home.social

#waap — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #waap, aggregated by home.social.

fetched live
  1. API-безопасность 2026: почему защита требует нового подхода

    Ещё пять лет назад Gartner предсказывал, что эксплуатация уязвимостей API станет самым частым вектором взлома приложений и сервисов. Сегодня этот сценарий атак стал практически нормой. Из-за этого API превратились в полноценный бизнес-актив, к которому, по-хорошему, должны применяться те же требования по безопасности и надёжности, что и к любому другому продукту. Однако на практике с этим возникают проблемы. По данным Salt Security , большинство компаний за последний год сталкивались с инцидентами, связанными с безопасностью API. При этом сами интерфейсы продолжают быстро расти и усложняться , а защита за этим ростом не всегда успевает. В таких условиях даже корректные запросы могут приводить к утечкам данных или обходу ограничений. Особую тревогу вызывает рост ИИ-уязвимостей , где API выступают основным каналом взаимодействия — а значит, и потенциальной точкой атаки. В статье разберу актуальные техники и тактики атак на API и рассмотрю, какие практики стоит внедрять уже сейчас для защиты веб-приложений.

    habr.com/ru/companies/garda/ar

    #waf #waap #api #api_security

  2. API под прицелом: Три типа «трупов» (Shadow, Orphan, Zombie) и одна новая надежда

    Использование API помогает выстраивать подобные архитектуры, а некоторые команды даже практикуют API-first разработку (приложение разрабатывается сначала с использованием API, а уже потом покрывается Веб-интерфейсом). И, когда вокруг нас такое развитие, мы как безопасники, задаемся вопросом: а достаточно ли защищено приложение, использующее API? API Gateway: Первый претендент на защиту API При упоминании API одна из первых ассоциаций - API Gateway. Возникновение этого класса решений - логичный ответ на сложность поддержки разрастающегося количества эндпоинтов: системам нужна «единая точка входа», чтобы планировать маршруты, трансформировать протоколы (из JSON в gRPC и обратно) и вешать базовую авторизацию.

    habr.com/ru/companies/angarase

    #API #WAF #WAAP #Shadow_API #Безопасность_API #API_Gateway #Микросервисы #OpenAPI #AppSec #DevSecOps

  3. Any suggestions what I could use as a Web Application Firewall or WAAP, if possible free and open source? If not free then open source is still preferred... I want to expose some things from my k8s cluster..

    #waf #waap #k8s

  4. Any suggestions what I could use as a Web Application Firewall or WAAP, if possible free and open source? If not free then open source is still preferred... I want to expose some things from my k8s cluster..

    #waf #waap #k8s

  5. 🏔️ Great days at the Ergon Airlock Partner Event 2026 on the Stoos.

    Proud to receive the award 'Biggest Microgateway Deal 2025' for our success story with HIN - Health Info Net.

    Full story: vshn.ch/en/blog/vshn-wins-bigg

    #Airlock #Ergon #Microgateway #IdentitySecurity #ZeroTrust #WAAP #DevOps #CloudNative

  6. 🏔️ Great days at the Ergon Airlock Partner Event 2026 on the Stoos.

    Proud to receive the award 'Biggest Microgateway Deal 2025' for our success story with HIN - Health Info Net.

    Full story: vshn.ch/en/blog/vshn-wins-bigg

    #Airlock #Ergon #Microgateway #IdentitySecurity #ZeroTrust #WAAP #DevOps #CloudNative

  7. 🎉 Check Point Software Technologies has been named a #RepresentativeVendor in the 2025 Gartner® Market Guide for Web Application and API Protection (WAAP)!

    What defines a next-gen WAAP?

    📌 Prevention-first mindset
    📌 AI-driven detection
    📌 Cloud-native agility

    Explore how Check Point Software Technologies was recognized within the report.

    Don’t just react. Prevent.

