Back to blog

Segui e iscriviti

Team di ricerca sulla sicurezza di Fastly

Team di ricerca sulla sicurezza di Fastly

Team di ricerca sulla sicurezza di Fastly, Fastly

Il team di ricerca sulla sicurezza di Fastly si occupa di garantire che i nostri clienti dispongano degli strumenti e dei dati necessari per mantenere sicuri i propri sistemi. Analizza e, in ultima analisi, contribuisce a prevenire gli attacchi su scala Fastly. Il team è composto da un gruppo di esperti di sicurezza che lavorano dietro le quinte per aiutarti a rimanere all'avanguardia in un panorama della sicurezza in continua evoluzione.

Page 1 of 3

What is Style Smuggler (CVE-2026-75650)?Matthew Mathur, Team di ricerca sulla sicurezza di Fastly
CVE-2026-75650 (StyleSmuggler) is a critical SSTI being actively exploited in ecommerce platforms. Learn what it is and how Fastly customers can stay protected.
Sicurezza
CVE-2026-82329: JFrog Artifactory Authentication Bypass Exploitation ActivitySimran Khalsa, Team di ricerca sulla sicurezza di Fastly
Attacks targeting JFrog Artifactory (CVE-2026-82329) exploded in 72 hours. Fastly threat intelligence breaks down the mass scanning surge—and how our virtual patch protects you today.
An illustration of a yellow, shining shield with a cracking gray shield peeling off of it
Che cos'è CVE-2026-66066? Proteggere l'app Rails dall'RCE in Active StorageMatthew Mathur, Team di ricerca sulla sicurezza di Fastly
Scopri di più su CVE-2026-66066: una vulnerabilità di lettura arbitraria di file in Active Storage di Rails. Comprendi i rischi e proteggi il tuo ambiente con la nostra patch virtuale.
Sicurezza
Che cos'è CVE-2026-23869? Un allarme di sicurezza di React Server ComponentsMatthew Mathur, Team di ricerca sulla sicurezza di Fastly
CVE-2026-23869: vulnerabilità ad alta gravità Denial of service nei React Server Components. Scopri gli impatti, le versioni interessate e ottieni protezione immediata con una patch virtuale.
SicurezzaApprofondimenti del settore
React2Shell continua: cosa sapere e cosa fare riguardo ai 2 CVE più recentiTeam di ricerca sulla sicurezza di Fastly
Sulla scia dei CVE di gravità critica di React2Shell, l'11 dicembre sono stati annunciati due nuovi CVE che sfruttano componenti simili di Next.js e React. Scopri di più su questi nuovi CVE.
SicurezzaApprofondimenti del settore
AI Bots in Q2 2025: Trends from Fastly's Threat Insights ReportMatthew Mathur, David King, +1
Fastly's Q2 2025 Threat Insights Report uncovers how Meta, OpenAI, and others are shaping web traffic and what organizations need to do to stay in control.
SicurezzaApprofondimenti del settore+1
ToolShell Remote Code Execution in Microsoft SharePoint: CVE-2025-53770 & CVE-2025-53771Simran Khalsa, Matthew Mathur, +1
Microsoft revealed two critical vulnerabilities, CVE-2025-53771 and CVE-2025-53770, actively exploited to compromise SharePoint servers.
Sicurezza
TLS configuration icon
OS Command Injection ExplainedMatthew Mathur, Team di ricerca sulla sicurezza di Fastly
In this blog, we'll explore the web application vulnerability, OS Command Injection, and how to prevent it.
Sicurezza
CVE-2025-29927: Authorization Bypass in Next.jsMatthew Mathur, Team di ricerca sulla sicurezza di Fastly
A critical Next.js Vulnerability (CVE-2025-29927) lets attackers bypass authorization. Protect your applications now.
Sicurezza
DDoS in FebruaryArun Kumar, David King, +1
Fastly's February 2025 DDoS report reveals a 285% month-over-month surge in DDoS attacks. Learn about key trends, targeted industries, and actionable security guidance.
SicurezzaApprofondimenti del settore
DDoS in JanuaryArun Kumar, David King, +1
Stay informed with Fastly's monthly DDoS report, highlighting a 14.5% rise in attacks. Utilize our data-driven insights to bolster your application's security.
SicurezzaApprofondimenti del settore
DDoS in DecemberSimran Khalsa, David King, +1
Discover the latest trends and actionable insights on application DDoS attacks in December 2024. Strengthen your security with our expert analysis and guidance.
SicurezzaApprofondimenti del settore
Back to Basics of Automated Attacks: Account TakeoverArun Kumar, Team di ricerca sulla sicurezza di Fastly
Explore account takeover attacks and mitigations including modern authentication with 2FA/passkeys, and anti-bot measures to enhance account security.
Sicurezza
Detection as Code with Fastly's WAF SimulatorSimran Khalsa, Team di ricerca sulla sicurezza di Fastly
Being able to test and validate rule behavior is critical to a maintainable WAF. With our WAF Simulator, you can validate rules in a safe simulation environment.
DevOpsIngegneria+2
Active exploitation of unauthenticated stored XSS vulnerabilities in WordPress PluginsTeam di ricerca sulla sicurezza di Fastly, Simran Khalsa, +2
We have observed active exploitation attempts targeting three high-severity CVEs: CVE-2024-2194, CVE-2023-6961, and CVE-2023-40000.
SicurezzaApprofondimenti del settore
How to Protect Against Credential Stuffing Arun Kumar, Team di ricerca sulla sicurezza di Fastly
In this post, we will discuss a low latency approach to detect these attacks by co-locating the password hashes in a KV Store, along with Compute on Fastly’s edge.
ComputeEdge network+2
An illustration of a yellow, shining shield with a cracking gray shield peeling off of it
Cyber 5 Threat InsightsSimran Khalsa, Charlie Bricknell, +1
To gain a broader understanding of the threat landscape during "Cyber 5" weekend, we analyzed attack activities with a particular focus on commerce sites.
Approfondimenti del settoreSicurezza+1
WAF Simulator: Transforming DevSecOps WorkflowsTeam di ricerca sulla sicurezza di Fastly, Simran Khalsa
We're excited to announce Fastly's new WAF Simulator, which simplifies the testing process and provides the following key benefits.
DevOpsIngegneria+1
Patch that Vuln! Identify, Triage, and Qualify CVEsTeam di ricerca sulla sicurezza di Fastly, Simran Khalsa
Vulnerabilities are an unfortunate inevitability. However, when using a WAF there are options for your security teams while waiting for a patch.
SicurezzaDevOps+1
CVE-2023-30534: Insecure Deserialization in Cacti prior to 1.2.25Team di ricerca sulla sicurezza di Fastly, Matthew Mathur
We have discovered two instances of insecure deserialization in Cacti versions prior to 1.2.25, tracked as CVE-2023-30534.
Sicurezza