gateway security: enforcing authN/authZ and rate limits at the edge

A single unauthenticated API endpoint exposed 37 million T-Mobile accounts in 2023. Edge-enforced authZ and identity-aware rate limits are how you prevent the repeat.

Jul 13, 20266 min read
Application Security

Building an authenticated, TLS-secured WebSocket server in Python

WebSockets skip same-origin checks by default — CWE-1385 exists because of it. Here's how to build one in Python with origin checks, TLS, and rate limits.

Jul 11, 20266 min read
Industry Analysis

Missing Rate Limiting on APIs and Login Endpoints

Missing rate limiting turned single APIs into 37-million-record breaches at T-Mobile and Optus. Here's why it happens, how attackers exploit it, and how to catch it first.

Jul 10, 20267 min read
Application Security

A practical REST API hardening checklist

OWASP's 2023 API Security Top 10 still ranks broken object-level authorization as the #1 risk — here's a concrete checklist for authn, rate limiting, and input validation.

Jul 8, 20266 min read
Security Guides

GraphQL API Security: Introspection, Depth Limits, and Authorization

GraphQL's flexibility is its attack surface. Nested queries, introspection, and per-field authorization all fail differently than REST. Here's how to secure them.

Jul 5, 20265 min read
Supply Chain Attacks

RubyGems Suspends New Signups After a 500-Package Malicious Flood (May 2026)

On 12-13 May 2026, RubyGems was hit by a coordinated spam-publishing flood that pushed 500+ malicious packages from newly-registered bot accounts. The registry paused new signups and re-enabled them on 16 May after tightening rate limiting with Fastly.

May 14, 20269 min read

Self-healing security runs on Safeguard.

Your first fix PR is minutes away.

No sales call required, even your agent can complete the purchase over MCP.