Pop Goes the Stack

A developer wanted to control his robot vacuum with a PS5 controller. With Claude Code’s help, he reverse-engineered the protocol, pulled an auth token, and unintentionally gained “root-level” control over roughly 7,000 vacuums across 24 countries, including access to live camera feeds, microphones, floor maps, and location data. In this episode of Pop Goes the Stack, F5's Lori MacVittie and Joel Moses talk with product leader Shaul Moav about why that happened, what it says about API security in an AI era, and why “guardrails” won’t save you if the pipe is broken.

Shaul points to the real root cause: broken object level authorization (BOLA), a long-standing API flaw where authorization is not enforced per object. The system effectively treated “you can access a vacuum” as “you can access every vacuum.” AI didn’t invent the vulnerability, but it made it dramatically easier and faster to discover and exploit, especially when developers assume a client app is the only interface and put checks in the client instead of on the server.

The discussion highlights AI's staggering blast radius. With APIs, the worst case is often data exposure. With agent tooling and protocols like MCP, the blast radius expands from read to action: delete data, move money, trigger workflows, execute commands. Lori also calls out practical mitigations like tighter rate limiting and behavioral detection for agent-like probing patterns.

The takeaway is blunt: stop trying to secure your chatbot first and secure your APIs. Treat agents like untrusted third parties, enforce object-level authorization everywhere, and assume any “internal-only” endpoint is mappable once AI is involved. As Shaul notes, faster shipping via AI-assisted coding can also mean more security findings if teams don’t deliberately optimize for correctness.

Creators and Guests

Host
Joel Moses
Distinguished Engineer and VP, Strategic Engineer at F5, Joel has over 30 years of industry experience in cybersecurity and networking fields. He holds several US patents related to encryption technique.
Host
Lori MacVittie
Distinguished Engineer and Chief Evangelist at F5, Lori has more than 25 years of industry experience spanning application development, IT architecture, and network and systems' operation. She co-authored the CADD profile for ANSI NCITS 320-1998 and is a prolific author with books spanning security, cloud, and enterprise architecture.
Guest
Shaul Moav
F5 Director of Product Management
Producer
Tabitha R.R. Powell
Technical Thought Leadership Evangelist producing content that makes complex ideas clear and engaging.

What is Pop Goes the Stack?

Explore the evolving world of application delivery and security. Each episode will dive into technologies shaping the future of operations, analyze emerging trends, and discuss the impacts of innovations on the tech stack.

Lori MacVittie (00:05.99)
Welcome back to Pop Goes the Stack, where the status page says all systems are operational, but your pager says, that's adorable. I'm Lori MacVittie and let's compare official narratives to observable reality. We've got our co-host Joel Moses, who has read the article, thank goodness. Joel.

Joel Moses (00:27.26)
Yes, indeed.

Lori MacVittie
Yes. And today we're joined by Shaul Moav

Lori MacVittie (00:33.14)
who is a director of product management and he is raring to talk about today's topic, which is APIs, security, and AI. Because, as Joel will explain in just a moment, we're diving into an absolute pinnacle of human innovation and modern cloud architecture.

Joel Moses (00:55.93)
Yeah.

Lori MacVittie
Yeah, a guy accidentally became the supreme overlord of an army of what, 7,000 robot vacuums?

Joel Moses (01:04.75)
You know, I have always wanted my own droid army. I didn't know that I could get it through AI, but apparently that's how you do it. So a software developer decided that he had a DJI Romeo, which is a vacuum--it's much like, you know, a Roomba or something like that. There's lots of different ones on the market. And all he wanted to do is he wanted to control it using a PS5 controller. So he used Claude Code

Lori MacVittie
Valid.

Joel Moses
and he reverse engineered the underlying protocol that the mobile application spoke. He was able to extract his authentication token and he created custom script in order to connect to the server, but because of a problem with the API downstream he thought he was getting control over his vacuum, and instead he gained root-level dominion over 7,000 independent droids across 24 countries, which is

Lori MacVittie
Ha ha ha.

Joel Moses
pretty cool, honestly. A little frightening, but definitely pretty cool. And it not just for the purposes of movement, but also live camera feeds, active microphones, spatial floor maps, precise location data, a lot of information. And that information, of course, was part of an insecure, unmapped API that AI was helpful in helping him map. Now, this is something that probably would have been found over time. I would argue that probably AI found it faster. But at the root of this, Shaul, is something that's very old in the API space. And what is that?

Shaul Moav (02:38.406)
It's called broken object level authorization, or as professionals call it, BOLA. And actually it's a case where the authorization is not enforced, you know, for specific users. So in that case, our user was asking for, you know, to get authority or to get data of his own vacuum cleaner. But instead, what he got is the information and data of the entire fleet or like all registered vacuum cleaners. That's insane.

But that's as old as APIs exist. It's nothing new. So

Lori MacVittie (03:23.635)
It, yeah.

Shaul Moav
that's

Lori MacVittie
It is and you could, if you had been able to get access to the API, you could have done that yourself programmatically with a script you wrote. I mean a human

Joel Moses
Sure.

Lori MacVittie
being could have done this too. So AI made it faster, made it easier, but it didn't create the original problem. And you know, for people who don't understand broken object level authorization, consider that the robot is an object. And so there were 7,000 objects and it just said, "Well, you're authorized to, you know, touch a robot, so you must be able to touch all of them." And that's

Joel Moses
Yeah.

Lori MacVittie
really what's going on. And it's been on the OWASP Top 10 for well, I think as long as the OWASP Top Ten has existed

Joel Moses
That's right.

Lori MacVittie
for APIs. Yes.

Shaul Moav (04:12.823)
Correct.

Joel Moses
Yeah.

Shaul Moav
And back to the

Joel Moses (04:14.364)
So that's another

Shaul Moav
Yeah, go ahead.

Joel Moses
Yeah, I, it's another point in favor of, you know, making sure that when you are working with AI systems that these AI systems can very easily navigate and find things in an unmapped insecure API. And so these tools are exposing these, but these conditions exist in lots of different applications. Shaul, why is it so difficult to make sure that your authorizations to certain objects are mapped?

I mean, why is this even a problem? That sounds like a fairly basic step in creating an application.

Shaul Moav (04:52.681)
It's, to be frank, it is a basic thing. But the thing is that systems today are so complex and are composed of so many different layers that sometimes you as a developer you are just responsible for a specific layer. Let's say you are responsible for the API itself and somebody else is taking care of the client, or somebody else is taking care of the database.

And so in many, many cases, we see that there's a kind of a trust because me as the API owner, I trust the client to make or to do all the tests for me. And what happens is that the client would assume that, yeah, maybe it does it or maybe it doesn't, but users are in many cases more sophisticated.

Joel Moses
Mm-hmm

Shaul Moav
And in some cases, they would bypass the client itself. Therefore, they would go and go straight to the API and bypass all the potential checks that were written in the client side. That's one example. So the split of authority in large systems kind of make it more prone to errors or are open to mistakes. So yes, that's not a super complex issue as itself, but the thing is that we're discussing, you know, systems that are more complex and

Joel Moses (06:31.190)
Yeah.

Shaul Moav
that are composed of many, many different moving parts. And that's where most of the cases are

Joel Moses
Yeah.

Shaul Moav
tearing apart.

Joel Moses
Yeah.

Lori MacVittie (06:42.043)
It's really like single point of, right, we know about in architecture, single point of failure is bad. You want redundancy, you want as many different options as you can have. And it sounds like in security part of this problem is we assume a single point of enforcement or a single point where things are gonna get checked. And if you bypass that, it doesn't

Joel Moses (07:02.869)
Yeah.

Lori MacVittie
work. And, you know, we've got APIs on top of APIs. When you add agents, now you've got things like, oh MCP, here's another API thing that you can

Joel Moses
Yeah.

Lori MacVittie
add on top that's gonna make it worse.

Joel Moses (07:15.869)
Yeah, that's a good point. And in fact, if you decompose this compromise that occurred, this inadvertent compromise, it was because the application developers were assuming certain things and failing to see that the system could be used outside of their assumptions. So they thought, remember that this all started because he wanted to control the robot with his PS5 controller and not the mobile app.

The developer assumed that the mobile app was the only thing that would be used to access certain APIs. And so when it was able to when Claude Code was able to talk to the API directly, it discovered certain endpoints that allowed it to talk to the backing MQTT server or broker, which receives and transmits information via a series of messages to these robots. And that was not designed to be talked to directly. And the mobile app would never talk to it directly.

Lori MacVittie (08:11.869)
Ha ha ha.

Joel Moses
But it was there. And because it was there, it was mappable, because it was mappable, it was usable, and the broken object level authorization didn't occur at the application layer. It actually occurred back at the broker. And so I think Shaul's exactly right, complex systems, when you put them all together and you assume certain things, your assumptions will kill you every time.

Shaul Moav (08:36.175)
Yep,

Lori MacVittie (08:42.383)
It's really behavior.

Shaul Moav
I'll say one

Lori MacVittie (08:39.383)
It's

Shaul Moav
Yeah.

Lori MacVittie
behavior, right? You just describe that. It's about the behavior like a thing should never talk to this. That would be odd behavior, maybe we should flag that. And we don't have the security systems that, right, identify that quite yet to be able to raise a red flag when I wanna talk directly to things I shouldn't be talking to.

Shaul Moav
Yep.

Joel Moses (09:01.015)
So let's talk about the impact that this has on something that's also another concept in security, and that's the blast radius.

Lori MacVittie
Mm.

Joel Moses
So AI, of course, allows people to find broken object level authorization problems, without a lot of reverse engineering experience. They actually can tie to and understand the flow of protocols without having a lot of experience with even coding. But then you get to the point where maybe you want to use agentic AI, and agentic AI has the same capacity to map and understand, and then automate actions against say 7,000 vacuums

Lori MacVittie
Ha ha ha.

Joel Moses
that don't belong to you. So what does that say for the blast radius problem? First of all, Shaul, why don't you describe what a blast radius is in this context?

Shaul Moav (09:54.392)
So yeah, so blast radius is the level of exposure your system is prone to. And the thing is that blast radius, when you add it to AI and to agentic AI, it's shifting drastically. And here's why. Because when we spoke about APIs only what is the worst thing that could happen if I hacked your APIs? I would be able to exfiltrate some information. That's a danger at its own. That's a thing. All right? But what happens when you add MCP to that?

Well, that's a whole different story. And that's where the potential damage grows dramatically. Because MCP allows you not just to get information but to actually perform actions. So you might accidentally

Lori MacVittie (10:52.779)
Mm.

Shaul Moav
or not accidentally delete your database.

Lori MacVittie (10:56.182)
Ha ha ha, no.

Shaul Moav
Or you might accidentally, yeah, absolutely, yes. You might want to transfer some funds from wherever to wherever else.

Lori MacVittie
Yeah.

Shaul Moav
The potential is huge, and the blast radius, the potential of damage

Shaul Moav (11:12.858)
completely changes with the addition of MCP. And hey, MCP is just a nice way, a super easy way to communicate with APIs. Let's face it. That's what it is, right?

Joel Moses (11:25.97)
Mm-hmm.

Shaul Moav
So we're wrapping our APIs with a super easy way to communicate with, and we're giving some extra abilities like performing kind of stuff that I've just mentioned, and boom, your blast radius is now

Shaul Moav (11:41.221)
completely different from just the APIs. So I think that's what, you know, when we talk about the blast radius in the context of APIs and AI, that's where the shift is.

Lori MacVittie (11:54.943)
Yeah, it's and that's interesting because CRUD has become CRUDE. Right, we have to add execution on the end. Hey, it's a valid thing. It's a good

Joel Moses (12:02.745)
Ha ha ha, I like it. I like it.

Lori MacVittie
You like it. It is, right? It moves from create, read, update, delete, which most developers, you know, they write APIs to do that, but also guard against it. But we have to add execute on the end and consider, right, whether it's even, you know, useful to have

Joel Moses
Yeah.

Lori MacVittie
an API that might

Lori MacVittie (12:23.52)
execute or that somebody might execute, right, through it. So we have to pay more attention to the execute piece, I think, is a really good point.

Joel Moses (12:33.218)
Yeah. I think one thing that's increasing the blast radius is also the speed of operations that these AI systems can work at. It's one thing to run a script and have the script sequentially go through and manipulate or modify certain things, and that takes a while. AI is capable of doing lots of things in parallel and at extremely high speed, faster than someone can run a script.

