News

The 12 Months of Innovation: How Salt Security Helped Rewrite API & AI Security in 2025

  • None--securityboulevard.com
  • published date: 2025-12-17 00:00:00 UTC

None

<p>As holiday lights go up and inboxes fill with year-in-review emails, it’s tempting to look back on 2025 as “the year of AI.”</p><p>But for security teams, it was something more specific – the year APIs, AI agents, and MCP servers collided across the API fabric, expanding the attack surface faster than most organizations could keep up.</p><p>At Salt Security, we spent 2025 focused on one thing: defending the API action layer where AI, applications, and data intersect. And we did it with a steady drumbeat of innovation, a new “gift” for security teams almost every month.</p><p>So in the spirit of the season, here’s a look back at Salt’s 12 Months of Innovation – a year-long series of product launches, partnerships, and research milestones designed to help organizations stay ahead of fast-moving threats.</p><h2>January – <a href="https://salt.security/blog/future-gazing-how-api-security-will-evolve-in-2025">The Year Kicks Off with APIs at the Center</a></h2><p>We kicked off the year by shining a harsh light on what many teams already suspected:</p><ul> <li>APIs now sit at the center of almost every digital initiative.</li> <li>Zombie and unmanaged APIs still live in production.</li> <li>Software supply chain dependencies are quietly multiplying risk.</li> </ul><p>Early 2025 research and thought leadership from Salt Labs showed just how dangerous it is to run modern AI and automation on top of APIs you don’t fully understand or control.</p><p><strong>Takeaway: </strong>January set the tone – defending tomorrow’s API fabric with yesterday’s tools is no longer an option.</p><h2>February – A Spotlight on API Reality</h2><p>In February, we went from “we think we have a problem” to <strong>“here are the numbers.”</strong></p><p>With the latest <a href="https://salt.security/press-releases/salt-labs-state-of-api-security-report-reveals-99-of-respondents-experienced-api-security-issues-in-past-12-months">State of API Security Report </a>and key industry recognitions such as inclusion in top security lists, Salt brought hard data to boardroom and CISO conversations.</p><p>The message was clear:</p><ul> <li>API traffic is exploding.</li> <li>Attackers are targeting APIs at scale.</li> <li>Traditional perimeter and app security are missing critical context.</li> </ul><p><strong>Takeaway: </strong>API security is no longer a niche concern. It’s a business risk that demands strategy, budget, and board-level attention.</p><h2>March – Gold Medals &amp; Rising Shadows</h2><p>March blended <strong>validation and urgency.</strong></p><p>On one side, industry bodies recognized Salt’s leadership with awards like a <a href="https://salt.security/press-releases/salt-security-wins-gold-at-the-20th-annual-2024-globee-r-awards-for-cybersecurity">Gold Globee</a>, underscoring the maturity and impact of our platform.</p><p>On the other, new blogs and research highlighted reality on the ground:</p><ul> <li>Compliance and data privacy pressure are rising.</li> <li>AI-driven attacks are accelerating, not slowing.</li> </ul><p><strong>Takeaway: </strong>Excellence in API security isn’t just about winning awards, it’s about staying ahead of adversaries who are constantly adapting.</p><h2>April – A Season of Partnerships &amp; Paradigm Shifts</h2><p>In April, collaboration took center stage.</p><p>We deepened integrations with leading platforms such as <a href="https://salt.security/press-releases/salt-security-and-crowdstrike-introduce-comprehensive-suite-of-api-security-integrations">CrowdStrike</a> and expanded support for modern ecosystems, including <a href="https://salt.security/press-releases/salt-security-launches-the-first-mcp-server-to-revolutionize-api-security-in-the-age-of-ai">MCP server–driven architectures</a>.</p><p>By weaving <strong>Salt API intelligence</strong> into tools security teams already rely on, we helped customers:</p><ul> <li>Gain richer, real-time context.</li> <li>Simplify deployment and operations.</li> <li>Extend protections into their existing workflows.</li> </ul><p><strong>Takeaway: </strong>API and AI security are team sports. Partnerships and integrations turn siloed tools into a cohesive defense fabric.</p><h2>May – The Cloud Era Gets Real</h2><p>By May, the conversation had shifted from “we’re moving to the cloud” to <strong>“our entire business depends on it.”</strong></p><p>Salt expanded coverage and governance capabilities for leading cloud environments and partners, helping customers:</p><ul> <li>Align API security with cyber insurance and regulatory expectations.</li> <li>Build stronger posture governance and risk-management processes.</li> <li>Translate technical API risk into board-ready language.</li> </ul><p><strong>Takeaway: </strong>In 2025, <a href="https://salt.security/blog/building-a-secure-foundation-compliance-driven-api-posture-governance">API security moved squarely into the boardroom</a> as a core pillar of enterprise risk.