Wallarm API Security Wallarm updates logo

Wallarm updates

Discover the latest features, improvements, and updates in Wallarm API Security

Subscribe to Updates

Labels

  • All Posts
  • API Security
  • WAAP
  • ANNOUNCEMENT
  • Security Edge
  • IMPROVEMENT
  • FIX
  • Security Testing
  • AI Security
  • AI Hypervisor
  • Infrastructure Discovery

Jump to Month

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • February 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • May 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • November 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • March 2022
  • February 2022
  • December 2021
  • November 2021
  • October 2021
  • August 2021
  • April 2021
  • March 2021
  • December 2020
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • December 2019
  • October 2019
  • August 2019
  • April 2019
ANNOUNCEMENTInfrastructure Discovery
yesterday

See how an attacker would reach your critical AWS assets

Your findings list tells you what's wrong. It can't tell you what's reachable.

Attack Paths works from a different input: the actual shape of your estate. Which AWS resources are exposed, which roles can be assumed by whom, which principals can read what. Those relationships are what a path is built from, whether or not anything along the chain has ever been flagged as a problem.

It's live in Infrastructure Discovery now, and there's nothing to install. If your AWS accounts are already connected, it's in your dashboard.

What's new

Paths built from configuration, not from CVEs A path exists because something is exposed, some permission is broader than intended, and something valuable sits at the end of it. Findings from Security Hub, Inspector, and GuardDuty can raise a path's priority, but they never create one and never gate one. Plenty of the paths worth your time have no finding attached anywhere along the chain.

Ranked paths, shown as a map Every path runs from an entry point, through any pivots along the way, to a crown jewel. You get the whole chain as a map, with a severity band and a plain-English reason it landed where it did.

Crown jewels you choose yourself You decide what counts as high value in your estate. Pin and unpin assets from the console, and path scoring reorganizes around your choices instead of our assumptions about your business.

Key nodes: entry points and choke points Entry points are ranked by what they actually open up. Choke points are the nodes that the most paths run through, which is usually where a single change does the most work.

Identity, not just network reachability Paths follow IAM as closely as they follow the network: role chaining, pass-role, policy attachment, self-escalation, and principals holding effective admin through AWS managed policies.

Why it matters

A severity list ranks problems one at a time, and it's genuinely good at that. What it can't do is tell you that a role you granted a vendor two years ago, with "read-only" in its name and a wildcard in its policy, sits one hop from every secret you own. There's no CVE on that role and nothing about it is broken. Someone made a reasonable call and the blast radius grew around it quietly. That's a path, and paths are what this is for.

Where to find it

Infrastructure Discovery → Attack Paths. 

Attack Paths is included in your Infrastructure Discovery license. No separate SKU, no add-on charge.

Full details in the Infrastructure Discovery documentation.

Avatar of authorTim Erlin
ANNOUNCEMENTAI SecurityAI HypervisorInfrastructure Discovery
a month ago

Introducing the Wallarm AI Control Platform

Your API security is already covered. What's changed is what's behind those APIs. AI agents are making decisions, accessing data, and calling external services right now, and most security teams can't see any of it. Not because they're not paying attention, but because no tool was built to show them.

Today that changes. We're launching the Wallarm AI Control Platform: two products that close the loop from estate-wide discovery through runtime enforcement through continuous compliance evidence. No new vendor to onboard. It extends the platform you already run.

What's shipping today

Infrastructure Discovery

Connect your AWS accounts once and get a continuously updated inventory of everything in your estate. EC2, VPC topology, EKS clusters, Lambda functions, API Gateway, IAM, and Bedrock models and agents, across every account and every region, in one searchable table.

  • Cross-account discovery via IAM role assumption, no write permissions required
  • Live relationship graph with blast-radius traversal and attack-path analysis
  • AWS Security Hub findings sync, placed on the graph node they affect with full asset context
  • Field-level drift detection between every scan, with CloudTrail creator attribution on every asset
  • Customer-authored detection and triage rules in Common Expression Language
  • Scheduled and on-demand scans; policy audit log for every triage decision

AI Hypervisor

A Kubernetes DaemonSet that instruments every AI workload at runtime via a mutating admission webhook, with zero application code changes. Label a namespace, and coverage begins within minutes. Works across Python, Go, Node.js, Java, Ruby, and generic containers.

  • Parses every major model provider: Anthropic, OpenAI, AWS Bedrock, Azure OpenAI, Google Gemini, and more
  • Attributes every LLM call back to the originating user or session, across internal service hops
  • Real-time sensitive data detection: credit cards, SSNs, passport numbers, API keys, JWT tokens
  • Session kill switch by user subject or W3C trace ID, enforced at the kernel, no restart required
  • Agent behavior certificates that pin and enforce what each agent is permitted to do
  • Continuous compliance report: AI inventory, coverage heatmap, session logs, PII egress records
  • SIEM, SOAR, and ticketing integrations for findings and policy violations

EU AI Act enforcement starts in August 2026. If that's on your radar, AI Hypervisor generates the compliance evidence you'll need continuously, not on demand when an audit appears. Getting it running now means you won't be assembling spreadsheets in July.

Learn more in our documentation for AI Hypervisor and Infrastructure Discovery, or request a demo. 

Avatar of authorWallarm team