COMPLETED5 of 5
Securing APIs
A five-part series on the parts of API security that trip real teams up. Written from the perspective of the code owner, not the auditor.
01/05
APIs Are the New Perimeter. 91% of Organizations Aren't Ready.
Why the API layer is now the front door, and what perimeter thinking gets wrong about it.
Jul 22, 2025
02/05
The REST API Vulnerability Every Developer Codes
Broken object-level authorization, in the wild and in your codebase. How to spot it and how to fix it.
Aug 4, 2025
03/05
Why API Gateways Give You False Security
A gateway is a control, not a strategy. What it can and cannot do for you.
Jul 12, 2026
04/05
The Microservices Security Problem No One Talks About
Most teams think they've secured their microservices. The east-west traffic between services says otherwise.
Aug 2026
05/05
API Testing That Actually Prevents Breaches
Contract tests, fuzzing, and runtime behavior. Testing that goes beyond checking that endpoints respond.
Sep 2026
Get the next article when it's published
No promotions. Just the next piece.
