Connect with us

Tech News

Qualys launches AI-powered Web Application Scanning (WAS) with API security

Published

on

Web Application Scanning

Qualys has announced the launch of its API security platform that leverages AI-powered scanning and deep learning-based web malware detection to secure web apps and APIs across the entire attack surface, including on-premises web servers, databases, hybrid, multi-cloud environments, API gateways, containerized architectures, and microservices.

APIs are integral to digital transformation initiatives across industries. The latest data indicates that over 83% of web traffic now comprises API traffic, highlighting their critical role in modern web applications using microservices, cloud, and hybrid environments. However, this also underscores the vulnerabilities that accompany their widespread adoption. 

“Many organizations use a variety of security tools, such as SAST, DAST, SCA, or point solutions for API security that often operate in isolation, without a unified platform to integrate their findings. Moreover, the absence of integration between these tools leads to a fragmented view of the application security posture and results in uncoordinated efforts and gaps in security coverage. Similarly, SAST & DAST tools offer limited coverage for API-specific issues and focus predominantly on code vulnerabilities,” commented Kunal Modasiya, Vice President, Product Management, CyberSecurity Asset Management, Qualys. “Mainly, these solutions fail to extend their assessment to the runtime or environmental threats where APIs operate and provide visibility into the vulnerabilities of the underlying infrastructure hosting these APIs, leaving significant security gaps at the network and host levels.”

Qualys API security addresses and allows organizations to:

  • Measure API risks across all attack surfaces with a unified view of API security by discovering & monitoring every API asset across diverse environments, enabling better decision-making and faster response times.
  • Communicate API risks like OWASP API Top 10 vulnerabilities & drift from OpenAPI specs with real-time threat detection and response, minimizing the risk window and enhancing overall security.
  • Eliminate API risks with integrated workflows supporting Shift-Left & Shift-Right practices, bridging the gap between IT and security teams, promoting seamless collaboration, and improving operational efficiency.

Key features of Qualys API

1. Comprehensive API discovery and inventory management

Qualys WAS with API Security automatically identifies and catalogs all APIs within an organization’s network, including internal, external, undocumented, rogue, and shadow APIs. Whether APIs are deployed in multi-cloud environments (AWS, Azure), containerized architectures (Kubernetes), or API gateways (Apigee, Mulesoft), Qualys’ continuous discovery ensures an updated inventory across all platforms, preventing unauthorized access points and shadow APIs.

2. API vulnerability testing & AI-powered scanning

Qualys provides comprehensive API vulnerability testing using 200+ prebuilt signatures to detect API-specific security vulnerabilities, including those listed in the OWASP API Top 10, such as rate limiting, authentication & authorization issues, PII collection, and sensitive data exposure. Moreover, for large applications, Qualys combines the power of deep learning and AI-assisted clustering to perform efficient vulnerability scans. This smart clustering mechanism targets critical areas, achieving a 96% detection rate with an 80% reduction in scan time.

3. API compliance monitoring

Qualys performs both active and passive compliance monitoring to identify and address any drift or inconsistencies in API implementation and documentation in adherence to the OpenAPI Specification (OAS v3). Clear, standardized API documentation, in adherence to OAS, ensures that shared documentation is easily understood by recipients, simplifies security assessments and enforcement, and enhances the accuracy of code, benefiting both automated tools and human developers. Qualys also continuously monitors APIs for compliance with industry standards such as PCI-DSS, GDPR, and HIPAA to ensure that APIs remain compliant with evolving regulations, avoiding potential fines and enhancing data protection.

4. API risk prioritization with TruRisk

Qualys leverages its proprietary TruRisk scoring system, which integrates multiple factors such as severity, exploitability, business context, and asset criticality to prioritize risks based on overall business impact, ensuring that the most critical vulnerabilities are addressed first. It also categorizes risks based on the OWASP API Top 10, helping organizations focus on the most prevalent and severe API security threats.

5. Seamless integration with Shift-Left and Shift-Right workflows

Qualys integrates seamlessly with existing CI/CD tools (e.g., Bamboo, TeamCity, Github, Jenkins, Azure DevOps) and IT ticketing systems (e.g., Jira, ServiceNow), supporting both shift-left and shift-right security practices. This facilitates automated security testing and real-time threat detection and response without disrupting development workflows. By bridging the gaps between IT and security teams, Qualys ensures smoother operational transitions, improving API security practices and reducing the risk window.