</p><h2>June – Illuminate Everything</h2><p>June was all about turning on the lights.</p><p>We <a href="https://salt.security/blog/introducing-salt-illuminate-api-security-that-works-in-minutes-not-months">launched Salt Illuminate</a> and expanded <strong>Cloud Connect</strong>, giving customers the ability to:</p><ul> <li>Discover APIs across complex, hybrid, and multi-cloud environments.</li> <li>Spot <strong>shadow, zombie, and unmanaged APIs</strong> in minutes instead of months.</li> <li>Build a live inventory that actually stays current.</li> </ul><p><strong>Takeaway:</strong> You can’t protect what you can’t see. Illuminate gave teams the visibility foundation they’ve been missing.</p><h2>July – <a href="https://salt.security/blog/the-cisos-api-security-paradox-high-priority-huge-blind-spots">CISOs Sound the Alarm</a></h2><p>In July, the stakes became very real.</p><p>High-profile AI mishaps, including incidents like the McDonald’s chatbot breach, made one thing painfully obvious: <strong>conversational AI and digital experiences are only as safe as the APIs behind them.</strong></p><p>Salt responded with:</p><ul> <li>Deep-dive blogs on AI agent risk and API blind spots.</li> <li>The launch of <strong>Salt Surface</strong>, designed to map and prioritize exposed API risk.</li> </ul><p><strong>Takeaway: </strong>2025 was the year CISOs started asking not just “What APIs do we have?” but “Which of these are exposed, exploitable, and business-critical?”</p><h2>August – Autonomous Everything</h2><p>By August, “autonomous” wasn’t just a buzzword, it was a roadmap theme.</p><p>Organizations leaned hard into:</p><ul> <li>Autonomous workflows</li> <li>AI-driven decisioning</li> <li>Automated threat detection and response</li> </ul><p>Salt’s innovation in this space emphasized a key reality: <strong>AI, autonomy, and APIs are inseparable.</strong></p><p>We advanced protections for <a href="https://salt.security/blog/beyond-anomalies-how-autonomous-threat-hunting-uncovers-the-full-attack-story">autonomous threat hunting</a> and AI-driven security use cases, reinforcing that <strong>if APIs are compromised, autonomous systems are too.</strong></p><p><strong>Takeaway: </strong>You can’t secure autonomous operations if you’re not securing the API action layer that powers them.</p><h2>September – <a href="https://salt.security/press-releases/salt-security-announces-the-industrys-first-solution-to-secure-api-actions-taken-by-ai-agents">Securing the AI Agent Revolution</a></h2><p>September was a turning point.</p><p>Salt introduced the <strong>industry’s first solution to secure AI agent actions</strong> across APIs and MCP servers, bringing real controls to a problem that had mostly been theoretical.</p><p>This meant:</p><ul> <li>Protection against prompt injection and misuse.</li> <li>Guardrails around what AI agents can access or execute.</li> <li>Enforceable policy where it matters: at the API and action level.</li> </ul><p><strong>Takeaway: </strong>The AI agent revolution doesn’t have to be a security nightmare — if you secure the actions, not just the model.</p><h2>October – The <a href="https://salt.security/press-releases/salt-security-report-shows-api-security-blind-spots-could-put-ai-agent-deployments-at-risk">Blind Spots Strike Back</a></h2><p>In October, new data from Salt and customer environments revealed <strong>how deep the AI + API blind spots really go.</strong></p><p>We broke down:</p><ul> <li>Misconfigurations in AI-driven workflows.</li> <li>Risky patterns in agentic and MCP deployments.</li> <li>Common mistakes teams make when bolting AI onto existing architectures.</li> </ul><p>Through detailed analysis and practical guidance, we helped teams <strong>turn confusion into a roadmap</strong> for modernizing their security posture.</p><p><strong>Takeaway: </strong>Education is as important as technology. You can’t fix what you don’t fully understand.</p><h2>November – Security Starts in Code</h2><p>November brought a massive step forward in <strong>shifting API security left and right at the same time.</strong></p><p>We launched:</p><ul> <li><a href="https://salt.security/blog/from-cloud-to-code-salt-cloud-connect-now-scans-github">GitHub Connect</a> – to scan code repositories for shadow APIs, spec mismatches, and insecure patterns before they ship.</li> <li><a href="https://salt.security/press-releases/salt-security-launches-salt-mcp-finder-technology-the-discovery-engine-for-mcp-servers-in-agentic-ai-deployments">MCP Finder </a>– to identify risky MCP configurations and AI-integrated workflows early in the development lifecycle.</li> </ul><p>Combined with runtime intelligence from the Salt platform, customers could now connect:</p><ul> <li>What’s <strong>being written</strong> → What’s <strong>being deployed</strong> → What’s <strong>being exploited</strong></li> </ul><p><strong>Takeaway: </strong>Real API security covers the full lifecycle, from design and code to production traffic and AI-agent actions.