Fastly Blog (Security)
Fastly's edge cloud platform helps the world's most popular digital businesses keep pace with their customer expectations by delivering fast, secure, and scalable online experiences.
Updated: 3 min 59 sec ago
Stopping Bad Bots Without Blocking the Good Ones
Keep trusted automation running while blocking malicious bots. Learn how precise WAF controls reduce false positives without weakening security.
Categories: Software Security
You own your availability: resilience in the age of third-party dependencies
When third-party services fail, your website — and revenue — can fail with them. Learn how to uncover hidden dependencies and use edge proxying to maintain uptime, performance, and control during outages.
Categories: Software Security
DDoS in December 2025
Learn how sophisticated Layer 7 and network DDoS attacks evolved in December 2025, including the year’s largest attack and mitigation strategies.
Categories: Software Security
Streamlining User Experiences While Fighting Bots
Streamline user experiences and fight bots with Fastly's new embedded challenges for Bot Management.
Categories: Software Security
Building Resilient Applications with Layered Security
Fastly's new security packages make layered application security easier to buy, use, and grow. Protect your apps with predictable pricing.
Categories: Software Security
From AI Crawlers to Headless Bots: How Automated Traffic is Changing the Web
Bots now drive nearly a third of web traffic. Learn how AI crawlers and headless bots are reshaping security, performance, and business decisions.
Categories: Software Security
IDC Study Reveals 3X Gains from Modern AppSec Programs
An IDC study reveals that modern AppSec programs achieve 3X better business outcomes and are almost 2X less likely to experience a data breach.
Categories: Software Security
The Sleep Test: How Embracing Chaos Unlocks API Resilience
Learn how Fastly's API Discovery and new Inventory feature unlock API resilience for platform engineers by embracing chaos and strategic, thoughtful planning.
Categories: Software Security
React2Shell Continued: What to know and do about the 2 latest CVEs
In the wake of the critical severity React2Shell CVEs, two new CVEs exploiting similar Next.js and React components were announced on December 11. Learn more about these new CVEs.
Categories: Software Security
DDoS in November
DDoS attackers were largely absent on Black Friday 2025. Fastly’s latest report reveals why, and what the shifting attack patterns mean for your apps and APIs.
Categories: Software Security
Black Friday is Dead, Long Live Black Fridays: Cyber 5 Traffic Insights
Black Friday isn’t the traffic spike it used to be. Fastly’s data shows holiday demand now stretches across all of November. Here’s what Cyber 5 2025 really looked like.
Categories: Software Security
How React2Shell is evolving: Industries and regions targeted
Fastly is seeing sustained React2Shell attacks across all industries and regions. Learn what’s happening and the critical steps enterprises should take to patch vulnerable apps.
Categories: Software Security
Fastly’s Proactive Protection for Critical React RCE CVE-2025-55182 and CVE-2025-66478
Protect your apps from the critical React RCE bugs (CVE-2025-55182/66478). Fastly's NGWAF Virtual Patch provides proactive defense.
Categories: Software Security
Mitigating DDoS attacks faster and with even more accuracy
Learn how Fastly's Adaptive Threat Engine update for DDoS Protection boosts mitigation accuracy and reduces Mean Time to Mitigation by 72% for the holidays.
Categories: Software Security
Outages, Attacks, and a Need for Resilience
Cloud outages are a stark reminder of our digital economy's fragility. Learn how Fastly mitigated a major traffic failover and concurrent DDoS attacks with zero disruption.
Categories: Software Security
Wikipedia Tells AI Companies to "Stop Scraping"
Wikipedia cracks down on AI scraping, citing server strain and lost traffic. See why publishers are fighting back and turning to bot management.
Categories: Software Security
The New 2025 OWASP Top 10 List: What Changed, and What You Need to Know
The 2025 OWASP Top 10 list is here! Discover what changed, the two new categories, and how to secure your applications against emerging threats.
Categories: Software Security
Increasing the accessibility of managed security services
Make world-class protection accessible. Fastly’s new Managed Security Professional delivers 24/7 expert defense for your most critical apps and APIs.
Categories: Software Security
Your API Catalog Just Got an Upgrade
Discover, monitor, and secure your APIs with Fastly API Discovery. Get instant visibility, cut the noise, and keep your APIs secure and compliant.
Categories: Software Security
3 Costly Mistakes in App and API Security and How to Avoid Them
Avoid costly app and API security mistakes. Learn how to streamline WAF evaluation, estimate TCO, and embrace agile development for optimal security.
Categories: Software Security