Critical zero-day in F5 BIG-IP APM: Emergency CVE-2026-94127 hotfixes released
Tracked as CVE-2026-94127, the flaw carries a near-maximum severity rating and allows unauthenticated remote code execution (RCE)...
Learn how to strengthen your infrastructure with Web Application Firewalls (WAF) and advanced security features. Perform SSL/TLS offloading and protect against application layer threats to ensure your critical systems are always compliant and protected.
You need a clear, comprehensive view of your entire load balancing estate to maintain control and security...
It can sometimes be useful to make load balancing decisions based on the time and date. This allows you to conditionally refuse or redirect connections based on the time they're received...
There are two schools of thought on this: ‘yes, it should’ and ‘no, it shouldn't’. Let's look at the arguments both for and against...
Here's what we learned from crAPI about API security, and how a Web Application Firewall (WAF) can help you take things one step further...
Getting on board with zero trust is the easy part. Actually applying these principles to your architecture is less black and white...
I had the privilege of speaking in Dublin at this year's OWASP Core Rule Set Community Summit before then attending OWASP Global AppSec immediately afterwards...
I thought I would try and cover the basics here by explaining how to create an SSL certificate and the various files that you'll end up with...
We'd all rather prevent a disaster than have to live with the consequences of one...
Sometimes, we need to pass unusually large HTTP requests through our WAF stack...
A while ago I was asked if it would be possible to apply some general rate limiting in HAProxy and the WAF, in order to help prevent DOS-style attacks on a customer's servers...
F5 recently announced a critical security vulnerability, allowing an attacker to bypass its iControl REST authentication, and execute commands such as creating or deleting files and disabling services...
It's a fair question, right? Let's take away the strain of SSL terminations from our application servers and let the load balancers deal with it. After all, why would we want to bog down our nifty application with network-level considerations?..