Wallarm Releases API Attack Surface Management
August 22, 2024

Wallarm released API Attack Surface Management (AASM), an agentless technology to help organizations identify, analyze, and secure their entire API attack surface.

Designed for effortless deployment, Wallarm AASM empowers organizations to discover all of their externally-facing APIs and web applications, identify where they are missing critical web application firewalls (WAF)/web application and API protection (WAAP) coverage, and mitigate API leaks.

“Even though APIs are a well-known source of application vulnerabilities, and we’ve seen a more than 30% increase in API vulnerabilities in 2023 alone, too many organizations are operating without adequate detection and response capabilities. They either don’t know where to get started, or they mistakenly think that their current solutions have them protected, which is usually not the case,” says Ivan Novikov, co-founder and CEO of Wallarm. “And for organizations that do have API detection and response capabilities, they are often dependent on too many manual processes that are distributed between multiple tools. This is far too time-consuming for most security teams and leads to inefficient security operations, missed detections and unacceptably slow response times.”

Wallarm has officially launched its AASM solution, a platform engineered to empower organizations to rapidly and seamlessly address the growing challenge of API vulnerabilities without deploying agents / sensors with minimal effort. Wallarm AASM delivers valuable capabilities to help customers discover their external API Attack Surface, test its security, assess its risk and enable customizable remediation strategies. They include:

- Automated API Attack Surface Discovery that identifies all external hosts with their web apps and APIs, including specific API protocols (REST API, GraphQL, SOAP, XML-RPC and more).

- Scanning public repositories for leaked API secrets, including API keys, PII (usernames and passwords, authorization tokens (Bearer/JWT) and other targets).

- Identification of which API hosts are secured with WAFs and testing to identify which types of threats their WAFs can detect.

New users can enable AASM within minutes and Wallarm offers a free, 7-day trial to help organizations get started have instant access to API attack surface visibility and results.

Share this

Industry News

November 20, 2024

Spectro Cloud completed a $75 million Series C funding round led by Growth Equity at Goldman Sachs Alternatives with participation from existing Spectro Cloud investors.

November 20, 2024

The Cloud Native Computing Foundation® (CNCF®), which builds sustainable ecosystems for cloud native software, has announced significant momentum around cloud native training and certifications with the addition of three new project-centric certifications and a series of new Platform Engineering-specific certifications:

November 20, 2024

Red Hat announced the latest version of Red Hat OpenShift AI, its artificial intelligence (AI) and machine learning (ML) platform built on Red Hat OpenShift that enables enterprises to create and deliver AI-enabled applications at scale across the hybrid cloud.

November 20, 2024

Salesforce announced agentic lifecycle management tools to automate Agentforce testing, prototype agents in secure Sandbox environments, and transparently manage usage at scale.

November 19, 2024

OpenText™ unveiled Cloud Editions (CE) 24.4, presenting a suite of transformative advancements in Business Cloud, AI, and Technology to empower the future of AI-driven knowledge work.

November 19, 2024

Red Hat announced new capabilities and enhancements for Red Hat Developer Hub, Red Hat’s enterprise-grade developer portal based on the Backstage project.

November 19, 2024

Pegasystems announced the availability of new AI-driven legacy discovery capabilities in Pega GenAI Blueprint™ to accelerate the daunting task of modernizing legacy systems that hold organizations back.

November 19, 2024

Tricentis launched enhanced cloud capabilities for its flagship solution, Tricentis Tosca, bringing enterprise-ready end-to-end test automation to the cloud.

November 19, 2024

Rafay Systems announced new platform advancements that help enterprises and GPU cloud providers deliver developer-friendly consumption workflows for GPU infrastructure.

November 19, 2024

Apiiro introduced Code-to-Runtime, a new capability using Apiiro’s deep code analysis (DCA) technology to map software architecture and trace all types of software components including APIs, open source software (OSS), and containers to code owners while enriching it with business impact.

November 19, 2024

Zesty announced the launch of Kompass, its automated Kubernetes optimization platform.

November 18, 2024

MacStadium announced the launch of Orka Engine, the latest addition to its Orka product line.

November 18, 2024

Elastic announced its AI ecosystem to help enterprise developers accelerate building and deploying their Retrieval Augmented Generation (RAG) applications.

Read the full news on APMdigest

November 18, 2024

Red Hat introduced new capabilities and enhancements for Red Hat OpenShift, a hybrid cloud application platform powered by Kubernetes, as well as the technology preview of Red Hat OpenShift Lightspeed.

November 18, 2024

Traefik Labs announced API Sandbox as a Service to streamline and accelerate mock API development, and Traefik Proxy v3.2.