Filter by Tags

API Security Gap

The API and Agentic AI Security Gap Behind Recent Breaches

⏱︎ 14 min read

TL;DR Two Second Stages, One Blind Spot Most coverage of API breaches focuses on the entry

MCP Server control

MCP Security Controls: The Complete Technical Reference for Securing MCP Servers and Clients

⏱︎ 13 min read

TL;DR MCP servers are control plane infrastructure, not just integration middleware. Securing them requires controls at

Best API Frameworks in 2026: How to Choose the Right One (and What Most Teams Miss)

⏱︎ 11 min read

TL;DR What Does “Best API Framework” Mean? Framework choice isn’t really about syntax or GitHub stars.

MCP Prompt Injection: How Attackers Hijack AI Agent Workflows Through MCP Tool Calls

⏱︎ 12 min read

TL;DR When Agents Act, Injection Has Consequences Prompt injection in a standard LLM interaction produces bad

Best API Discovery Tools for Lineage Mapping

⏱︎ 22 min read

API discovery has become a foundational capability for modern enterprises as API ecosystems expand across cloud-native

Agentic RCE Chain

Why Do AI Coding Agents Keep Getting the Same RCE Vulnerability?

⏱︎ 9 min read

TL;DR It’s one pattern An agent reads a file, approves its own next action, and the

The Abbott Cyber Incident Reveals Why Infrastructure Security Is No Longer Enough for Healthcare

⏱︎ 8 min read

TL;DR Healthcare has spent years strengthening its infrastructure against ransomware, patching vulnerabilities, deploying endpoint detection, and implementing

When AI Agents Run Healthcare Workflows, Business Logic Becomes the New Attack Surface 

⏱︎ 6 min read

TL;DR AI Has Rewired How Healthcare Operates Healthcare has moved well past pilot projects. AI agents

Continuous API Discovery in Microservices for 2026

⏱︎ 14 min read
Your enterprise runs on APIs. Every customer interaction, every data exchange, every AI decision flows through
Secure APIs and Stop Exploit

API Security: Protecting Modern and AI-Driven APIs from RCE, Abuse, and Data Breaches

⏱︎ 18 min read
APIs power nearly every digital interaction today, from mobile banking to AI chatbots. Yet poorly secured

5.7 Million Records Exposed: What the Qantas Breach Reveals About Business Logic Blind Spots

⏱︎ 7 min read

TL;DR One phone call. One deceived agent. 5.7 million exposed records and zero regulatory penalty. That’s the uncomfortable

The Agentic Attack Surface Is Growing Faster Than Your API Inventory

⏱︎ 11 min read

TL;DR AI Agents Are the New Decision Layer, and Nobody Fully Sees What They’re Calling Ask

MCP Data Exfiltration: How AI Agents Leak Sensitive Data Through MCP Tool Calls

⏱︎ 12 min read

TL;DR The Access Problem No One Scoped Properly Model Context Protocol (MCP) is what turns an

Two Months After PocketOS: What a 9-Second Database Deletion Taught Us About Agentic AI Security

⏱︎ 9 min read

TL;DR Nine seconds. One API call. A car rental software company’s production data was gone. That’s

MCP Supply Chain Security: How Malicious MCP Servers Are Infiltrating Enterprise AI Environments

⏱︎ 13 min read

TL;DR AI Agents Have a Supply Chain Problem Nobody’s Solving Every enterprise deploying AI agents is

The Four Attack Patterns Traditional Security Tools Miss at FIFA-Scale Events 

⏱︎ 5 min read

Key Takeaways  Every major tournament cycle, ticketing platforms brace for a traffic spike. Most security teams plan for

OWASP Top 10 for Agentic Applications 2026: What It Means for Enterprise AI Security 

⏱︎ 6 min read

TL;DR  What Is the OWASP Top 10?  OWASP, the Open Worldwide Application Security Project, has published

ServiceNow, Then PeopleSoft: Why the Same Endpoint Failure Keeps Repeating

⏱︎ 7 min read

TL;DR  A Pattern, Not a One-Off  Three weeks ago, it was ServiceNow: an endpoint that never asked

What Is Agentic AI Security? Why AI Agents Need a New Security Model

⏱︎ 10 min read

Key Takeaways Introduction AI systems are starting to do more than generate answers. Across customer support,

5 Agentic AI Security Use Cases Every Security Leader Must Know in 2026

⏱︎ 8 min read

Key Takeaways  Agentic AI Changes What Application Security Has to Cover   A human employee who wants to delete a customer

Top Continuous API Discovery Tools for 2026 (Enterprise SaaS & AI-First Apps)

⏱︎ 18 min read
Not all API discovery tools solve the same problem. Some help teams discover APIs once.

Why Web Application Firewalls (WAFs) are inadequate against API Attacks

⏱︎ 1 min read

During our various customer interactions, we often discuss how Appsentinels solution is different compared to a

API Security Buyer’s Guide

⏱︎ 1 min read

In the digital age, business leaders see software teams as core to the business and demand

OWASP Web Top 10 vs OWASP API Top 10 – Illusion of Security due to similarities?

⏱︎ 2 min read

In 2019, OWASP released first version of API Security Top 10. Like the omnipresent OWASP Top

Why DAST/IAST products are inadequate against finding API vulnerabilities

⏱︎ 2 min read

During our various customer interactions, customers using Dynamic Application Security Testing (DAST) or Interactive Application Security

Application Security for Cloud Native Applications

⏱︎ 2 min read

In the digital age, business leaders see software teams as core to the business and are

It’s all about business logic security!

⏱︎ 1 min read

In May’22, a major Indian payment gateway reported a fraud of 7.3 Crore (approx. 1 million