Skip to main content
Web application firewall

Web application firewall

Search complete. 92 mentions across 27 episodes found for "Web application firewall".

Sep 11, 2026

Ben HarrisGUEST
4:23
Of course, one thing we've launched recently is our mitigation capability.
Ben HarrisGUEST
4:26
Given how quickly in the wild exploitation now happens, we're talking single-digit hours, because we've become, I think, well, uh, well used to kind of reproducing vulnerabilities at scale very quickly, especially now with the advent of AI, we can flip reproduction, so POCs, into WAF rules, IDS, IPS rules, and ultimately then push those automatically once we actually find a vulnerable VPN or mail server or similar.
Ben HarrisGUEST
4:49
So ultimately, uh, yeah-
Patrick GrayHOST
4:50
Yeah

6 MINS LATER

Patrick GrayHOST
10:30
Okay, that makes sense.
Patrick GrayHOST
10:31
I can s- absolutely see why someone would pay money for that, 100%.
Patrick GrayHOST
10:35
Um, the other side of this, though, is that there's, you know, you mentioned that there's, like, this WAF component to it, right? Is this a Watchtower-developed WAF that goes in front of an organization's applications, or are you just providing rules for existing WAFs? Like, how does that work?
Ben HarrisGUEST
10:48
So, so the big thing for us with mitigation at this point is that the challenge around remediation and kind of moving new things in is stability, availability, change controls for it.
Sam CurryGUEST
6:29
But
Ryan DonovanHOST
6:30
this is where the idea of WAF
Sam CurryGUEST
6:31
came from, the notion of web application firewalls.
Sam CurryGUEST
6:35
And at the same time, we can apply zero-trust principles, which is not just least privilege, which is what most people go to, it's also least function.
Aaron CampbellGUEST
21:33
If, um, if they're blocking at the network layer known bad actors, then some of those people don't even get the chance to try to break into your, uh, site.
Aaron CampbellGUEST
21:43
If they're then looking at requests that are coming in using some sort of WAF and identifying things like potential SQL injection, then even if your plugin h- is susceptible to that, it's maybe still safe.
Aaron CampbellGUEST
21:57
If they have something like Monarch that runs in the runtime layer that's looking at the behavior of the actual request and saying, "Oh, that looked safe, but what it's actually doing isn't," and it gets shut down there, again, your, your plugin, it doesn't matter if the plugin was vulnerable, it's you're protected anyway.
Aaron CampbellGUEST
22:19
Um, and, and, and I think that that kind of thing, you know, also things like virtual patching, you know, fixing your plugin for you even though you didn't realize it was needed.
Aaron CampbellGUEST
23:44
We, we, um, detect and remediate more malware than, than anyone else.
Aaron CampbellGUEST
23:50
Um, but, you know, you start by removing the malware, and then you say, "Well, how's that getting there?" And you, you know, you sort of move into the, the next layer up, looking at the, the runtime when, you know, PHP is actually writing the file to disk and being able to prevent that from happening.
Aaron CampbellGUEST
24:10
Um, and then stepping up into things like, well, when someone's doing that several times in a row, we should just block them at that network layer, and so our smart WAF does that.
Aaron CampbellGUEST
24:20
And so it's, it's really a layered approach for hosts.
Abby GobbinsGUEST
16:02
It's really low resource, and it means that you're completely covered for all of those user agents.
Abby GobbinsGUEST
16:06
Um, the other two things that I'd like to mention here, um, is double-checking, like, any WAF systems that you have.
Abby GobbinsGUEST
16:13
So for example, if you have CloudFair, uh, Cloudflare or Akamai, um, or any other kind of, like, similar web application firewalls, um, that are protecting your site, just making sure that you don't have any settings automatically turned on that you might need to toggle off.
Abby GobbinsGUEST
16:27
Um, so this could be, like, bot site mode, for example, um, or, or having AI scrapers and crawler toggle off.
BaluHOST
24:34
Option A, Amazon GuardDuty.
BaluHOST
24:36
Option B, AWS WAF.
BaluHOST
24:39
Option C, Amazon Inspector.
BaluHOST
24:42
And option D, AWS Shield Standard.
BaluHOST
24:45
Let's pause here.
BaluHOST
24:51
The correct answer is option B, AWS WAF, the web application firewall.
BaluHOST
24:57
And here's why it's right.
BaluHOST
24:59
WAF is a web application firewall that lets you create rules to filter web traffic.
speaker_0HOST
20:27
None at all.
speaker_0HOST
20:28
Number three, the application layer.
speaker_0HOST
20:30
Update your SuperForms and Elementor Pro WordPress plugins right now and tune your WAFs to look for base 64 anomalies to stop a massive wave of automated remote code execution attacks deploying web shells.
speaker_1HOST
20:42
Those are the immediate tactical actions to secure your environment today.
speaker_1HOST
20:46
But I want to leave you with a strategic thought to mull over as you look at your own network architecture.
Aaron D. CampbellGUEST
5:48
We protect more than just WordPress, but obviously WordPress is a big part of that.
Aaron D. CampbellGUEST
5:53
And we help hosts keep their users, their end users, safe and secure and malware-free by monitoring the files, the runtime, having a WAF layer, sort of protecting it several different layers along the way.
Nathan WrigleyHOST
6:08
So is this kind of like a white label solution? You're in talks with hosts, many of which I'm sure we've heard of, but their purchase of the products and services that you sell is kind of white labeled? Yes, they may sell us as their
Aaron D. CampbellGUEST
6:21
own security product.
Aaron D. CampbellGUEST
5:48
We protect more than just WordPress, but obviously WordPress is a big part of that.
Aaron D. CampbellGUEST
5:53
And we help hosts keep their users, their end users, safe and secure and malware-free by monitoring the files, the runtime, having a WAF layer, sort of protecting it several different layers along the way.
Nathan WrigleyHOST
6:08
So is this kind of like a white label solution? You're in talks with hosts, many of which I'm sure we've heard of, but their purchase of the products and services that you sell is kind of white labeled? Yes, they may sell us as their
Aaron D. CampbellGUEST
6:21
own security product.
speaker_3UNKNOWN
12:20
Huskies is taking on a really interesting challenge.
speaker_3UNKNOWN
12:23
They're reinventing the Web Application Firewall, or WAF, layer.
speaker_3UNKNOWN
12:29
That technology was invented in Israel almost 30 years ago and has barely changed since.
speaker_3UNKNOWN
12:35
Huskies is injecting agentic AI into that infrastructure to modernize it.
Ryan LucasHOST
28:23
Like you've got these rules and, you know, there's certain rules.
Ryan LucasHOST
28:25
You only get certain capacities per like, I mean, mostly in WAF, not so much in network firewalls, but you know, like it's a thing that is nice to have when you need the metric to know if it's actually being hit or not.
Justin BrodleyHOST
28:41
AWS is launching their local zone in Las Vegas.
Justin BrodleyHOST
28:43
We talked about it when it was announced, but it's finally ready.

17 more episodes mention Web application firewall.

Create an account to see the whole feed, search across every transcript, and follow the entities you care about.

We value your privacy

We use cookies to understand how you use our platform and to improve your experience. Click “Accept All” to consent, or “Decline non-essential” to opt out of non-essential cookies. Read our Privacy Policy.