Wallarm API Security Wallarm updates logo

Wallarm updates

Discover the latest features, improvements, and updates in Wallarm API Security

Subscribe to Updates

Labels

  • All Posts
  • API Security
  • WAAP
  • ANNOUNCEMENT
  • Security Edge
  • IMPROVEMENT
  • FIX
  • FAST

Jump to Month

  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • March 2022
  • February 2022
  • December 2021
  • November 2021
  • October 2021
  • August 2021
  • April 2021
  • March 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • December 2019
  • October 2019
  • August 2019
  • April 2019
API SecurityWAAP
4 weeks ago

Deploy Wallarm With Azure APIM, Apigee, and Akamai

We’re continually working to expand and maintain our deployment options for Wallarm filtering nodes. We have three updates to share regarding connector-based integrations. 

New Azure APIM Connector:

For customers with APIs managed by Azure APIM, Wallarm now offers a new connector to collect relevant API traffic for analysis. This connector can be deployed in both synchronous and asynchronous modes. 

Read more about our Azure APIM connector in the documentation. 

Updated Apigee Connector: 

Wallarm has updated our existing Apigee connector to parse and analyze API responses in addition to requests. This change expands the Wallarm features supported by the connector. 

Read more about our Apigee connector in the documentation. 

Updated Akamai Connector: 

Wallarm has updated our existing Akamai connector to parse and analyze API responses in addition to requests. This change expands the Wallarm features supported by the connector. 

Read more about our Akamai connector in the documentation. 

Avatar of authorWallarm team
API SecurityWAAP
4 weeks ago

Faster, Easier Custom Response Options for Attacks

Wallarm delivers outstanding automated attack protection, but there are situations where you want to create custom criteria, rules, and thresholds for taking action. Previously, these capabilities were distributed within Wallarm rules and triggers, making it complicated to manage. In order to streamline the process of configuring and managing custom response actions, Wallarm has introduced Mitigation Controls. 

You can find Mitigation Controls as a separate menu item in the Security Controls section of the menu. The new Mitigation Controls capability brings together a collection of response options in a centralized, easy to manage interface. Here you can configure capabilities like blocking modes, GraphQL policies, custom BOLA protection, and more. 



The configuration and response options available for each mitigation control vary based on the control, providing you with the information you need to generate the mitigation results you want. Mitigation Controls are available with node 6.5.x+. Existing customers with configured triggers for Brute Force, Forced Browsing, and BOLA will be individually migrated once all nodes are compatible. Read more about each mitigation control and their configurations in the Wallarm documentation.

 

Avatar of authorWallarm team
API Security
a month ago

Granular Control to Stop Attacks Without Disrupting Legitimate Users

Attackers are evolving — rotating IPs, spreading abuse across multiple requests, and bypassing traditional defenses. In this environment, simply detecting attacks is not enough. Security teams need precise tools to stop attacks without breaking customer experiences.

With the introduction of session-based blocking, Wallarm gives customers surgical control over active attacks. This capability allows teams to terminate compromised API sessions in real time, even when attackers switch IPs or distribute activity, while keeping legitimate users unaffected.

Wallarm now offers three advanced options for active attack mitigation:

  • Block Individual Requests — Instantly shut down malicious requests such as SQL injection, RCE, and path traversal exploits.
  • Block IP Addresses — Eliminate abusive IPs proactively or reactively when needed.
  • Block Compromised Sessions (New) — Target and terminate malicious sessions to neutralize sophisticated, multi-request API abuse.

Unlike traditional IP-based blocking, session-based blocking focuses on attacker behavior, not network location. It enables security teams to stop ongoing attacks with granular precision, preserving user experience while strengthening API defenses.

Users can enable API session blocking in their API Abuse Prevention profiles and in specific Mitigation Controls. 

You can read more about using session-based blocking in the Wallarm documentation. 

Avatar of authorWallarm team
API Security
a month ago

Shift Left: Find API Vulnerabilities Faster

We’re excited to announce that Schema-Based Testing is now generally available as part of the Wallarm Security Testing suite.

