The BatchQL tool is a GraphQL security auditing script with a focus on performing batch GraphQL queries and mutations.

This script is not complex, and we welcome improvements. When exploring the problem space of GraphQL batching attacks, we found that there were a few blog posts on the internet, however no tool to per ...

Continue Reading
APIs are everywhere, and it’s impossible to know all of them.

You can’t rely on manual processes for visibility into your attack surface. Lack of understanding about the risk that APIs present? Even if you have a good handle on what APIs you have in your envi ...

Continue Reading
I’m a fan of the new format.

It does what it sets out to do, and I think that’s great https://t.co/C6Sz4GxrMm ...

Continue Reading
We’re going to be sending you a lot of emails from now on

We're going to be sending you a lot of emails from now on https://t.co/bBgvdTKAKE ...

Continue Reading
I’m a software engineer at Google, and I make things.

I was born in the late 80s, which means that my first computer was an Apple IIe. My parents bought it for me when I was 8 years old because they wanted to teach me how to program. They were right: pro ...

Continue Reading
If you are a developer, you need to know about API Security.

Read More 3 July 2021 API Security Need to Know: T tl;dr: If you are a developer, you need to know about API Security https://t.co/gwbahdf0I9 ...

Continue Reading
You should only trust your own APIs and the data they return.

No one else. 5. Use a Centralized Logging System for All API Traffic to Keep Track of Everything That Happens in Your Network This is an important security principle that will stay with us forever: ...

Continue Reading
It’s not a good idea to use the same password for multiple sites.

tl;dr: Don’t reuse passwords. Use a password manager and two-factor authentication whenever possible. tl;dr: If you have an account on any site that has been breached, change your password immediate ...

Continue Reading

Back to Main

Subscribe for the latest news: