Much like the first wave of content including GraphQL as a module, there should more than likely be one for REST API security / best practices.
I think before moving on this we should compile a list of reputable resources to build lessons around.
Relevant Resources: