Back to blog

Follow and Subscribe

Security

Page 10

  • 30 Years of Web: Building for Tomorrow

    Lee Chen

    The web’s infrastructure — and the applications we build on it — must constantly evolve to meet the ever-transforming expectations of modern and future end users. We’ve gathered five lessons today’s builders can use to drive the next three decades of the web.

    Industry insights
    + 2 more
  • Grinch bots penalized w/ enriched security data & our edge cloud platform | Fastly

    Brooks Cunningham

    In this post, we’ll show how you can use information from an origin response to add an abuse IP address to our penalty box. We've been touting the promise of security at the edge, and this is just one example of what it can do.

    Security
    + 2 more
  • 30 Years of Web: Securing Tomorrow

    Mike Johnson

    To create more secure and resilient web experiences, we must design, build, and execute applications with security top of mind, and consider how the lessons of the past 30 years inform how we think about the future of security.

    Industry insights
    Security
  • Use After Free flaw in Lucet-runtime

    Fastly Security Research Team, The Fastly Security Technical Account Management Team

    On November 11th 2021, Fastly Engineering received alerts related to segmentation faults on Compute@Edge. A Fastly investigation into CVE-2021-43790, a bug in Lucet, a dependency of Compute@Edge, is disclosed in a recent Bytecode Alliance security advisory. Fastly investigations have not identified additional impact outside of the single case disclosed in this advisory. It's our goal in this Fastly Security Advisory to illustrate our knowledge about the bug discovered and the actions we have taken to prevent further possible impact to our customers.

    Security
  • 30 Years of Web: Future-Ready Apps

    Jana Iyengar

    Many websites today are really applications, and we should be building them as such. To do that, we need application architectures and networks that are capable of supporting fast, secure, and scalable user experiences. We must embrace a more dynamic mindset in how we approach web development and consider the tools we need to get there.

    Industry insights
    + 3 more
  • 30 Years of Web: Future Demands

    Davin Camara

    As we look back to celebrate the 30th anniversary of the website, it’s also worth thinking about the next 30 years. There are a couple of areas where we — as engineers, developers, and builders in general — can champion innovation, mainly around architecture and security.

    Industry insights
    + 5 more
  • Subresource monitoring with Compute

    Fastly Security Research Team

    Compute, our serverless compute environment, can be used to solve headaches dealing with attackers looking to modify and manipulate resources. In this post, we tell you how.

    Security
    Compute
  • Preventing SSRF: Apache CVE-2021-40438 | Fastly

    Fastly Security Research Team

    Our Security Research Team provides guidance on how to address CVE-2021-40438, a vulnerability in Apache HTTP Server version 2.4.48 and earlier, by patching impacted version(s) and enabling a new templated rule to prevent exploitation.

    Engineering
    Security
  • Protect against Apache vulnerability | Fastly

    Fastly Security Research Team

    The recent Apache HTTP Server vulnerability (CVE-2021-41773) is reportedly being exploited in the wild. Fastly already detects this vulnerability, but our next-gen WAF customers can also create a rule to block exploitation.

    Security
  • DevOps Practices Primed to Combat Threats | Fastly

    Brendon Macaraeg

    Organizations implementing DevOps practices often sacrifice security for speed, exposing them to potential threats. In reality though, many DevOps practices are already primed for security initiatives.

    Security
    DevOps
  • The Importance of Securing Applications & Security in DevOps

    Julie Rockett

    Forrester’s 2021 Annual State of Application Security Report stresses the need for updated application security tools that can be easily integrated into development plans and architecture.

    Security
    DevOps
  • Integrating Security in DevOps

    Brendon Macaraeg

    Your organization may have operational and cultural roadblocks to overcome when it comes to integrating security and DevOps. These tips can help you ensure a smooth transition to more secure DevOps.

    DevOps
    Security
  • Legacy vs next-gen WAF: the differences matter

    Brendon Macaraeg

    Compare legacy versus next-gen WAFs to see what sets them apart. Determine if your company can benefit from a next-gen approach.

    Security
  • Atlassian Confluence OGNL Injection Vulnerability Protection | Fastly

    Fastly Security Research Team, Xavier Stevens, + 1 more

    Our Security Research Team has built and deployed a rule to help protect customers of our next-gen WAF against the recently announced Confluence Server OGNL injection vulnerability, CVE-2021-26084.

    Security
  • 6 essential features of modern web app & API security tools

    Julie Rockett

    Modern applications need modern security tools that include flexible deployment, DevOps support, and strong API protection. Here are the six most important characteristics of modern web app and API security tools.

    Security
  • Legacy security tools: peace of mind at what price?

    Julie Rockett

    Companies using an average of 11 web application and API security tools should be able to rest easy, but the vast majority of them report successful attacks are still getting through. These legacy tools aren’t cutting it.

    Industry insights
    Security
  • Fastly/Signal Sciences: one year update | Fastly

    Dana Wolf

    When we acquired Signal Sciences, we put a stake in the ground as a company that cares about the complete delivery path and making it not just resilient and performant, but inherently secure as well. Here’s our update on that mission.

    Company news
    + 3 more
  • Introducing right-sized web app and API protection packages

    Brendon Macaraeg

    Today, we launched Fastly Secure packages, a unified web app and API security solution that provides “right-sized” protection for any organization at a spend level that works for a variety of budgets.

    Product
    Security
  • 4 Steps to Centralized Security Tooling

    Sean Leach

    Here are four repeatable steps that will help you pay down your security technical debt, make your apps and APIs more secure, and move you toward consolidated security tooling.

    Industry insights
    Security
  • Why don’t your security tools work anymore?

    Sean Leach

    As the internet landscape gets more complex, more API driven, and more distributed, many security and IT professionals are left wondering — why aren’t the security tools that were good enough a few years ago good enough now?

    Industry insights
    Security