top of page

Blogs


Leveraging open-appsec / CloudGuard WAF for PCI DSS Requirement 6.4.1-2 Compliance
Learn how to leverage open-appsec / CloudGuard WAF for PCI DSS Requirement 6.4.1-2 Compliance.
Oriane Louzoun
Feb 25, 20243 min read


Announcing open-appsec WAF Integration with NGINX Proxy Manager
Announcing open-appsec WAF Integration with NGINX Proxy Manager!
Christopher Lutat
Dec 28, 20239 min read


Zero-day protection for MOVEit CVE-2023-36934
Blog examines CVE-2023-36934, a critical vulnerability in MOVEit Transfer software. We detailed the vulnerability's exploitation mechan
Boris Rozenfeld
Dec 18, 20233 min read


How you can integrate open-appsec logs into various SIEM services
open-appsec events can be seen in the open-appsec central management WebUI. Here we explain how these events can also be displayed in SIEM.
Christopher Lutat
Oct 27, 20236 min read


Transitioning from ModSecurity WAF to open-appsec at IT Creation, Netherlands
How IT Creation, Netherlands transitioned from ModSecurity WAF to a machine-learning based open source WAF.
Eyal Katz
Oct 17, 20233 min read


Using Gamification to demystify the AI black-box in a Web Application Firewall (WAF) product
Gamification and metaphors can make AI's learning journey more transparent and relatable, explained on an open-source ML-based WAF
Oded Gonda
Sep 29, 20235 min read


How to deploy open-appsec on MicroK8s
In this blog we describe how to secure MicroK8s Kubernetes cluster on an Ubuntu machine, using open-appsec based on NGINX ingress controller
Oriane Louzoun
Sep 29, 20236 min read


How to switch to a ModSecurity WAF alternative before it is EOL in March 2024?
ModSecurity will reach “End of Life“ by 31.3.2024. This blog explains how open-appsec can offer an open-source, free, ML-based alternative
Oded Gonda
Sep 4, 20235 min read


How to effectively Secure GraphQL APIs and Web Apps?
In this blog we explain how to protect GraphQL applications effectively without any change to the protected application, using open-appsec.
Netzer Shohet
Aug 31, 20234 min read


Issue with open-appsec Web Portal Events view
On Monday August 28th, 2023 at 9:31 GMT open-appsec team was notified by email about a potential issue with the Web Portal Events view...
Editorial
Aug 28, 20231 min read


Developing Web Application and API Rate Limiting using ChatGPT
We conducted an experiment developing in two methods: traditional vs. ChatGPT. We share the process and what we learned.
Netzer Shohet
Jul 26, 202310 min read


Best WAF solutions in 2023 - real-world comparison
Which WAF delivers the best Security and Detection Quality? We tested AWS, Azure, CloudFlare, F5 NGINX, ModSec, open-appsec / CloudGuard.
Boris Rozenfeld
Jul 13, 202311 min read


How to Deal with OWASP-Top-10 Attacks Using open-appsec Open Source WAF
In this article, we will present how open-appsec's capabilities can help address each of the OWASP-Top-10 risks.
Christopher Lutat
Jun 28, 202312 min read


How open-appsec Machine Learning WAF Pre-emptively Block Attacks? A Deep-Dive Video.
To explain the inner mechanics of open-appsec’s contextual ML engine, we created a video session, led by open-appsec PM, Christopher Lutat
Christopher Lutat
Jun 22, 20232 min read


How to deploy open-appsec on a Docker SWAG Linux server
In this blog we explain how to deploy open-appsec in SWAG version 2.5.0 in different options for self-compilation per OS and version.
Oriane Louzoun
Jun 4, 20234 min read


How to Easily Connect Your Locally Managed open-appsec Deployment to Management Portal (SaaS)
In this article you will learn how to easily migrate or connect an existing local open-appsec deployment to the WebUI management portal.
Netzer Shohet
Apr 20, 20235 min read


open-appsec Introduces CrowdSec Integration for Community Threat Intelligence Protection
This new integration allows open-appsec to connect to the CrowdSec local API to consume the CrowdSec Threat Intelligence.
Christopher Lutat
Apr 4, 20235 min read


How We Deployed open-appsec API Security Schema Validation to Protect our own Backend Systems
In this blog we describe how we used the open-appsec engine’s Schema Validation capability to protect our own APIs.
Netzer Shohet
Mar 22, 20235 min read


2023 GigaOm Radar report selects open-appsec as a Leader in the Application and API Security Space
The report evaluates and rates vendors based on a set of key criteria, including security capabilities, ease of use, and overall value.
Hen Eliyahu
Mar 13, 20235 min read


open-appsec provides ML-based API Security add-on for Kong API Gateways
open-appsec provides Kong users effective and integrated API Security including preemptive protection against zero-day attacks.
Christopher Lutat
Feb 23, 20236 min read
bottom of page