Critical zero-day in F5 BIG-IP APM: Emergency CVE-2026-94127 hotfixes released
Tracked as CVE-2026-94127, the flaw carries a near-maximum severity rating and allows unauthenticated remote code execution (RCE)...
Learn how to strengthen your infrastructure with Web Application Firewalls (WAF) and advanced security features. Perform SSL/TLS offloading and protect against application layer threats to ensure your critical systems are always compliant and protected.
Whilst the Heartbleed bug was relatively easy to exploit, the latest batch of bugs are not...
To ensure complete protection all SSL certificates that have been used with a vulnerable version of OpenSSL should be regenerated using a new private key...
Let me first say that I'm not really a fan of PCI scanners. It's not so much that I'm anti security scanners but rather that scanning for vulnerabilities based on only the version number a package returns seems rather simplistic to me...
There are a lot of SSL offload throughput statistics available for appliances across the internet but rarely do they detail the way they were tested...
The BEAST attack is a practical attack based on a protocol vulnerability and mainly affects the client side...
Any engineer dealing with PCI DSS compliance issues probably looses a little bit of the joy in life...
I've previously blogged about how to get TPROXY and HAProxy working nicely together, but what if you want to terminate SSL traffic on the load balancer to use HAProxy to insert cookies in the standard HTTP stream to the backend servers?..