Back to blog

Segui e iscriviti

Sicurezza

Page 13 of 19

With the launch of edge deployment, the Fastly Next-Gen WAF is first in the industry to offer a fully unified web app and API security solutionSean Leach
The Fastly Next-Gen WAF (powered by Signal Sciences) protects apps wherever they live: on-premises, in containers, in the cloud, and — as of today — at the edge. This makes it the industry’s first and only unified WAF.
Sicurezza
An illustration of a browser window with a large magnifying glass over the left portion of the screen
Inside Fastly: a look at our vulnerability remediation processSandra Escandor-O’Keefe
In this post, we present a look at our vulnerability remediation and engineering team and how they were able to roll out a recent fix for a QUIC/H2O vulnerability in under two weeks.
IngegneriaSicurezza
Open redirects: abuse & recs [Ex.] | FastlyTeam di ricerca sulla sicurezza di Fastly
Open URL redirection is a class of web app security problems that make it easier for attackers to direct users to malicious resources. Here are some examples of how they do it and what you can do to prevent it.
Sicurezza
How to Secure your GraphQLTeam di ricerca sulla sicurezza di Fastly, Simran Khalsa
There are many benefits to adopting GraphQL, but its security implications are less understood. In this post, we’ll explore those implications and offer guidance on which defaults and controls can support a safer GraphQL implementation.
IngegneriaSicurezza
Fastly's 2021 in ReviewDavid Belson
In this post, we’ll take a look back at the past year through the eyes of our edge cloud network to explore what we saw across new protocol adoption, security initiatives, network growth, and more.
Approfondimenti del settoreSicurezza+3
Il framework di efficacia WAF misura l’efficacia del WAF | FastlyTeam di ricerca sulla sicurezza di Fastly, Simran Khalsa, +1
Il nostro nuovo framework di efficacia WAF fornisce un modo standardizzato per misurare l’efficacia delle capacità di rilevamento di un web application firewall attraverso verifica e convalida continue. Ecco come funziona.
IngegneriaSicurezza
Log4Shell attacks (CVE-2021-44228) insights | FastlyTeam di ricerca sulla sicurezza di Fastly, Xavier Stevens, +1
We’re sharing our latest data and new insights into the Log4j/Log4Shell vulnerability (CVE-2021-44228 + CVE-2021-45046) in this post in order to help the engineering community cope with the situation. We also share our guidance around testing your environment against many of the new obfuscation methods that have been seen.
Approfondimenti del settoreSicurezza
Log4Shell exploit found in Log4j | FastlyTeam di ricerca sulla sicurezza di Fastly, Xavier Stevens, +1
CVE-2021-44228 is a Remote Code Execution vulnerability in the Apache Log4j library being actively exploited. We provide our observations into the exploit and a summary of its impact.
SicurezzaIngegneria
30 Years of Web: Building for TomorrowLee Chen
The web’s infrastructure — and the applications we build on it — must constantly evolve to meet the ever-transforming expectations of modern and future end users. We’ve gathered five lessons today’s builders can use to drive the next three decades of the web.
Approfondimenti del settoreIngegneria+1
Grinch bots penalized w/ enriched security data & our edge cloud platform Brooks Cunningham, Solution Architect Enterprise di Fastly
In this post, we’ll show how you can use information from an origin response to add an abuse IP address to our penalty box. We've been touting the promise of security at the edge, and this is just one example of what it can do.
SicurezzaIngegneria+1
30 Years of Web: Securing TomorrowMike Johnson
To create more secure and resilient web experiences, we must design, build, and execute applications with security top of mind, and consider how the lessons of the past 30 years inform how we think about the future of security.
Approfondimenti del settoreSicurezza
Use After Free flaw in Lucet-runtimeTeam di ricerca sulla sicurezza di Fastly, The Fastly Security Technical Account Management Team
On November 11th 2021, Fastly Engineering received alerts related to segmentation faults on Compute@Edge. A Fastly investigation into CVE-2021-43790, a bug in Lucet, a dependency of Compute@Edge, is disclosed in a recent Bytecode Alliance security advisory. Fastly investigations have not identified additional impact outside of the single case disclosed in this advisory. It's our goal in this Fastly Security Advisory to illustrate our knowledge about the bug discovered and the actions we have taken to prevent further possible impact to our customers.
Sicurezza
30 Years of Web: Future-Ready AppsJana Iyengar
Many websites today are really applications, and we should be building them as such. To do that, we need application architectures and networks that are capable of supporting fast, secure, and scalable user experiences. We must embrace a more dynamic mindset in how we approach web development and consider the tools we need to get there.
Approfondimenti del settoreIngegneria+2
30 Years of Web: Future DemandsDavin Camara
As we look back to celebrate the 30th anniversary of the website, it’s also worth thinking about the next 30 years. There are a couple of areas where we — as engineers, developers, and builders in general — can champion innovation, mainly around architecture and security.
Approfondimenti del settoreIngegneria+4
Subresource monitoring with ComputeTeam di ricerca sulla sicurezza di Fastly
Compute, our serverless compute environment, can be used to solve headaches dealing with attackers looking to modify and manipulate resources. In this post, we tell you how.
SicurezzaCompute
Preventing SSRF: Apache CVE-2021-40438 | FastlyTeam di ricerca sulla sicurezza di Fastly
Our Security Research Team provides guidance on how to address CVE-2021-40438, a vulnerability in Apache HTTP Server version 2.4.48 and earlier, by patching impacted version(s) and enabling a new templated rule to prevent exploitation.
IngegneriaSicurezza
Protect against Apache vulnerability | FastlyTeam di ricerca sulla sicurezza di Fastly
The recent Apache HTTP Server vulnerability (CVE-2021-41773) is reportedly being exploited in the wild. Fastly already detects this vulnerability, but our next-gen WAF customers can also create a rule to block exploitation.
Sicurezza
DevOps Practices Primed to Combat Threats | FastlyBrendon Macaraeg
Organizations implementing DevOps practices often sacrifice security for speed, exposing them to potential threats. In reality though, many DevOps practices are already primed for security initiatives.
SicurezzaDevOps
The Importance of Securing Applications & Security in DevOps Julie Rockett
Forrester’s 2021 Annual State of Application Security Report stresses the need for updated application security tools that can be easily integrated into development plans and architecture.
SicurezzaDevOps
Integrating Security in DevOpsBrendon Macaraeg
Your organization may have operational and cultural roadblocks to overcome when it comes to integrating security and DevOps. These tips can help you ensure a smooth transition to more secure DevOps.
DevOpsSicurezza