About

Latest Akamai security news


Casting a SpEL

Akamai WAF bypassed via Spring Boot to trigger RCE14 December 2022Casting a SpELAkamai WAF bypassed via Spring Boot to trigger RCE

Researchers net $46k for Akamai misconfiguration vulnerability

04 October 2022Researchers net $46k for Akamai misconfiguration vulnerabilityA lesson in how to achieve maximum value for your discoveries

Browser-powered desync

New class of HTTP request smuggling attacks showcased at Black Hat USA11 August 2022Browser-powered desyncNew class of HTTP request smuggling attacks showcased at Black Hat USA

Into the wild

Middleboxes being used in fresh wave of DDoS attacks10 March 2022Into the wildMiddleboxes being used in fresh wave of DDoS attacks

White House FOSS summit

Biden administration tackles ‘unique security challenges’ faced by open source ecosystem17 January 2022White House FOSS summitBiden administration tackles ‘unique security challenges’ faced by open source ecosystem

Credential stuffing attacks

New York Attorney General alerts 17 ‘well-known’ organizations to 1.1m compromised online accounts06 January 2022Credential stuffing attacksNew York Attorney General alerts 17 ‘well-known’ organizations to 1.1m compromised online accounts

Lasso bug, roped up

Akamai offers comprehensive post-mortem on recently resolved authentication platform vulnerability03 June 2021Lasso bug, roped upAkamai offers comprehensive post-mortem on recently resolved authentication platform vulnerability

The age of Covid-19: Lockdowns and cybersecurity, 12 months on

Infosec ‘slow-pocalypse’ sees surge in ransomware and fraud16 March 2021The age of Covid-19: Lockdowns and cybersecurity, 12 months onInfosec ‘slow-pocalypse’ sees surge in ransomware and fraud

PasswordsCon 2020

Authentication expert expresses skepticism about ‘passwordless’ future25 November 2020PasswordsCon 2020Authentication expert expresses skepticism about ‘passwordless’ future

You lose!

Capcom takes systems offline following cyber-attack06 November 2020You lose!Capcom takes systems offline following cyber-attack

Security AI and automation slashes the cost of data breaches – IBM

03 November 2020Security AI and automation slashes the cost of data breaches – IBMAugmenting or replacing human intervention cut per-breach losses by $3.58m

Behind the botnet

Akamai’s Tony Lauro on tackling real-world credential stuffing attacks30 October 2020Behind the botnetAkamai’s Tony Lauro on tackling real-world credential stuffing attacks

PunkBuster, punk’d

Anti-cheat gaming servers vulnerable to remote exploitation01 October 2020PunkBuster, punk’dAnti-cheat gaming servers vulnerable to remote exploitation

Credential stuffing attacks: How to protect your accounts from being compromised

30 September 2020Credential stuffing attacks: How to protect your accounts from being compromised

Gamers fragged by surge in credential stuffing attacks during lockdown

25 September 2020Gamers fragged by surge in credential stuffing attacks during lockdownAttacks soar as DDoS attacks against video game firms rise – Akamai

Hacker-powered security

US federal agencies required to launch vulnerability disclosure policies03 September 2020Hacker-powered securityUS federal agencies required to launch vulnerability disclosure policies

Online security advice fails to help users prioritize problems, report warns

Proof that bombarding users with security advice doesn’t always work25 August 2020Online security advice fails to help users prioritize problems, report warnsProof that bombarding users with security advice doesn’t always work

Black Hat 2020: Web cache poisoning offers fresh ways to smash through the web stack

Flawed cache keys unlock a giant backdoor to your website05 August 2020Black Hat 2020: Web cache poisoning offers fresh ways to smash through the web stackFlawed cache keys unlock a giant backdoor to your website

DIY phishing kits dissected

Tackling the underground ecosystem that democratized cybercrime30 July 2020DIY phishing kits dissectedTackling the underground ecosystem that democratized cybercrime

Akamai traces sharp rise in SQLi attacks

Number one OWASP threat shows no sign of abating29 November 2017Akamai traces sharp rise in SQLi attacksNumber one OWASP threat shows no sign of abating