< ciso
brief />
Tag Banner

All news with #web application firewall tag

33 articles

Adaptive AI-driven WAF testing and lessons

🛡️ Cloudflare evaluated how frontier LLMs can act as adaptive attackers against a WAF by building a tester that iterates payload encodings and delivery methods, observing HTTP responses to guide next moves. The tests ran against an authorized staging environment across 45 scenarios and six attack categories, producing 1,107 attempts that were human-triaged into 49 actionable findings and 558 blocked requests. Findings led to rule and normalization changes in the Managed Ruleset and produced practical deployment guidance to strengthen layered defenses.
read more →

Attackers Bypass WAFs to Exploit Oracle PeopleSoft

🛡️ Google warns of renewed mass exploitation of a critical Oracle PeopleSoft flaw (CVE-2026-35273, CVSS 9.8) by activity linked to ShinyHunters/UNC6240. The campaign weaponizes a modified exploit that URL-encodes the character "P" to bypass WAF rules, targeting multiple sectors globally and deploying web shells, trojanized installers, and backdoors. Affected organizations are urged to apply patches, disable or remove the PSEMHUB component, inspect logs and web directories, rotate credentials, and hunt for signs of data exfiltration and persistence.
read more →

ShinyHunters renews PeopleSoft exploit campaign

🔍 Mandiant and Google Threat Intelligence Group (GTIG) report that UNC6240 (ShinyHunters) resumed mass exploitation of CVE-2026-35273 against Oracle PeopleSoft by URL-encoding the vulnerable /PSEMHUB/ path to bypass WAF rules. The actor deployed web shells and a trojanized binary (Ple64.exe) loading the SIDEEYE backdoor, expanding targeting across education, technology, healthcare, government and more. Immediate patching, WAF normalization, and mitigation guidance are recommended.
read more →

WordPress Comment2Shell vulnerability patched

🛡️ WordPress fixed a critical flaw, CVE-2026-93485 dubbed Comment2Shell, on September 17 in version 7.1.1 after a researcher showed how a crafted comment could plant a hidden script that executes when a page is viewed. The bug allowed that script to act with the viewer's privileges and, if an administrator viewed the page, to leverage the admin session to upload a plugin web shell. Site owners are urged to update immediately or temporarily disable comments and consider WAF or security plugin mitigations.
read more →

AWS WAF adds pre-parse and new text transforms

🔒 Today, AWS WAF adds pre-parse text transformations for query arguments and ten new text transformations for use in any rule statement. These capabilities help normalize request content so that AWS WAF inspects requests the same way your application interprets them. New pre-parse options close HTTP parameter pollution and parser-differential evasion gaps, while new transforms include Uppercase, Trim, SHA256, and OS- and JavaScript-aware decoders.
read more →

AWS Shield Advanced adopts Anti‑DDoS WAF rule group

🛡️ In June 2025 AWS introduced the AWS WAF Anti‑DDoS managed rule group to protect application‑layer (L7) traffic. Starting July 27, 2026, Shield Advanced will add this rule group to eligible web ACLs in Count mode and eventually replace Shield’s existing L7 automatic mitigation by January 1, 2027. The rollout includes a free evaluation period, configurable sensitivities, new Challenge actions, reduced WCU usage, and a dedicated dashboard and metrics for observability.
read more →

Critical WordPress REST Batch API RCE Patch Urged

⚠️ Security researchers disclosed a pre-authentication remote code execution flaw in WordPress’ built-in REST Batch API, tracked as wp2shell. The bug allows attackers to execute arbitrary code on default WordPress installs without plugins or authentication by exploiting an indexing mismatch in the batch/v1 endpoint. Affected versions include 6.9.0–6.9.4 and 7.0.0–7.0.1; fixes were released in 6.9.5, 7.0.2 and 6.8.6. Administrators are urged to patch immediately or block the REST Batch endpoints at the web server or WAF and inventory all WordPress instances.
read more →

Australia alerts on global CMS exploitation campaign

⚠️ The Australian Cyber Security Centre (ACSC) warned of a global campaign exploiting vulnerabilities in multiple content management systems and plugins, with many Australian small and medium businesses affected. Threat actors are deploying webshells to maintain persistence, steal credentials, and escalate access. The campaign targets several CMS platforms and specific plugins, and the ACSC cautions that AI may be used to accelerate attacks. Administrators are urged to apply patches, remove unused components, and tighten web-server protections.
read more →

Protect GenAI Chatbots with Check Point WAF

🛡️ Check Point explains why GenAI chatbots create new security risks by acting as a front door to internal systems and data. The post highlights real incidents—prompt injection, data exposure, and misleading responses—that demonstrate legal, financial, and reputational impacts. It describes how Check Point WAF extends unified application and API security into the conversational layer to detect and block malicious prompts, prevent data leaks, and control unsafe outputs.
read more →

Google Cloud Fraud Defense: Evolution of reCAPTCHA

🛡️ Google Cloud has launched Fraud Defense, a trust platform that advances reCAPTCHA to address risks from autonomous AI agents as well as traditional bots and human fraud. The offering includes agentic activity measurement, an agentic policy engine for granular controls across the customer journey, and an AI-resistant QR code challenge to request human presence when needed. It integrates industry standards such as Web Bot Auth and SPIFEE and leverages Google’s global signals to enable largely invisible verification for legitimate users. Existing reCAPTCHA customers are automatically included with no migration or pricing changes.
read more →

