ThreatX Integrates with Cortex XSOAR by Palo Alto Networks

Posted by Gene Fay on Jul 7, 2020 3:53:56 PM

Today I am proud to announce the integration of the ThreatX WAAP with the Palo Alto Networks XSOAR platform. You can read the official announcement for more details here. This integration is exciting for me personally because it tackles one of the most important issues I see facing enterprise security teams regardless of size or industry. Virtually every organization needs to get more leverage out of their security tools, whether that means arming analysts with critical data or turning that data into automated responses. This integration lets organizations harness the power of the ThreatX’s web application + api protection + bog protection + DDoS attack mitigation (WAAP++) platform for such things as risk scores, entity details, and other insights and leverage that data across the enterprise so that teams can do more, faster. 

Read More

Topics: Web, Application & Hybrid Cloud Security, Company | News

Fighting the AppSec Fight: Don't sell products. Create partnerships.

Posted by Chris Brazdziunas on Mar 18, 2020 9:26:34 AM

It’s been a few weeks since we closed the book on another RSA conference. And as always, it was nice to catch up with old friends, meet new ones, and talk to many of the security professionals who are on the frontlines of AppSec every day.

However, after spending some time on the show floor, one thing really stood out for me: vendors were selling security products, and most attendees were looking for security partnerships.

Every vendor seemingly has a promise for why their technology, products, or features are better than their competitors. But ultimately, it falls to the customers to take a leap of faith, invest in a product, staff the product, and make it deliver on its promises. It is the customer that must do the heavy lifting and take on the risk.

Read More

Topics: Web, Application & Hybrid Cloud Security, Threat Intelligence

OWASP TOP 10: APIs Take Center Stage in Latest List of Priorities

Posted by Chris Brazdziunas on Feb 12, 2020 7:57:58 AM

OWASP recently released the first iteration of the API Security Top 10. Like the ubiquitous OWASP Top 10, the API Security Top 10 delivers a prioritized list of the most critical application security issues with a focus on the API side of applications. This is a critical new tool for AppSec teams that hones in on one of the fastest growing, yet chronically under-addressed aspects of security. In this blog, I’d like to offer you an overview of the API top 10 with comparisons to the OWASP top 10 for web applications.

Read More

Topics: Web, Application & Hybrid Cloud Security, Threat Intelligence

Better Security + More Efficient Ops with a Unified Approach to AppSec

Posted by Chris Brazdziunas on Aug 19, 2019 11:52:55 AM

As the demands of both modern applications and complex threat landscapes have continued to increase, many organizations have been forced to adopt an ever-growing list of new, specialized security tools in an attempt to keep pace. This often includes a mixture of WAFs, anti-bot tools, DDoS prevention, behavioral and analytics tools, intelligence feeds, and more. However, a fractured approach to security is rarely effective and almost never efficient. 

Read More

Topics: Web, Application & Hybrid Cloud Security

Why Security Teams Need to Virtual Patch

Posted by Andrew Useckas | CTO on Jul 8, 2019 10:28:31 AM

We live in a world where new application security vulnerabilities are discovered daily. Additionally, the advent of botnets and crypto currency mining has increased the attractiveness of targets. There are two major techniques utilized by attackers to find vulnerable applications en masse:

  1. Run scanners against large portions of the Internet to look for common exploits, such as SQL injection, Remote Command Execution, etc. Virtually any poorly coded web application can be vulnerable to these attacks.

  2. Follow the security feeds for newly discovered vulnerabilities, create exploits and launch them against every public instance of the application. Well known platforms like Wordpress and Drupal are especially susceptible to such an attack.

There is little debate that the best place to fix security issues is within the application code itself. However, that is not always feasible given the time that is required.

Read More

Topics: Web, Application & Hybrid Cloud Security

2019 Application Security Priorities - Stats & Trends

Posted by Chris Brazdziunas on Jun 13, 2019 8:45:04 AM

Application security never fails to keep us on our toes. Between the continuous evolution of application frameworks and integrations, and the advancement of human and automated attackers, security teams must always be braced for change and new challenges. On a similar vein, if the trends from 2018 continue, web application attacks will remain the most successful hacked area of the enterprise. In fact, over 60% of actual breaches occurred through web applications.*

Read More

Topics: Web, Application & Hybrid Cloud Security

Flying Blind Into the Threat Visibility Gap

Posted by David Geer on Jun 4, 2019 6:57:00 AM

Data, data everywhere and yet there’s very little insight to inform the business on the true nature and severity of cyber threats. That’s the story at most organizations where traditional Web Application Firewalls (WAFs) fail to bring into focus the visibility into the mounting expanse of security data.

Read More

Topics: Web, Application & Hybrid Cloud Security

How and Why to Use APIs to Strengthen Your AppSec Strategy

Posted by Kelly Brazil | VP of Sales Engineering on May 13, 2019 12:15:00 PM

APIs are at the heart of modern applications and have quickly become a favorite target of attackers. And for good reason - they expose a wealth of functionality and attack surface that is often poorly defended. In our previous article we introduced the key building blocks of API security that can help ensure your APIs get the same level of protection as the web front-end of your application.

Read More

Topics: Web, Application & Hybrid Cloud Security

ThreatX Labs - Blog

Arm yourself with information and insights on the latest cybersecurity trends to defend against today's most advanced cyber criminals with articles from the leader in SaaS-based web application firewall solutions.

Subscribe Here!

Recent Posts

Follow Me