> Source: https://planckproof.ai/subscribe  |  Plain-Markdown twin of the page.

The API Security Brief

# Field notes from the offensive side of APIs

A short, occasional email from the team behind Operator: real CVEs we disclose, the BOLA and BFLA authorization flaws scanners keep missing, and what agentic penetration testing is actually finding in production APIs. No spam, no filler, unsubscribe in one click.

What Lands In Your Inbox

## Signal, not a content calendar

We send when we have something worth your attention, not on a schedule. Expect a handful of emails a quarter.

CVEs

### Real disclosures

When our team discloses a vulnerability, you get the write-up and what it means for teams running similar stacks, in plain terms.

Deep dives

### Authorization flaws

BOLA, BFLA, and the business-logic bugs that scanners structurally cannot find, explained with the reasoning an attacker uses.

Field notes

### What the agent finds

Patterns from continuous, exploit-proven API testing across real production surfaces, with the false-positive noise stripped out.

Rather see it work?

## Watch Operator test an API end to end

Every finding is reproduced and proven before it reaches you. See the agent map a surface and prove what it surfaces.

[Meet Operator](https://planckproof.ai/meet-operator)

[Get a Quote](https://planckproof.ai/quote)