NETSCOUT Arbor Threat Mitigation Wins Multiple G2 Badges

🛡️ NETSCOUT’s Arbor Threat Mitigation System (TMS) earned five G2 winter 2026 badges, including Leader distinctions for Enterprise DDoS Protection, DDoS Protection, and Web Security, plus a regional nod in Asia. Arbor Sightline also secured a leader badge for enterprise network management. G2 awards reflect verified user reviews and NETSCOUT’s market presence; customers praise AI/ML-driven visibility, automated defenses, and carrier-grade, hybrid/cloud mitigation.
read more →

Secure URL and Domain Filtering with Google Cloud NGFW

🔒 Google Cloud's Cloud NGFW Enterprise now supports domain and SNI-based URL filtering with limited wildcard matching to shift enforcement to the application layer. The URL filtering service inspects HTTP payloads and SNI headers to enable granular egress policies and block malicious domains without requiring full TLS decryption. This reduces the operational burden of tracking dynamic IPs and helps prevent bypass techniques such as SNI spoofing while preserving end-to-end encryption and compliance.
read more →

AI Is Changing App Threats Faster Than Teams Can Adapt

🔒 AI-driven changes in web applications and APIs are outpacing traditional controls, creating large visibility and detection gaps. The 2026 Web Application Security Report, based on a global survey of over 800 security professionals, finds only 29% confidence in overall application security and just 15% for AI-integrated apps. FortiAppSec Cloud is presented as an integrated platform combining WAF, API protection, bot mitigation, and application security services to provide shared telemetry and consistent enforcement across dynamic, service-generated traffic.
read more →

Cloudflare launches Attack Signature Detection for WAFs

🛡️ Cloudflare announced Attack Signature Detection, a new always-on framework that inspects every proxied request and attaches signature metadata for full visibility without sacrificing protection. The model separates detection from mitigation, populating fields like cf.waf.signature.request.ref, confidence, and categories for use in Security Analytics and the Edge Rules Engine. Detections use the same heuristics as the Managed Ruleset but operate as non-blocking signatures by default, and Full-Transaction Detection — which correlates request and response to reduce false positives and confirm exploits — is under development and available for early interest.
read more →

Why Application Security Should Begin at the Load Balancer

🔐 The article contends that application security must start at the load balancer, which serves as the primary traffic entry and trust boundary rather than just a performance device. The author describes consulting cases across finance, healthcare, SaaS and retail where permissive edge settings enabled downgrade attacks, bot floods, and long-term technical debt. Recommended controls include enforcing modern TLS, sanitizing requests, applying bot and rate controls at the edge, and integrating the load balancer with downstream WAFs and security tools to reduce incident scope and operational cost.
read more →

Toxic combinations: small signals leading to incidents

🔍 Cloudflare describes how dispersed, low‑severity signals can combine into a full security incident termed “toxic combinations.” Using network-wide telemetry, Cloudflare correlates bot indicators, sensitive paths, anomalies, and misconfigurations to detect multi-step reconnaissance and exploitation before a clear exploit appears. The post outlines concrete detection queries and practical mitigations — from WAF rules and Zero Trust controls to API authentication and debug flag hygiene.
read more →

WAF Security Test Results 2026: Prevention First Matters

🔒 The WAF Comparison Project 2026 presents the findings of a third annual, real-world evaluation of 14 leading WAF vendors using 1 million legitimate requests and 74,000 malicious payloads. Testers found attackers increasingly employ evasion, payload padding, and zero-day techniques that can bypass signature-based defenses. The report emphasizes a prevention-first strategy — combining proactive filtering, behavioral controls, and continuous tuning — to better protect web apps, APIs, and GenAI workloads.
read more →

Yokogawa FAST/TOOLS Multiple Web and Crypto Flaws Reported

⚠️ Yokogawa's FAST/TOOLS (versions R9.01–R10.04) contains multiple web and cryptographic vulnerabilities tracked across 14 CVEs that could enable redirection to malicious sites, decryption of communications, man-in-the-middle attacks, cross-site request forgery, script execution, and unauthorized file access. Example CVSS v3 scores reach up to 8.2 for some issues. Yokogawa advises updating to R10.04, applying patch CS_e12787, then installing R10.04 SP3. CISA recommends minimizing Internet exposure for control systems, isolating OT networks behind firewalls, and using secure remote access.
read more →

Attackers Abuse React2Shell to Hijack NGINX Traffic

🔒 Datadog Security Labs disclosed an active web-traffic hijacking campaign that leverages the critical React2Shell vulnerability (CVE-2025-55182, CVSS 10.0) to inject malicious nginx configurations. Attackers use multi-stage shell scripts to create proxy_pass rules that route requests to attacker-controlled backends, focusing on Asian and government/education TLDs and Baota management panels. GreyNoise telemetry links the activity to two dominant IPs and over 1,000 unique sources.
read more →

Attackers Modify NGINX Configurations to Redirect Traffic

🔁 Researchers at DataDog Security Labs uncovered a campaign in which threat actors compromise NGINX servers and Baota-managed hosting panels to inject malicious 'location' blocks into configuration files, rerouting user requests through attacker-controlled backends. The attackers preserve headers like Host, X-Real-IP, User-Agent, and Referer to blend traffic with legitimate requests. The injection toolkit runs in five scripted stages and exfiltrates a map of hijacked domains to a C2 at 158.94.210[.]227.
read more →