Back to blog

Follow and Subscribe

Team di ricerca sulla sicurezza di Fastly

Team di ricerca sulla sicurezza di Fastly, Fastly

Il team di ricerca sulla sicurezza di Fastly si occupa di garantire che i nostri clienti dispongano degli strumenti e dei dati necessari per mantenere sicuri i propri sistemi. Analizza e, in ultima analisi, contribuisce a prevenire gli attacchi su scala Fastly. Il team è composto da un gruppo di esperti di sicurezza che lavorano dietro le quinte per aiutarti a rimanere all'avanguardia in un panorama della sicurezza in continua evoluzione.

Page 1 of 3

  • React2Shell continua: cosa sapere e cosa fare riguardo ai 2 CVE più recenti

    Team di ricerca sulla sicurezza di Fastly

    Sulla scia dei CVE di gravità critica di React2Shell, l'11 dicembre sono stati annunciati due nuovi CVE che sfruttano componenti simili di Next.js e React. Scopri di più su questi nuovi CVE.

    Sicurezza
    Approfondimenti del settore
  • AI Bots in Q2 2025: Trends from Fastly's Threat Insights Report

    Matthew Mathur, David King, + 1 more

    Fastly's Q2 2025 Threat Insights Report uncovers how Meta, OpenAI, and others are shaping web traffic and what organizations need to do to stay in control.

    Sicurezza
    Approfondimenti del settore
  • ToolShell Remote Code Execution in Microsoft SharePoint: CVE-2025-53770 & CVE-2025-53771

    Simran Khalsa, Matthew Mathur, + 1 more

    Microsoft revealed two critical vulnerabilities, CVE-2025-53771 and CVE-2025-53770, actively exploited to compromise SharePoint servers.

    Sicurezza
  • OS Command Injection Explained

    Team di ricerca sulla sicurezza di Fastly, Matthew Mathur

    In this blog, we'll explore the web application vulnerability, OS Command Injection, and how to prevent it.

    Sicurezza
    TLS configuration icon
  • CVE-2025-29927: Authorization Bypass in Next.js

    Matthew Mathur, Team di ricerca sulla sicurezza di Fastly

    A critical Next.js Vulnerability (CVE-2025-29927) lets attackers bypass authorization. Protect your applications now.

    Sicurezza
  • DDoS in February

    Arun Kumar, David King, + 1 more

    Fastly's February 2025 DDoS report reveals a 285% month-over-month surge in DDoS attacks. Learn about key trends, targeted industries, and actionable security guidance.

    Sicurezza
    Approfondimenti del settore
  • DDoS in January

    Arun Kumar, David King, + 1 more

    Stay informed with Fastly's monthly DDoS report, highlighting a 14.5% rise in attacks. Utilize our data-driven insights to bolster your application's security.

    Sicurezza
    Approfondimenti del settore
  • DDoS in December

    Simran Khalsa, David King, + 1 more

    Discover the latest trends and actionable insights on application DDoS attacks in December 2024. Strengthen your security with our expert analysis and guidance.

    Sicurezza
    Approfondimenti del settore
  • Back to Basics of Automated Attacks: Account Takeover

    Arun Kumar, Team di ricerca sulla sicurezza di Fastly

    Explore account takeover attacks and mitigations including modern authentication with 2FA/passkeys, and anti-bot measures to enhance account security.

    Sicurezza
  • Detection as Code with Fastly's WAF Simulator

    Simran Khalsa, Team di ricerca sulla sicurezza di Fastly

    Being able to test and validate rule behavior is critical to a maintainable WAF. With our WAF Simulator, you can validate rules in a safe simulation environment.

    DevOps
    + 3 more
  • Active exploitation of unauthenticated stored XSS vulnerabilities in WordPress Plugins

    Team di ricerca sulla sicurezza di Fastly, Simran Khalsa, + 2 more

    We have observed active exploitation attempts targeting three high-severity CVEs: CVE-2024-2194, CVE-2023-6961, and CVE-2023-40000.

    Sicurezza
    Approfondimenti del settore
  • How to Protect Against Credential Stuffing

    Arun Kumar, Team di ricerca sulla sicurezza di Fastly

    In this post, we will discuss a low latency approach to detect these attacks by co-locating the password hashes in a KV Store, along with Compute on Fastly’s edge.

    Compute
    + 3 more
  • Cyber 5 Threat Insights

    Simran Khalsa, Charlie Bricknell, + 1 more

    To gain a broader understanding of the threat landscape during "Cyber 5" weekend, we analyzed attack activities with a particular focus on commerce sites.

    Approfondimenti del settore
    + 2 more
    An illustration of a yellow, shining shield with a cracking gray shield peeling off of it
  • WAF Simulator: Transforming DevSecOps Workflows

    Team di ricerca sulla sicurezza di Fastly, Simran Khalsa

    We're excited to announce Fastly's new WAF Simulator, which simplifies the testing process and provides the following key benefits.

    DevOps
    + 2 more
  • Patch that Vuln! Identify, Triage, and Qualify CVEs

    Team di ricerca sulla sicurezza di Fastly, Simran Khalsa

    Vulnerabilities are an unfortunate inevitability. However, when using a WAF there are options for your security teams while waiting for a patch.

    Sicurezza
    + 2 more
  • CVE-2023-30534: Insecure Deserialization in Cacti prior to 1.2.25

    Team di ricerca sulla sicurezza di Fastly, Matthew Mathur

    We have discovered two instances of insecure deserialization in Cacti versions prior to 1.2.25, tracked as CVE-2023-30534.

    Sicurezza
  • Back to Basics: Directory Traversal

    Team di ricerca sulla sicurezza di Fastly, Matthew Mathur

    In this post, we'll explore the application vulnerability directory traversal. What is it and how can you protect your apps from it?

    Sicurezza
  • Network Effect Threat Report: Uncovering the power of collective threat intelligence

    Team di ricerca sulla sicurezza di Fastly, Simran Khalsa, + 3 more

    Announcing the Network Effect Threat Report, Fastly’s threat intelligence report with insights based on unique data from April to June of 2023

    Sicurezza
    + 2 more
  • CVE-2023-34362: Progress MOVEit Transfer SQL Injection Vulnerability

    Team di ricerca sulla sicurezza di Fastly, Simran Khalsa, + 3 more

    What you need to know about CVE-2023-34362: Progress MOVEit Transfer SQL Injection Vulnerability

    Sicurezza
  • Command Injection CVE-2021-25296: A Deep Dive

    Team di ricerca sulla sicurezza di Fastly, Matthew Mathur

    NagiosXI versions 5.5.6 to 5.7.5 are vulnerable to three different instances of command injection.

    Sicurezza
    Approfondimenti del settore