Field notes from the offensive side of APIs
A short, occasional email from the team behind Operator: real CVEs we disclose, the BOLA and BFLA authorization flaws scanners keep missing, and what agentic penetration testing is actually finding in production APIs. No spam, no filler, unsubscribe in one click.
Signal, not a content calendar
We send when we have something worth your attention, not on a schedule. Expect a handful of emails a quarter.
Real disclosures
When our team discloses a vulnerability, you get the write-up and what it means for teams running similar stacks, in plain terms.
Authorization flaws
BOLA, BFLA, and the business-logic bugs that scanners structurally cannot find, explained with the reasoning an attacker uses.
What the agent finds
Patterns from continuous, exploit-proven API testing across real production surfaces, with the false-positive noise stripped out.
Watch Operator test an API end to end
Every finding is reproduced and proven before it reaches you. See the agent map a surface and prove what it surfaces.