top of page

Blogs

Transitioning from ModSecurity WAF to open-appsec at IT Creation, Netherlands
How IT Creation, Netherlands transitioned from ModSecurity WAF to a machine-learning based open source WAF.
Eyal Katz
Oct 17, 20233 min read

Using Gamification to demystify the AI black-box in a Web Application Firewall (WAF) product
Gamification and metaphors can make AI's learning journey more transparent and relatable, explained on an open-source ML-based WAF
Oded Gonda
Sep 29, 20235 min read


How to deploy open-appsec on MicroK8s
In this blog we describe how to secure MicroK8s Kubernetes cluster on an Ubuntu machine, using open-appsec based on NGINX ingress controller
Oriane Louzoun
Sep 29, 20236 min read

How to switch to a ModSecurity WAF alternative before it is EOL in March 2024?
ModSecurity will reach “End of Life“ by 31.3.2024. This blog explains how open-appsec can offer an open-source, free, ML-based alternative
Oded Gonda
Sep 4, 20235 min read


How to effectively Secure GraphQL APIs and Web Apps?
In this blog we explain how to protect GraphQL applications effectively without any change to the protected application, using open-appsec.
Netzer Shohet
Aug 31, 20234 min read


Issue with open-appsec Web Portal Events view
On Monday August 28th, 2023 at 9:31 GMT open-appsec team was notified by email about a potential issue with the Web Portal Events view...
Editorial
Aug 28, 20231 min read

Developing Web Application and API Rate Limiting using ChatGPT
We conducted an experiment developing in two methods: traditional vs. ChatGPT. We share the process and what we learned.
Netzer Shohet
Jul 26, 202310 min read

Best WAF solutions in 2023 - real-world comparison
Which WAF delivers the best Security and Detection Quality? We tested AWS, Azure, CloudFlare, F5 NGINX, ModSec, open-appsec / CloudGuard.
Boris Rozenfeld
Jul 13, 202311 min read


How to Deal with OWASP-Top-10 Attacks Using open-appsec Open Source WAF
In this article, we will present how open-appsec's capabilities can help address each of the OWASP-Top-10 risks.
Christopher Lutat
Jun 28, 202312 min read


How open-appsec Machine Learning WAF Pre-emptively Block Attacks? A Deep-Dive Video.
To explain the inner mechanics of open-appsec’s contextual ML engine, we created a video session, led by open-appsec PM, Christopher Lutat
Christopher Lutat
Jun 22, 20232 min read


How to deploy open-appsec on a Docker SWAG Linux server
In this blog we explain how to deploy open-appsec in SWAG version 2.5.0 in different options for self-compilation per OS and version.
Oriane Louzoun
Jun 4, 20234 min read


How to Easily Connect Your Locally Managed open-appsec Deployment to Management Portal (SaaS)
In this article you will learn how to easily migrate or connect an existing local open-appsec deployment to the WebUI management portal.
Netzer Shohet
Apr 20, 20235 min read


open-appsec Introduces CrowdSec Integration for Community Threat Intelligence Protection
This new integration allows open-appsec to connect to the CrowdSec local API to consume the CrowdSec Threat Intelligence.
Christopher Lutat
Apr 4, 20235 min read


How We Deployed open-appsec API Security Schema Validation to Protect our own Backend Systems
In this blog we describe how we used the open-appsec engine’s Schema Validation capability to protect our own APIs.
Netzer Shohet
Mar 22, 20235 min read

2023 GigaOm Radar report selects open-appsec as a Leader in the Application and API Security Space
The report evaluates and rates vendors based on a set of key criteria, including security capabilities, ease of use, and overall value.
Hen Eliyahu
Mar 13, 20235 min read

open-appsec provides ML-based API Security add-on for Kong API Gateways
open-appsec provides Kong users effective and integrated API Security including preemptive protection against zero-day attacks.
Christopher Lutat
Feb 23, 20236 min read

open-appsec ML-based WAF protects against modern SQLi AutoSpear evasion techniques
Modern SQLi evasion techniques evolve day by day raising the question of whether traditional WAF systems are able to handle this challenge.
Boris Rozenfeld
Feb 19, 20234 min read


Deep Dive into open-appsec Machine Learning Technology
Article explains how open-appsec ML-based engine allow pre-emptive protection against zero-days and how to configure it.
Fortune Adekogbe
Feb 6, 20238 min read

open-appsec / CloudGuard AppSec is the only product known to pre-emptively block Claroty WAF bypass
Claroty developed a bypass for WAF products. The attack involves appending JSON syntax to SQL injection. Many leading WAFs were vulnerable.
Oded Gonda
Dec 10, 20224 min read

NGINX WAF and Kubernetes WAF options (App Protect vs. open-appsec)
This articles compares NGINX App Protect signature-based WAF and open-appsec free open-source ML-based WAF.
Christopher Lutat
Nov 17, 20224 min read
bottom of page