Monday, 29 September 2025
30.2 C
Singapore
32.7 C
Thailand
29.7 C
Indonesia
28.2 C
Philippines

Thales enhances Imperva Application Security with new API threat detection and response capabilities

Thales updates Imperva Application Security with real-time API threat detection and response, tackling BOLA and business logic risks.

Thales has announced new capabilities in the Imperva Application Security platform, aimed at helping organisations detect and mitigate API-based attacks in real time. The update introduces integrated detection and response for threats such as Broken Object Level Authorisation (BOLA), which remains the top-ranked risk in the OWASP API Security Top 10.

The enhanced platform is designed to operate across both cloud and on-premise environments. It enables enterprises to address growing threats posed by unauthorised or outdated APIs and other business logic vulnerabilities while preserving performance and user experience.

Addressing rising threats from API traffic

APIs have become a key foundation for modern digital services, allowing businesses to streamline operations and offer personalised services at scale. According to Imperva Threat Research, APIs now represent 71% of all web traffic. The same report highlights a worrying trend—44% of advanced bot traffic is now directed at APIs, compared to just 10% targeting web applications.

This shift highlights the increasing appeal of APIs to threat actors, especially as these interfaces often handle sensitive or high-value data. One of the most critical risks is BOLA, a vulnerability that allows attackers to bypass authorisation checks and access data they should not see. When APIs do not correctly confirm a user’s permissions, malicious actors can exploit this to retrieve or manipulate restricted data objects.

“API security is no longer optional – it’s fundamental to maintaining business continuity and trust,” said Tim Chang, Global Vice President and General Manager of Application Security at Thales. “Imperva Application Security bridges the gap by delivering a fully unified platform that identifies business logic threats and actively blocks malicious sessions, setting a new benchmark for API protection.”

A unified and automated approach

With this update, the Imperva platform brings together several API security features into a single management console. This unified architecture allows security teams to oversee API discovery, threat assessment, detection, and response actions without relying on separate tools or risking operational delays.

The platform uses both behavioural analysis and rule-based systems to monitor API traffic patterns and spot anomalies. Suspicious or unauthorised API calls are flagged in real time, enabling prompt responses. Integration with Imperva Cloud WAF and WAF Gateway allows immediate enforcement, such as blocking malicious sessions directly as they occur. The platform also connects with existing automation tools to ensure rapid incident response.

This flexible deployment model supports enterprises operating in complex hybrid environments. Whether hosted in the cloud or on-premises, organisations can adapt the platform to their needs without disrupting service or slowing development cycles.

Delivering on the Imperva Security Anywhere vision

The latest updates reflect Thales’ broader goal of offering scalable and seamless application security under its Security Anywhere strategy. By integrating API detection and response capabilities into the core Imperva offering, the company aims to deliver end-to-end visibility into automated API threats across any environment.

The platform now supports detection and mitigation for BOLA threats, as well as unauthenticated and deprecated APIs, which are common attack vectors. This enables businesses to respond proactively before security lapses impact users or operations.

Detection and response to deprecated APIs, unauthenticated APIs, and BOLA attacks are now available as part of the Imperva Application Security platform.

Hot this week

Okta unveils new identity security tools to protect AI-driven enterprises and fight fraud

Okta introduces advanced identity security features to protect AI-driven enterprises and fight fraud with tamper-proof digital credentials.

YouTube to allow banned creators to apply for reinstatement

YouTube will allow banned creators to apply for reinstatement, ending lifetime bans for content related to COVID-19 and election misinformation.

Salesforce advances enterprise AI with new agent simulation, benchmarking and data tools

Salesforce introduces new AI simulation, benchmarking and data tools to help enterprises deploy reliable and sustainable AI agents.

OPPO showcases industry-leading on-device AI at Snapdragon Summit China

OPPO unveils record-breaking on-device AI speed and long-context capabilities at Snapdragon Summit China, advancing mobile AI privacy and performance.

The global E-E-A-T gap: Why authority does not always travel

Global brands often lose visibility abroad without local E-E-A-T signals. Learn why authority fails across borders and how to fix it.

Building the next-generation enterprise data centre

Enterprises in Southeast Asia must modernise data centres with AI-ready compute, NVMe-TCP storage, advanced cooling, and green standards.

China builds rival to US Project Stargate with US$37 billion data centre push

China launches a US$37 billion data centre project in Wuhu to rival Project Stargate, raising questions over chips, land use and sustainability.

Qualcomm unveils Snapdragon X2 Elite series to rival AMD and Intel

Qualcomm launches Snapdragon X2 Elite processors with up to 128GB of memory, 80 TOPS AI, and 5.0GHz speeds, aiming to rival AMD and Intel.

Pixel Buds Pro 2 receive adaptive audio and gesture controls in latest update

Google’s latest update adds adaptive audio, gesture controls, and more to the Pixel Buds Pro 2, enhancing sound quality and hands-free usability.

Related Articles

Popular Categories