And so the blast radius, of course, is part and parcel of a factor of the speed with which you can do these operations. The more you can do in a short period of time, the more you can do over a longer period of time. So the blast radius ends up looking like the size of the moon. The other thing is throwing AI at an unmapped and insecure API is a little bit like detonating a grenade inside of a small closet.

You think the blast radius is confined, but you don't realize there's a gas main behind the closet wall. Unmapped APIs and AI that's able to quickly iterate and develop against certain things, they can find things that you do not expect. And I think that a blast radius usually emanates from a lack of understanding of how the system actually fits together. We just talked about that.

And so what you think you are defended against you may not be adequately defended against. So, what are some of the things people can do about defending against API-level attacks? I mean, it strikes me that AI systems, you can put as much prompt injection protection as you want on them, but if what they're using is at the heart insecure, other APIs, then we're not done with those protections.

Shaul Moav (14:11.977)
Oh, absolutely. I would say, you know, all the people that are trying to secure the chatbot or secure, you know, add guardrails and prompts saying, okay, here's what you're allowed to do and here's what you're not. I would say forget about the chatbot. Secure your pipe. So make sure your APIs and the permissions you've granted to your, you know, internal AI agents and MCP service are in place.

So treat your AI agent like a third-party contractor. Okay? You can never trust your AI agent. But

Lori MacVittie (15:00.409)
Don't trust anyone.

Shaul Moav
and what you want to do is you want to make sure that your APIs provide the right level of security.

Shaul Moav (15:10.472)
That's what you want to secure. Because again, while with APIs it's a matter of whether, it's a one and zero, right? There's no way to misinterpret if somebody has a permission or not. While with an AI agent, that's a completely different story. It depends on how they interpret your instructions on what they're allowed to do and what they're not. So if you ask me, go back to the basics, secure your APIs.

Lori MacVittie (15:43.033)
Yeah, how they felt that day. I love the X-file strategy: trust no one! Like that should be the de-, that is zero trust. I think

Shaul Moav (15:52.423)
Yeah.

Lori MacVittie
one thing that people don't consider doing, that they could, and that helps against this, right? We know that AI is really fast. And it also tends to probe APIs really fast. Like it will just zip through multiple, right, endpoints and start asking questions. Implement some rate limiting

Lori MacVittie (16:13.686)
for those agents. You

Joel Moses
Sure.

Lori MacVittie
can detect it's an agent. So you can apply a little bit stricter rate limiting on it, going, "Hey, why did you just ask 400 questions? Like stop it, back off, not yet." You know, and just kind of, you know, keep an eye on how much they're probing and which systems they're probing. Because maybe that gives you a clue that you need to go look at that particular system or API and maybe comb through it, you know, with a very, very good security eye.

Shaul Moav (16:44.155)
I want to give another perspective to that. And that's a

Lori MacVittie (16:47.691)
Okay.

Shaul Moav
different perspective on the blast radius, if I may. And that's about vibe coding, right?

Lori MacVittie
Ha ha ha, ahhh.

Shaul Moav
So everyone is using AI coding assistants, right? Like Cursor and Copilot and whatever. And these are great. These are really, really great because they allow to ship, they allow developers to ship code four times faster than they would

Shaul Moav (17:13.148)
usually do. And that's fantastic, but that has a cost. And the cost is that I think of of I've read somewhere, you get ten times security findings in your code.

Joel Moses/Lori MacVittie
Mm.

Shaul Moav
The reason is that AI is built to please and to help you accomplish your targets as soon as it can. And if your target is ship code fast, then AI will optimize for that. So that adds to the blast radius, right? If you ship an unsecure or an incomplete secure code or a code that is less secure than the code that you would normally do as a developer, hmm. That adds

Joel Moses (18:06.616)
Yeah.

Shaul Moav
to the potential damage that your system can take.

Joel Moses (18:10.198)
And in the end analysis it might give you access to your own global bot army. Which, you know,

Lori MacVittie (18:16.097)
It could.

Joel Moses
who can complain about that, Lori? I mean really.

Lori MacVittie
It could and I'd love to talk more about that and the implications of what else you could control besides, you know, your vacuum cleaner, but we're really kinda out of time here. But so, you know, that's a wrap, I guess, and hit subscribe before your vacuum cleaner starts plotting against you in the corner. Yeah.