Security knowledge
Industry insights on DDoS, API security, acceleration and TLS.
Security knowledge
5 articlesSelected industry events, security alerts and protection practices from May 2024 to October 2026, with historical events organized by event date.
2026
OWASP A01 access control: authentication does not authorize every object
Check API authorization by object, tenant and action rather than relying on hidden buttons.
Read moreJA4, TLS and CC defense: fingerprints are signals, not identity
Combine TLS fingerprints with behavior while treating certificate validation as a separate control.
Read moreSQL injection and XSS need different defensive controls
Prevent injection at database and browser boundaries instead of relying on a universal input filter.
Read moreSSRF and command injection: constrain destinations and execution
Control destinations, process invocation and privileges in fetchers, converters and administrative tools.
Read moreOWASP A03 supply chains: protect builds and releases as well as dependencies
Review component versions, build credentials, artifact provenance and recovery paths.
Read more