Blog

API and AI security, from the team building it.

Research, best practices, and news on securing APIs and the agentic AI systems that call them.

API & AI security, from the team

Latest posts

June 30, 2026 · Hugh Carroll

Vibe Coding Has a Security Debt Problem. Here's How to Stop Inheriting It.

Between 40–62% of AI-generated code contains vulnerabilities, produced at 2.74x the rate of human-written code.

Read post →
May 8, 2026 · Hugh Carroll

The Best API Security Platform for the Agentic Enterprise

What to weigh when selecting an API security platform built for AI-driven, agentic enterprise environments.

Read post →
February 16, 2026 · Hugh Carroll

The State of API Security Report 2026

A data-driven look at real-world API vulnerabilities and the implementation mistakes behind them.

Read post →
November 18, 2025 · Anthony Lonergan

Securing Model Context Protocol (MCP)

How MCP's contract-based design enables automated tool discovery — and secure execution.

Read post →
September 30, 2025 · Jacques Declas

API Security-by-Design in the Age of Agentic AI

How agentic AI is reshaping the cyber threats aimed at APIs, and what security-by-design means in response.

Read post →
September 2, 2025 · Anthony Lonergan

Closed Guard: Locking Down APIs Against AI-Powered Attacks

Defensive strategies for protecting APIs against increasingly capable, autonomous attack agents.

Read post →
August 18, 2025 · Jacques Declas

Why FAPI 2.0 Alone Is Not Enough to Secure Healthcare APIs

Norway's mandate of FAPI 2.0 strengthens healthcare API authentication, but comprehensive security still requires controls against risks like broken object-level authorization.

Read post →
July 15, 2025 · Anthony Lonergan

When API Drift Turns Malicious

When backend APIs unexpectedly return malicious payloads, drift stops being a nuisance and becomes a security threat — here's how to detect and prevent it.

Read post →
June 9, 2025 · Hugh Carroll

Bridging the API Security Gap — The Perception and Reality of API Security

Organizations often believe their existing security tools protect their APIs, but a significant gap remains between that perception and the reality of API vulnerabilities.

Read post →
May 22, 2025 · Anthony Lonergan

The Radware WAF Vulnerability: When Unexpected Input Bypasses Security

A Radware WAF vulnerability shows how traditional pattern-based firewalls fail against malformed requests, while a specification-driven approach blocks anything outside the defined contract.

Read post →
Browse the archive
Latest posts 2024 2023 2017–2022

Want new posts in your inbox?