Critical zero-day in F5 BIG-IP APM: Emergency CVE-2026-94127 hotfixes released
Tracked as CVE-2026-94127, the flaw carries a near-maximum severity rating and allows unauthenticated remote code execution (RCE)...
Learn how to strengthen your infrastructure with Web Application Firewalls (WAF) and advanced security features. Perform SSL/TLS offloading and protect against application layer threats to ensure your critical systems are always compliant and protected.
Using client certificates for security is a pretty cool idea! You can protect an entire application or even just a specific Uniform Resource Identifier (URI) to only those that provide a valid client certificate...
SSL offload is handled by STunnel, while HAProxy handles back-end server re-encryption...
How frustrating do you find it when hackers or robots fill in your website forms with "Buy Viagra Now!" type spam?..
The long and short of it is, there are updates to the Linux kernel and glibc packages which will 'fix' the issue..
Different vendors have widely different opinions on which method should be used to deploy web filters or SWGs. Historically, vendors struggled to implement authentication in Transparent mode, and maybe they remember some awkward conversations with customers that chose the wrong method...
The Web Application Firewall is based on ModSecurity which is an open source WAF for Apache, IIS, and Nginx for protecting against a many variety of attacks and allows for HTTP traffic monitoring and logging...
SNI is an extension to the TLS protocol which enables the client to broadcast its hostname when it tries to connect to your server. This allows you to use multiple SSL certificates on a single IP...
Due to the way that PuTTY uses a signed integer variable to store the number of characters to be erased and there was inadequate checking for overflow, there was the potential for an attacker to corrupt important data in certain circumstances...
Anomaly score based blocking is more flexible and effective than simple first error blocking...
Denial of Service (DOS) attacks can be used to degrade or cripple the functionality of a site...
Is getting an A+ rating with the Qualys scanner starting to feel a bit like chasing a mythical unicorn? Every time you get close to catching and keeping the beast — it run's away and they change the rules again!..
There seems to have been so much hype over the recent bash bug, shell shock! And there were all the people in the Microsoft world thinking YES we are so cool we are NOT affected by it!..