</p><h2>December – Hello, Pepper</h2><p>We closed the year with a new kind of experience: <a href="https://salt.security/press-releases/salt-security-launches-ask-pepper-ai-leveraging-aws-bedrock-to-bring-generative-ai-to-api-security">Ask Pepper AI.</a></p><p>Ask Pepper AI turns Salt’s platform into a conversational partner, letting users:</p><ul> <li>Ask natural-language questions about APIs, risks, and threats.</li> <li>Accelerate investigation and incident response.</li> <li>Bring complex insights to teams who don’t live inside dashboards.</li> </ul><p>Alongside <strong>MCP protection for AWS WAF</strong>, December marked the next stage in our vision: <strong>API security that’s not just powerful, but accessible and intuitive.</strong></p><p><strong>Takeaway: </strong>When security teams can simply ask questions and get meaningful, contextual answers, they move faster, and so does the business.</p><h2>Looking Ahead: Building on a Year of Innovation</h2><p>If 2025 was the year APIs fully merged with AI agents, automation, and MCP servers, 2026 will be the year organizations either <strong>embrace the API action layer</strong> or fall behind those that do.</p><p>At Salt Security, our focus remains the same:</p><ul> <li><strong>See everything</strong> – every API, every action, every blind spot.</li> <li><strong>Understand the context</strong> – who’s calling what, from where, and why.</li> <li><strong>Stop attacks</strong> – before they turn into outages, data loss, or brand damage.</li> </ul><p>The 12 Months of Innovation were just the beginning. The threats are evolving, and so are we.</p><p>If you want to learn more about Salt and how we can help you, please <a href="https://salt.security/contact-us">contact us</a>, <a href="https://salt.security/demo-request">schedule a demo</a>, or <a href="https://salt.security/">visit our website</a>. You can also <a href="https://salt.security/attack-surface">get a free API Attack Surface Assessment</a> from Salt Security’s research team and learn what attackers already know.</p><div class="spu-placeholder" style="display:none"></div><div class="addtoany_share_save_container addtoany_content addtoany_content_bottom"><div class="a2a_kit a2a_kit_size_20 addtoany_list" data-a2a-url="https://securityboulevard.com/2025/12/the-12-months-of-innovation-how-salt-security-helped-rewrite-api-ai-security-in-2025/" data-a2a-title="The 12 Months of Innovation: How Salt Security Helped Rewrite API &amp; AI Security in 2025"><a class="a2a_button_twitter" href="https://www.addtoany.com/add_to/twitter?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2025%2F12%2Fthe-12-months-of-innovation-how-salt-security-helped-rewrite-api-ai-security-in-2025%2F&amp;linkname=The%2012%20Months%20of%20Innovation%3A%20How%20Salt%20Security%20Helped%20Rewrite%20API%20%26%20AI%20Security%20in%202025" title="Twitter" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_linkedin" href="https://www.addtoany.com/add_to/linkedin?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2025%2F12%2Fthe-12-months-of-innovation-how-salt-security-helped-rewrite-api-ai-security-in-2025%2F&amp;linkname=The%2012%20Months%20of%20Innovation%3A%20How%20Salt%20Security%20Helped%20Rewrite%20API%20%26%20AI%20Security%20in%202025" title="LinkedIn" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_facebook" href="https://www.addtoany.com/add_to/facebook?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2025%2F12%2Fthe-12-months-of-innovation-how-salt-security-helped-rewrite-api-ai-security-in-2025%2F&amp;linkname=The%2012%20Months%20of%20Innovation%3A%20How%20Salt%20Security%20Helped%20Rewrite%20API%20%26%20AI%20Security%20in%202025" title="Facebook" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_reddit" href="https://www.addtoany.com/add_to/reddit?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2025%2F12%2Fthe-12-months-of-innovation-how-salt-security-helped-rewrite-api-ai-security-in-2025%2F&amp;linkname=The%2012%20Months%20of%20Innovation%3A%20How%20Salt%20Security%20Helped%20Rewrite%20API%20%26%20AI%20Security%20in%202025" title="Reddit" rel="nofollow noopener" target="_blank"></a><a class="a2a_button_email" href="https://www.addtoany.com/add_to/email?linkurl=https%3A%2F%2Fsecurityboulevard.com%2F2025%2F12%2Fthe-12-months-of-innovation-how-salt-security-helped-rewrite-api-ai-security-in-2025%2F&amp;linkname=The%2012%20Months%20of%20Innovation%3A%20How%20Salt%20Security%20Helped%20Rewrite%20API%20%26%20AI%20Security%20in%202025" title="Email" rel="nofollow noopener" target="_blank"></a><a class="a2a_dd addtoany_share_save addtoany_share" href="https://www.addtoany.com/share"></a></div></div><p class="syndicated-attribution">*** This is a Security Bloggers Network syndicated blog from <a href="https://salt.security">Salt Security blog</a> authored by <a href="https://securityboulevard.com/author/0/" title="Read other posts by Eric Schwake">Eric Schwake</a>. Read the original post at: <a href="https://salt.security/blog/the-12-months-of-innovation-how-salt-security-helped-rewrite-api-ai-security-in-2025">https://salt.security/blog/the-12-months-of-innovation-how-salt-security-helped-rewrite-api-ai-security-in-2025</a> </p>