    👉 Read more here: blog.checkpoint.com/securing-t

    #CloudGuard #CloudGuardWAF #WAAP #CheckPoint #ChillwithCloudGuard

  8. 🚀 Secure your Kubernetes workloads with ease!
    Discover how Airlock Microgateway on Servala delivers Kubernetes-native Web App and API Protection (WAAP) - fully managed, sovereign, and developer-friendly.
    Read the full story: servala.com/article/airlock-mi

    #Airlock #Microgateway #Kubernetes #APIsecurity #WAAP #Security #DevSecOps #CloudNative #SovereignCloud

  9. 🚀 Secure your Kubernetes workloads with ease!
    Discover how Airlock Microgateway on Servala delivers Kubernetes-native Web App and API Protection (WAAP) - fully managed, sovereign, and developer-friendly.
    Read the full story: servala.com/article/airlock-mi

    #Airlock #Microgateway #Kubernetes #APIsecurity #WAAP #Security #DevSecOps #CloudNative #SovereignCloud

  10. 🚀 New Brand Story from #RSAC2025: Runtime Protection at the New Digital Front Line

    At #RSAC Conference 2025, Sean Martin, CISSP sat down with Rupesh Chokshi, Senior Vice President and GM of Application Security at Akamai Technologies, to talk about how AI-driven applications and #APIs are reshaping the security landscape.

    🔐 Why are runtime attacks on APIs and #AI apps growing—and why is prevention alone no longer enough?

    Find out how Akamai is evolving its Web Application and API Protection (#WAAP) strategies to meet these emerging threats head-on.

    🎙️ Watch, listen, or read the full story here:
    👉 itspmagazine.com/their-stories

    #cybersecurity #infosec #appsec #apisecurity #technology #infosecurity

  11. 🚀 New Brand Story from #RSAC2025: Runtime Protection at the New Digital Front Line

    At #RSAC Conference 2025, Sean Martin, CISSP sat down with Rupesh Chokshi, Senior Vice President and GM of Application Security at Akamai Technologies, to talk about how AI-driven applications and #APIs are reshaping the security landscape.

    🔐 Why are runtime attacks on APIs and #AI apps growing—and why is prevention alone no longer enough?

    Find out how Akamai is evolving its Web Application and API Protection (#WAAP) strategies to meet these emerging threats head-on.

    🎙️ Watch, listen, or read the full story here:
    👉 itspmagazine.com/their-stories

    #cybersecurity #infosec #appsec #apisecurity #technology #infosecurity

  12. Использование машинного обучения для выявления скрытых угроз веб-безопасности

    Анализ большого объема логов ‒ сложный и длительный процесс, и обычные алгоритмы редко выявляют больше, чем система активной защиты. Поэтому логичным и перспективным решением становится применение машинного обучения. В этой статье рассмотрены варианты применения ML-моделей для анализа веб-угроз, когда сложные модели оправданы, а когда можно обойтись более простыми решениями без потери точности.

    habr.com/ru/companies/garda/ar

    #выявление_атак #машинное_обучение #ML #waf #waap

  13. Web Application and API Protection (WAAP): эволюция WAF (Web Application Firewall)

    WAAP (Web Application and API Protection) является брандмауэром веб-приложений следующего поколения WAF (Web Application Firewall) . Термин впервые начал использовать Gartner для описания защиты современных, постоянно меняющихся web-сервисов. Так как в мире CI/CD, динамики и API first компаний, функций традиционного WAF (Web Application Firewall) уже недостаточно. WAAP - это совокупность методов и технологий, которые используются для защиты веб-приложений и сервисов от атак и уязвимостей. WAAP включает в себя технологии, такие как WAF-NG, сканер уязвимостей, автоматическое обнаружение и блокирование атак 0-дня (в том числе с помощью виртуального патчинга), выявление аномалий с помощью технологий Machine Learning и смарт-капчи.

    habr.com/ru/companies/owasp/ar

    #WAAP #waf #web_application_firewall #защита_сайта #защита_api

  14. 💪 Empower your #SOC team to detect and respond to #ddos attacks effectively.

    Read our latest blog, which provides a brief guide to mastering traffic analysis techniques: bit.ly/3tRAnJi

    #ddosattacks #ddosprotection #ddosmitigation #ddostraffic #webapplications #apiapplications #apis #waap #ratelimiting #apptrana #indusface

  15. 💪 Empower your #SOC team to detect and respond to #ddos attacks effectively.

    Read our latest blog, which provides a brief guide to mastering traffic analysis techniques: bit.ly/3tRAnJi

    #ddosattacks #ddosprotection #ddosmitigation #ddostraffic #webapplications #apiapplications #apis #waap #ratelimiting #apptrana #indusface