Blog
Original research and disclosure write-ups.
Broken Object Level Authorization is the #1 OWASP API Top 10 risk. It needs two access tokens and an OpenAPI spec to detect. Most scanners do not bother.
Apr 30, 2026
Customers fix the A01/A02/A03 stuff. A09 - security logging and alerting failures - quietly stays broken on most production systems. Why, and how NANOTESTING surfaces it.
Apr 27, 2026