This release introduces Dynamic Application Security Testing (DAST) for APIs, enabling shift-left API testing and seamless integration into CI/CD pipelines and the SDLC process.

Key Highlights

Expanded Vulnerability Coverage:

  • OWASP API Top 10 risks
  • Business Logic flaws (BOLA, BFLA)
  • Input validation issues (Injections, RCE, Path Traversal)
  • Environment misconfigurations
  • GraphQL misconfigurations

Supported Inputs:

  • OpenAPI specifications
  • Postman collections (for advanced testing of business logic scenarios and access control violations)


Schema-Based Testing runs on a lightweight Docker-based agent, ensuring fast and isolated execution. It supports both one-time scans for quick assessments and continuous testing integrated into CI/CD pipelines, making it flexible for different stages of the development lifecycle.

Test results are available locally for immediate review and are also synced to the Wallarm Console, where issues can be tracked and prioritized. Users can define a configurable risk-level threshold to automatically determine when a test run should fail, aligning security checks with organizational policies. You can learn more in the Wallarm documentation.






Avatar of authorWallarm team
API Security
a month ago

Improved Detection of Account Takeover (ATO) Attacks

Attackers continue to adapt and Wallarm continues to innovate API protection. We’ve introduced improvements to API Abuse Prevention in order to improve detection of Account Takeover (ATO) attacks. Wallarm now supports two additional machine learning detectors. 

IP Rotation

The IP rotation detector identifies account takeover attacks where attackers utilize a pool of IP addresses to perform an attack. In these types of attacks, the session remains stable, with cookies, headers, and other key fields unchanged, but each request or a small set of requests is made from a different IP address, often using each IP only once. This results in a single long session involving multiple IPs.

The detector analyzes this IP diversity within a consistent session to flag sophisticated automated attacks that evade traditional security measures.

Session Rotation

The Session rotation detector identifies account takeover attacks where attackers rotate session identification to avoid detection. In these types of attacks, a unique session (e.g., a cookie-based ID) is assigned to each client, but an attacker intentionally modifies or removes the session identifier. This results in one attacker using a single IP address with multiple sessions.

The detector analyzes this unusual behavior of high session diversity from the same IP to detect sophisticated automated attacks.

Both of these new detectors were created to better identify anomalies in API traffic that indicates an account takeover attack. You can read more about API Abuse Prevention in the documentation. 

Avatar of authorWallarm team
API Security
2 months ago

New Protection Mechanisms For OWASP API4:2023 – Unrestricted Resource Consumption

To strengthen defenses against resource exhaustion and abuse, Wallarm has released two new mitigation controls specifically addressing "OWASP API4:2023 – Unrestricted Resource Consumption" threats.

📁 File Upload Restriction Policy 

This real-time node-side mitigation allows you to block oversized or maliciously crafted requests before they reach your app.

Two configuration options provide flexibility:

  • Maximum Total Request Size – limit the full request, including headers, body, and parameters

  • Maximum Size per Parameter – restrict specific fields such as JSON parameters, Multipart parameters, headers. etc.

This control is effective across all content types (e.g., POST-multipart, PUT, JSON with base64) and helps prevent denial-of-service, memory exhaustion, and CVE exploitation through size abuse.

Included in API Security and WAAP subscriptions with Node ≥ 6.3.0

🌐 Unrestricted Resource Consumption Detection

Part of the API Abuse detection module, this cloud-based control detects excessive and abnormal resource usage that may degrade system performance, even in the absence of traditional attack signatures.

Common attack scenarios include:

  • Sending large requests to overload memory or bandwidth

  • Triggering heavy operations (e.g., complex database queries) to slow down the server

  • Downloading massive responses to consume outbound traffic (scraping) or exfiltrate data

Included in Advanced API Security (API Abuse module) with Node ≥ 6.3.0

🔍 Feature Comparison


File Upload Restriction Policy

Unrestricted Resource Consumption Detection

Enforcement

Real-time (Node)

Reactive (Cloud)

Configuration

Manual thresholds

Adaptive, traffic-based

Detection Scope

Request size (total/parameter)

Request size, response size, processing time



✅ Full-Spectrum Protection for API4:2023

These two new controls, alongside Wallarm’s existing threat mitigation and behavioral detection capabilities, form a robust and layered defense against all known vectors of OWASP API4 Unrestricted Resource Consumption. 

