Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Why Your WAF Isn't Enough: Runtime Protection for AI Agents and APIs

Most security leaders believe their API attack surface is covered. A Web Application Firewall (WAF) sits in front of the application. An API gateway manages authentication, rate limiting, and schema validation. Some teams add a bot management layer on top. This looks like defense in depth. In practice, it repeats the same layer, the perimeter, multiple times. Most API breaches do not start with a WAF bypass.

Zombie APIs Are Costing You More Than You Think: A Risk Quantification Guide

Zombie APIs are API versions or endpoints that were once known and documented, but were never properly retired. A team ships v2 of an API, tells everyone to migrate, and assumes v1 is dead. In reality, v1 is still running on a server somewhere, still accepting requests, and still connected to production data. This is different from unmanaged APIs, which were never documented in the first place. Zombie APIs were documented once.

The Hidden Cost of BOLA/BFLA Vulnerabilities: A CISO's Guide to Quantifying Risk

Every CISO managing an API estate has heard of Broken Object Level Authorization (BOLA) and Broken Function Level Authorization (BFLA). What is harder to pin down is what these vulnerabilities actually cost the business when they go unaddressed. Board members and finance teams want numbers, not acronyms, and that gap between technical risk and financial risk is where security budgets get lost. BOLA has held the number one spot in the OWASP API Security Top 10 since the list was created in 2019.

Secure AI Written Code Before It Ships: Salt Code

AI coding assistants are transforming how enterprise software gets built. Developers at every level are prompting their way to production-ready APIs, MCP integrations, and agentic workflows faster than any security team can review them. The problem is that none of those assistants knows your internal security standards, regulatory obligations, or risk tolerance. The result is insecure patterns shipping unnoticed, vulnerabilities discovered downstream when fixes are costly, and compliance becoming a guessing game on every commit.

What is Security Posture Management and Why is it Important?

Modern organizations don't operate from a single server room anymore. Today's enterprise environment spans dozens of cloud services, SaaS applications, APIs, AI agents, and non-human identities, all of which are continuously changing. A quarterly security audit is no longer a safety net, but now considered a gap.

Validity-Override API Tutorial: Confirm If a Leaked Secret Is Still Exploitable

GitGuardian's validity-override API lets security and engineering teams tell GitGuardian whether an exposed credential is actually valid, even when automatic checks mark it as Failed to Check. Secrets tied to internal services, private APIs, or systems GitGuardian cannot reach often fall into this category. GitGuardian automatically validates most supported credential types, but when it cannot, teams can now perform their own validation and feed the result back into the platform.

7 API Security Requirements for Payment Transactions

Every payment flow your organization runs, from card authorization to ACH transfers to embedded lending to open banking consent, is now an API call. That’s good for velocity. It’s also why payment APIs sit at the top of the attack surface for financial services and enterprise SaaS platforms handling money movement.

Whos watching your AI A security leader panel on runtime visibility and accountability

AI is making decisions across your environment — calling APIs, accessing data, and taking action. Most organizations know it's happening, but far fewer can see it, let alone stop it. In this panel discussion, security leaders will share what they've learned deploying and governing AI workloads at scale on AWS, and what it takes to close the gap between deployment and accountability.