#web-application-firewall

[ follow ]
fromSecurityWeek
3 hours ago

Hundreds of Malicious Packages Force RubyGems to Suspend Registrations

New account registrations on RubyGems.org, the official Ruby gem hosting service, have been suspended after threat actors published hundreds of malicious packages. RubyGems maintainers announced on May 12 that registrations have been temporarily disabled due to a "DDoS attack". Nearly 24 hours later, registrations are still disabled and will likely remain closed for another 2-3 days until account creation rate limiting can be tightened and WAF protection is enabled.
Ruby on Rails
Information security
fromThe Hacker News
2 months ago

How to Protect Your SaaS from Bot Attacks with SafeLine WAF

SaaS applications face constant automated bot attacks that exploit business logic, appearing as legitimate growth while degrading performance; SafeLine WAF protects by inspecting traffic patterns and behavior before requests reach application code.
Information security
fromThe Hacker News
6 months ago

Why Unmonitored JavaScript Is Your Biggest Holiday Security Risk

Unmonitored client-side JavaScript enables attackers to steal payment data while WAFs and network defenses remain blind, creating a critical security gap.
fromThe Hacker News
8 months ago

Adobe Commerce Flaw CVE-2025-54236 Lets Hackers Take Over Customer Accounts

"A potential attacker could take over customer accounts in Adobe Commerce through the Commerce REST API," Adobe said in an advisory issued today. The issue impacts the following products and versions - Adobe Commerce (all deployment methods): 2.4.9-alpha2 and earlier 2.4.8-p2 and earlier 2.4.7-p7 and earlier 2.4.6-p12 and earlier 2.4.5-p14 and earlier Adobe Commerce B2B: 1.5.3-alpha2 and earlier 1.5.2-p2 and earlier 1.4.2-p7 and earlier
E-Commerce
Web frameworks
fromthehackernews.com
11 months ago

SafeLine WAF: Open Source Web Application Firewall with Zero-Day Detection and Bot Protection

SafeLine is a leading self-hosted web application firewall that provides exceptional attack detection and data sovereignty.
[ Load more ]