Avatar of authorWallarm team
API Security
3 months ago

Automated Security Issue Rechecking in AASM

In order to streamline the vulnerability management process and allow users to focus on actionable data, API Attack Surface Management (AASM) now automates the evaluation and updating of discovered Security Issues after each scan. Here’s how it works:

  • After every scan, AASM compares the new scan results with the current state of each Security Issue.
  • If the scan job completes successfully and changes are detected in the findings, the relevant Security Issue may be automatically closed or reopened.
  • Each status update is logged in the Status History of the Security Issue.
  • A comment is added to explain the reason for the change.

Possible closure reasons include:

  • Port not found during last scan — the previously open port is now closed.
  • Network service has changed — e.g., the service on the port changed, for example from SSH to HTTP.
  • New version of the product detected — indicating a product upgrade.
  • Vulnerable version no longer present — the outdated component has been removed
  • Vulnerability not detected during last scan — the issue is no longer observable.


This feature automates and simplifies vulnerability management by updating issue statuses based on scan results, reducing manual effort and ensuring accurate, real-time tracking of security risks.

Additional information is available in the documentation. 

Avatar of authorWallarm team
IMPROVEMENT
3 months ago

Find Issues Faster with Node Traffic Charts

We’ve added a new enhancement to the Nodes page to give you visibility into your traffic trends.

Until now, users have had visibility into total volume of traffic and traffic by application. With this enhancement, users can view traffic by node as well. 


For each specific Node instance on the "Nodes" page, the detail view now shows a chart of daily request volume. Users can adjust the time range to explore how much traffic each Node handled over a specific period of time. This increased visibility provides greater transparency into node utilization and faster troubleshooting of node issues. 

Avatar of authorWallarm team
API Security
4 months ago

Find Important Sessions Details Faster

We are excited to announce significant improvements to our API Sessions user experience, designed to help you find important API session details faster and more efficiently.

The following enhancements are now available:

  • Performance Improvements: Faster loading times for sessions, eliminating waits for large datasets.
  • Exclusion Filters: Filter API sessions with both included and excluded criteria.
  • Sortable Columns: Sorting by date and number of requests is now supported.
  • Separated Sections in Session Details: Improved data visibility with icons and highlights, making it easier to locate specific information.
  • Collapsable Sections: Hide less frequently used data until needed, streamlining your view.
  • Intelligent Linking: Navigate quickly between session details with intuitive linking.
  • Attack Details Display: View detected attacks and attack details directly within the API sessions interface.

For more details, check out the documentation or see the demo data in the Wallarm Playground. 

Avatar of authorWallarm team
API Security
5 months ago

More Control and Accuracy in Scan Scope Configuration in API Attack Surface Management

We’re excited to introduce a major upgrade to how scans are configured in API Attack Surface Management (AASM). We’ve improved the user experience to deliver more flexibility, precision, and alignment with your unique API security needs.

You can now granularly define your scan scope, allowing for more targeted and accurate results. With this update, you’ll be able to cut through the noise and focus on what matters most.

Here’s what’s new:

  • Bulk Import of Root Domains: Quickly onboard your assets by importing multiple domains at once.
  • Expanded Scope Definition: Add additional hosts to ensure comprehensive coverage of your environments.
  • Advanced Scheduler Control:
    • Turn on/off the auto-rescan scheduler per domain.
    • Globally manage the scan schedule (weekly, bi-weekly, or monthly).
    • Global scheduler settings override domain-level preferences for consistency.
  • Scanning Profiles: Choose from pre-defined scanning profiles or create your own to match your risk posture.
  • Modular Control: Enable or disable specific scanning modules as part of your scheduled scans.

These enhancements are built to help you minimize noise, sharpen findings, and focus your efforts where they matter most.

Start refining your scan scope now to take full advantage of the improved accuracy and control.

Avatar of authorWallarm team