API Security Insights and Resources

Stay informed with expert articles, guides, and the latest trends in API security


Financial Services API Security Compliance Guide

Dan Barahona
Dan Barahona

API Abuse Detection: Distinguishing Between Bots

Dan Barahona
Dan Barahona

GraphQL Security Testing: Complete Guide for Developers

Dan Barahona
Dan Barahona

Unrestricted Business Flows: OWASP Principle 6 Explained

Dan Barahona
Dan Barahona

Instagram API Breach: Lessons on Sensitive Business Flows

Dan Barahona
Dan Barahona

BFLA Explained: Securing API Functions from Abuse

Dan Barahona
Dan Barahona

BOPLA Explained: Prevent Mass Assignment & Data Exposure

Dan Barahona
Dan Barahona

Preventing Resource Abuse: Protect APIs from Harvesting

Dan Barahona
Dan Barahona

Inside the Peloton Breach: Broken Authentication Lessons

Dan Barahona
Dan Barahona

Improper Inventory Management in APIs: OWASP 9 Explained

Dan Barahona
Dan Barahona

Unsafe API Consumption: Securing Third-Party Integrations

Dan Barahona
Dan Barahona

Broken Authentication Explained: OWASP API Principle 2

Dan Barahona
Dan Barahona

Are Free API Scanners Actually Worth It?

Dan Barahona
Dan Barahona

How to Choose the Right API Pen-Testing Tool

Dan Barahona
Dan Barahona

BOLA Explained: OWASP API Security Principle 1 for Teams

Dan Barahona
Dan Barahona

AppSec Tech Landscape: Strengths, Gaps & What Teams Need

Dan Barahona
Dan Barahona

The Three Pillars of Modern API Security

Dan Barahona
Dan Barahona

API Failure: 7 Causes and How to Fix Them

Dan Barahona
Dan Barahona

Which API Security Testing Tool Should I Choose

Dan Barahona
Dan Barahona

CI/CD API Security: A Complete Automation Guide

Dan Barahona
Dan Barahona

API Security Mistakes That Lead to Data Breaches

Dan Barahona
Dan Barahona

How to Detect Business Logic Vulnerabilities in API

Dan Barahona
Dan Barahona

Why Do APIs Keep Getting Hacked

Dan Barahona
Dan Barahona

API Fuzzing for Security Testing: Complete Guide

Dan Barahona
Dan Barahona

Difference Between SAST and DAST: Key Insights & Tools

Dan Barahona
Dan Barahona

BOLA Explained: The Threat No One’s Testing

Jesse Freeman
Jesse Freeman

APIsec presents the 2024 API Security Market Report

Shelby Matthews
Shelby Matthews

Internal APIs at Risk: Why Testing Matters

Stacey Levine
Stacey Levine

2024 API Security Best Practices

Dan Barahona
Dan Barahona

Upcoming DSS 4.0 Deadline for PCI Compliance

Shelby Matthews
Shelby Matthews

Inside the Edulog Breach: Lessons on BOLA & API Risk

Shelby Matthews
Shelby Matthews

2023 OWASP API Top Ten

Shelby Matthews
Shelby Matthews

HIPAA vs Cures Act: Navigating Privacy & Interoperability

Christine Bevilacqua
Christine Bevilacqua

How to Choose an API Security Tech Stack

Dan Barahona
Dan Barahona

Top 5 Burp Suite Alternatives for API Security Testing

Dan Barahona
Dan Barahona

Burp vs ZAP: Which Finds More API Bugs?

Dan Barahona
Dan Barahona

Best Pen-Testing Tools for Modern APIs

Dan Barahona
Dan Barahona

API Testing Automation: How It Transforms DevSecOps

Dan Barahona
Dan Barahona

Shift Left Security: The Ultimate Guide

Dan Barahona
Dan Barahona

Business Logic Flaws in APIs: The Silent Threat

Dan Barahona
Dan Barahona

HTTP Verb Tampering: Key Risks and Fixes

Wesley Meier
Wesley Meier

Generate Flawless OpenAPI Specs & Secure APIs

Dave Piskai
Dave Piskai

Business Logic vs Application Logic: Key Differences

Wesley Meier
Wesley Meier

What Is a Business Logic Layer?

Dan Barahona
Dan Barahona

Fintech API Security Checklist: Avoid Disaster

Dan Barahona
Dan Barahona

Banking APIs: Closing the Door on Fraud

Dan Barahona
Dan Barahona

Fintech APIs: Are You Leaking Money & Data?

Dan Barahona
Dan Barahona

What Is OAuth 2.0 and How Does It Work?

Dan Barahona
Dan Barahona

Top API Security Testing Tools You Need Now

Dan Barahona
Dan Barahona

API Security Checklist: What You Need To Know

Dan Barahona
Dan Barahona

Excessive Data Exposure: Are Your APIs Over-Sharing?

Dan Barahona
Dan Barahona

3 Steps for an Effective API Testing Process

Dan Barahona
Dan Barahona

The Hidden Cost of Late API Bug Discovery

Dan Barahona
Dan Barahona

Why APIs Are Quietly Your Largest Risk

Dan Barahona
Dan Barahona

API Security Glossary

Dan Barahona
Dan Barahona