⤷ Title: The Five-Month Window
════════════════════════
𐀪 Author: Alexius McMullin
════════════════════════
ⴵ Time: Wed, 16 Sep 2026 20:49:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #software_vulnerabilities #jwt #api_security #enterprise_security
════════════════════════
𐀪 Author: Alexius McMullin
════════════════════════
ⴵ Time: Wed, 16 Sep 2026 20:49:44 GMT
════════════════════════
⌗ Tags: #cybersecurity #software_vulnerabilities #jwt #api_security #enterprise_security
Medium
The Five-Month Window
WSO2 patched it in April. Attackers exploited it in September.
⤷ Title: REST, GraphQL, or gRPC? How I Actually Choose API Architecture for Enterprise Software
════════════════════════
𐀪 Author: Sizan Mahmud
════════════════════════
ⴵ Time: Thu, 17 Sep 2026 08:35:49 GMT
════════════════════════
⌗ Tags: #software_architecture #api_security #software_development
════════════════════════
𐀪 Author: Sizan Mahmud
════════════════════════
ⴵ Time: Thu, 17 Sep 2026 08:35:49 GMT
════════════════════════
⌗ Tags: #software_architecture #api_security #software_development
Medium
REST, GraphQL, or gRPC? How I Actually Choose API Architecture for Enterprise Software
A practical framework from years of building custom SaaS and ERP systems — not a textbook comparison.
⤷ Title: The OTP Attack That Taught Me a Lesson About Security
════════════════════════
𐀪 Author: Umar Farook J
════════════════════════
ⴵ Time: Thu, 17 Sep 2026 10:15:00 GMT
════════════════════════
⌗ Tags: #secure_coding #authentication #application_security #real_application_security #api_security
════════════════════════
𐀪 Author: Umar Farook J
════════════════════════
ⴵ Time: Thu, 17 Sep 2026 10:15:00 GMT
════════════════════════
⌗ Tags: #secure_coding #authentication #application_security #real_application_security #api_security
Medium
The OTP Attack That Taught Me a Lesson About Security
One unexpected incident. One small exception. And a lesson I will never forget.
⤷ Title: How to Inventory and Lock Down the API Surfaces on Your Network Appliances
════════════════════════
𐀪 Author: Anthony Bahn
════════════════════════
ⴵ Time: Thu, 17 Sep 2026 13:59:46 GMT
════════════════════════
⌗ Tags: #attack_surface_management #api_security #network_appliance #cybersecurity #access_control_list
════════════════════════
𐀪 Author: Anthony Bahn
════════════════════════
ⴵ Time: Thu, 17 Sep 2026 13:59:46 GMT
════════════════════════
⌗ Tags: #attack_surface_management #api_security #network_appliance #cybersecurity #access_control_list
Medium
How to Inventory and Lock Down the API Surfaces on Your Network Appliances
Infrastructure ACLs only work if you know every listener an appliance exposes. Six steps to enumerate API surfaces, map their…
⤷ Title: From IDOR to Fraud: Breaking Access Control in a Travel Booking Platform
════════════════════════
𐀪 Author: Romene Mohtadi It
════════════════════════
ⴵ Time: Thu, 17 Sep 2026 18:32:59 GMT
════════════════════════
⌗ Tags: #pentesting #api_security #cybersecurity #bug_bounty #owasp
════════════════════════
𐀪 Author: Romene Mohtadi It
════════════════════════
ⴵ Time: Thu, 17 Sep 2026 18:32:59 GMT
════════════════════════
⌗ Tags: #pentesting #api_security #cybersecurity #bug_bounty #owasp
Medium
From IDOR to Fraud: Breaking Access Control in a Travel Booking Platform
Introduction
⤷ Title: Why Admin Panel Subdomain vs Path Isn’t a Security Decision
════════════════════════
𐀪 Author: FOLAKE SOWONOYE
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 18:55:31 GMT
════════════════════════
⌗ Tags: #backend_development #cybersecurity #access_control #web_development #api_security
════════════════════════
𐀪 Author: FOLAKE SOWONOYE
════════════════════════
ⴵ Time: Fri, 18 Sep 2026 18:55:31 GMT
════════════════════════
⌗ Tags: #backend_development #cybersecurity #access_control #web_development #api_security
Medium
Why Admin Panel Subdomain vs Path Isn’t a Security Decision
A decision framework for backend and frontend teams weighing where the admin portal should live, and the RBAC, MFA, and gateway controls
❤1
⤷ Title: AI Agent Egress Control: Sandbox, Allowlist, and API Gateway
════════════════════════
𐀪 Author: ActionDock
════════════════════════
ⴵ Time: Thu, 17 Sep 2026 00:00:34 GMT
════════════════════════
⌗ Tags: #ai_security #agentic_ai #ai_agent #cybersecurity #api_security
════════════════════════
𐀪 Author: ActionDock
════════════════════════
ⴵ Time: Thu, 17 Sep 2026 00:00:34 GMT
════════════════════════
⌗ Tags: #ai_security #agentic_ai #ai_agent #cybersecurity #api_security
Medium
AI Agent Egress Control: Sandbox, Allowlist, and API Gateway
AI agent egress control decides what an agent can send out of its environment, where it can send it, and under which authority. A…
⤷ Title: The Twin Illusions of AI Agent Security: Why “Read-Only” and “Human-in-the-Loop” Fail
════════════════════════
𐀪 Author: Akansha Shukla
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 11:13:16 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #appsec #devsecops #api_security
════════════════════════
𐀪 Author: Akansha Shukla
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 11:13:16 GMT
════════════════════════
⌗ Tags: #artificial_intelligence #appsec #devsecops #api_security
Medium
The Twin Illusions of AI Agent Security: Why “Read-Only” and “Human-in-the-Loop” Fail
Restricting autonomous assistants to GET requests and terminal approvals fails against client-side rendering side channels, and how to…
⤷ Title: Your AI Agent’s Reasoning Isn’t as Private as You Think
════════════════════════
𐀪 Author: Ali Süleyman TOPUZ
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 15:01:02 GMT
════════════════════════
⌗ Tags: #api_security #llm_security #ai_security
════════════════════════
𐀪 Author: Ali Süleyman TOPUZ
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 15:01:02 GMT
════════════════════════
⌗ Tags: #api_security #llm_security #ai_security
Medium
Your AI Agent’s Reasoning Isn’t as Private as You Think
Do you actually know whether your encrypted reasoning trace is private? Not “probably,” not “the docs say it’s encrypted so it must be…
⤷ Title: Shared Libraries Are Not Enough: Making Authorization Secure by Default
════════════════════════
𐀪 Author: Kovid
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 19:04:59 GMT
════════════════════════
⌗ Tags: #api_security #software_architecture #software_engineering #engineering_leadership #distributed_systems
════════════════════════
𐀪 Author: Kovid
════════════════════════
ⴵ Time: Sat, 19 Sep 2026 19:04:59 GMT
════════════════════════
⌗ Tags: #api_security #software_architecture #software_engineering #engineering_leadership #distributed_systems
Medium
Shared Libraries Are Not Enough: Making Authorization Secure by Default
In my last article, I wrote about a simple but important distinction: authentication tells us who you are; authorization determines what…