Back to blog

Segui e iscriviti

Sicurezza

Page 14 of 19

Legacy vs next-gen WAF: the differences matterBrendon Macaraeg
Compare legacy versus next-gen WAFs to see what sets them apart. Determine if your company can benefit from a next-gen approach.
Sicurezza
Atlassian Confluence OGNL Injection Vulnerability Protection | FastlyTeam di ricerca sulla sicurezza di Fastly, Xavier Stevens, +1
Our Security Research Team has built and deployed a rule to help protect customers of our next-gen WAF against the recently announced Confluence Server OGNL injection vulnerability, CVE-2021-26084.
Sicurezza
6 essential features of modern web app & API security tools Julie Rockett
Modern applications need modern security tools that include flexible deployment, DevOps support, and strong API protection. Here are the six most important characteristics of modern web app and API security tools.
Sicurezza
Legacy security tools: peace of mind at what price? Julie Rockett
Companies using an average of 11 web application and API security tools should be able to rest easy, but the vast majority of them report successful attacks are still getting through. These legacy tools aren’t cutting it.
Approfondimenti del settoreSicurezza
Fastly/Signal Sciences: one year update | FastlyDana Wolf
When we acquired Signal Sciences, we put a stake in the ground as a company that cares about the complete delivery path and making it not just resilient and performant, but inherently secure as well. Here’s our update on that mission.
Notizie aziendaliProdotto+2
Introducing right-sized web app and API protection packages Brendon Macaraeg
Today, we launched Fastly Secure packages, a unified web app and API security solution that provides “right-sized” protection for any organization at a spend level that works for a variety of budgets.
ProdottoSicurezza
4 Steps to Centralized Security ToolingSean Leach
Here are four repeatable steps that will help you pay down your security technical debt, make your apps and APIs more secure, and move you toward consolidated security tooling.
Approfondimenti del settoreSicurezza
Why don’t your security tools work anymore?Sean Leach
As the internet landscape gets more complex, more API driven, and more distributed, many security and IT professionals are left wondering — why aren’t the security tools that were good enough a few years ago good enough now?
Approfondimenti del settoreSicurezza
0-100 mph: Boosting App SecurityThe Fastly Collective
How to accelerate your WAF visibility from 0 to 100MPH
Sicurezza
New research shows security tooling is at a tipping pointBrendon Macaraeg
We released a new report today in partnership with ESG Research that reveals some fascinating insights into the state of web application security tooling.
Sicurezza
Request enrichment helps identify user data Brooks Cunningham, Solution Architect Enterprise di Fastly
Requests passing through Fastly can be transformed in many ways. In this example, we’ll show you how to use enriched requests and our next-gen WAF to help you make more informed security decisions.
ProdottoSicurezza
Introducing Response Security ServiceKevin Rollinson
Our new Response Security Service provides direct, 24/7 access to our Customer Security Operations Center to help you prepare for and respond when you suspect an attack.
Sicurezza
How to recognize and repel four high-risk attack typesBrendon Macaraeg
After years of helping protect companies across a variety of industries, we’ve come to recognize four common risk attack types. Here’s how they work and how to counter them.
Sicurezza
4 Ways Legacy WAF Fails to Protect Your AppsLiz Hurder
The legacy WAF isn’t ubiquitous because it’s the perfect technology. Its success comes down to being mandated, despite four ways it often fails.
Sicurezza
Suggestive signals: how to tell good bot traffic from badBrendon Macaraeg
While some bots are benign search engine crawlers or website health monitors, others are on the prowl with nefarious intent, looking to execute account takeovers and compromise APIs. In this post, we’ll look at how to tell them apart in order to allow the good bots and block the bad ones.
Sicurezza
Cranelift vetted for secure sandboxing in Compute@Edge | FastlyPat Hickey, Chris Fallin, +1
Alongside the Bytecode Alliance, Fastly’s WebAssembly team recently led a rigorous security assessment of Cranelift, an open-source, next-generation code generator for use in WebAssembly to provide sandbox security functionality.
Approfondimenti del settoreSicurezza+2
Answers to your top Kubernetes security questionsBrendon Macaraeg
As Kubernetes has become widespread for container orchestration needs, it’s natural for security questions to arise. Here are answers to the Kubernetes questions we hear most often.
Sicurezza
Memory access due to code generation flaw in Cranelift moduleThe Fastly Security Technical Account Management Team, Team di ricerca sulla sicurezza di Fastly
The bug identified in the Cranelift x64 backend performs a sign-extend instead of a zero-extend on a value loaded from the stack, when the register allocator reloads a spilled integer value narrower than 64 bits. This interacts poorly with another optimization: the instruction selector elides a 32-to-64-bit zero-extend operator when we know that an instruction producing a 32-bit value actually zeros the upper 32 bits of its destination register. Hence, the x64 compiler relies on these zeroed bits, but the type of the value is still i32, and the spill/reload reconstitutes those bits as the sign extension of the i32’s MSB.
Sicurezza
Memory flaw in Cranelift moduleTeam di ricerca sulla sicurezza di Fastly
The bug identified in the Cranelift x64 backend performs a sign-extend instead of a zero-extend on a value loaded from the stack, when the register allocator reloads a spilled integer value narrower than 64 bits. This interacts poorly with another optimization: the instruction selector elides a 32-to-64-bit zero-extend operator when we know that an instruction producing a 32-bit value actually zeros the upper 32 bits of its destination register. Hence, the x64 compiler relies on these zeroed bits, but the type of the value is still i32, and the spill/reload reconstitutes those bits as the sign extension of the i32’s MSB.
Sicurezza
Prevent Wasm Compiler Bugs Early | Fastlyiximeow, Chris Fallin
We recently discovered a compiler bug in part of the WebAssembly compiler that we use for Compute@Edge, that could have allowed a WebAssembly module to access memory outside of its sandboxed heap. But because of the people, processes, and tools we have in place, the bug was caught and patched on our infrastructure before it was exploited.
SicurezzaWebAssembly