The API Security Brief

Field notes from the offensive side of APIs

A short, occasional email from the team behind Operator: real CVEs we disclose, the BOLA and BFLA authorization flaws scanners keep missing, and what agentic penetration testing is actually finding in production APIs. No spam, no filler, unsubscribe in one click.

By subscribing you agree to receive occasional emails from Planck Proof. We never share your address. See our Privacy Policy.

What Lands In Your Inbox

Signal, not a content calendar

We send when we have something worth your attention, not on a schedule. Expect a handful of emails a quarter.

CVEs

Real disclosures

When our team discloses a vulnerability, you get the write-up and what it means for teams running similar stacks, in plain terms.

Deep dives

Authorization flaws

BOLA, BFLA, and the business-logic bugs that scanners structurally cannot find, explained with the reasoning an attacker uses.

Field notes

What the agent finds

Patterns from continuous, exploit-proven API testing across real production surfaces, with the false-positive noise stripped out.

Rather see it work?

Watch Operator test an API end to end

Every finding is reproduced and proven before it reaches you. See the agent map a surface and prove what it surfaces.