<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>NavonStack Blog</title><description>Field notes on API abuse, anomaly detection, and developer-first tooling.</description><link>https://navonstack.com/</link><item><title>Microservices Broke the Security Perimeter. Most Teams Haven&apos;t Noticed.</title><link>https://navonstack.com/blog/posts/microservices-broke-the-security-perimeter/</link><guid isPermaLink="true">https://navonstack.com/blog/posts/microservices-broke-the-security-perimeter/</guid><description>The perimeter model assumed one front door. Microservices gave you dozens. Here&apos;s what that actually means for runtime security — and why the tooling most teams rely on was built for an architecture that no longer exists.</description><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate></item><item><title>Detection You Can Read: Why Explainable API Security Alerts Matter</title><link>https://navonstack.com/blog/posts/detection-you-can-read/</link><guid isPermaLink="true">https://navonstack.com/blog/posts/detection-you-can-read/</guid><description>Most API security tools answer &apos;is this an attack?&apos; with a number you have to trust. The better question is whether the engineer on call can read the rule that fired — and disagree with it.</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate></item><item><title>What Makes an API Alert Worth Waking Up For</title><link>https://navonstack.com/blog/posts/what-makes-an-alert-worth-waking-up-for/</link><guid isPermaLink="true">https://navonstack.com/blog/posts/what-makes-an-alert-worth-waking-up-for/</guid><description>An alert that doesn&apos;t tell you how serious it is, or why it fired, isn&apos;t help — it&apos;s homework. Here&apos;s the case for detection you can read at 3am, not a score you have to trust.</description><pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Why Most API Abuse Looks Valid at First</title><link>https://navonstack.com/blog/posts/why-api-abuse-looks-valid/</link><guid isPermaLink="true">https://navonstack.com/blog/posts/why-api-abuse-looks-valid/</guid><description>The dangerous API requests don&apos;t fail authentication. They pass it — and then do something they shouldn&apos;t. Here&apos;s why that&apos;s hard to catch, and what actually works.</description><pubDate>Sat, 13 Jun 2026 00:00:00 GMT</pubDate></item><item><title>The dead-man&apos;s switch for telemetry</title><link>https://navonstack.com/blog/posts/the-dead-mans-switch-for-telemetry/</link><guid isPermaLink="true">https://navonstack.com/blog/posts/the-dead-mans-switch-for-telemetry/</guid><description>Most monitoring tells you when something fires. The more dangerous failure is when your telemetry goes quiet — and nothing tells you at all. Here&apos;s how APIGuard treats silence as a security event.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate></item><item><title>Why valid traffic can still be dangerous</title><link>https://navonstack.com/blog/posts/why-valid-traffic-can-still-be-dangerous/</link><guid isPermaLink="true">https://navonstack.com/blog/posts/why-valid-traffic-can-still-be-dangerous/</guid><description>Most API attacks don&apos;t fail authentication — they authenticate successfully, then do something they shouldn&apos;t. Here&apos;s why that&apos;s the hard part.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate></item></channel></rss>