Tech News

FVC and SearchInform Join Forces to Boost Insider Threat Prevention and Data Protection in MENA

Published

on

FVC and SearchInform Join Forces to Boost Insider Threat Prevention and Data Protection in MENA

FVC, a prominent distributor specialising in innovative technology solutions, is pleased to announce its strategic partnership with SearchInform, a leader in information security and insider threat prevention solutions. Together, they are committed to strengthening organizations’ defenses against data leaks, corporate fraud, human-factor related risks.

K.S. Parag, Managing Director, FVC:

“We are excited to welcome SearchInform to our cybersecurity portfolio. The company offers the most powerful and localized DLP on the MENA market. SearchInform solution stands out from the competition due to a number of advantages. The system can be deployed within a few hours, protects the maximum number of data transfer channels, provides smart content-based blocking for all controlled channels and also use digital watermarks to trace the source of potential leaks. SearchInform DLP supports analysis of data in Arabic and has security policies, tailored for requirements of local organizations, enabling timely detection and prevention of confidential data leaks. The solution leverages AI to monitor atypical data transfer channels, recognize graphic elements, transcribe audio into text, detect attempts to photograph PC screens with smartphones.”

SearchInform offers a range of products, including DCAP, DLP, and SIEM. All the tools are seamlessly integrated. Technical support is provided through a specialist assigned to the company, who has extensive experience thanks to clients from various fields.

Commenting on the Partnership, Artem Volodin, CEO SearchInform MENA, stated:

“We are proud to collaborate with FVC, whose expertise in the Middle Eastern market will strengthen our efforts to combat insider threats and data leaks. The region needs a comprehensive solution that will enable organizations to meet regulatory standards, including SAMA, PDPL, DCC, ECC, UAE Information Assurance (IA) Regulation etc. and global ones, such as GDPR, PCI DSS. SearchInform delivers tools for data protection and risk mitigation across all levels: FileAuditor secures file systems, DLP covers workstations and human risks, Risk Monitor addresses corporate fraud, and SIEM protects IT infrastructure.”

The partners are currently conducting expert training, partner enablement sessions, and are also negotiating the implementation of SearchInform products in local companies.

Continue Reading

Tech News

Etihad Salam and AFR-IX telecom Join Forces to Boost Intercontinental Digital Links Across Europe, Middle East, and Africa 

Published

on

Etihad Salam and AFR-IX telecom Join Forces

Etihad Salam, a premier telecommunications and digital infrastructure company in Saudi Arabia, has entered into a strategic with AFR-IX telecom, an infrastructure and telecom operator and the developer and operator of the Medusa Submarine Cable System.

This collaboration aims to elevate digital connectivity spanning Europe, North Africa, the Middle East, Gulf Cooperation Council (GCC) countries, and Asia.  Through this agreement, Etihad Salam becomes the primary landing and interconnection hub for the Medusa system within Saudi Arabia through Aqaba (Jordan), solidifying the Kingdom’s position as a pivotal digital gateway connecting Asia, Europe, and Africa.

The partnership introduces resilient, high-bandwidth, and low-latency pathways from the Mediterranean to the Arabian Peninsula, fostering expansion for hyperscale data centers, cloud service providers, and digital operators throughout the region. 

With this partnership, Etihad Salam will deliver terrestrial backhaul services and capacity swapping to seamlessly incorporate Medusa’s network into Saudi Arabia and the broader GCC, and onward to Asia. This initiative represents a significant advancement in Etihad Salam’s global cable strategies and underscores its dedication to Saudi Vision 2030’s goals for digital innovation and economic diversification. 

Medusa Submarine Cable System is an 8,760 km undersea cable network linking critical points in the Mediterranean, such as Spain, France, Italy, Malta, Greece, Cyprus, Morocco, Algeria, Tunisia, Libya and Egypt. Engineered for high-speed, reliable data transfer between Europe, North Africa, and the Middle East, Medusa delivers up to 480 Tbps of capacity, serving as a vital conduit for surging intercontinental data flows. 

Quote from Salam

“Our partnership with Medusa underscores Salam’s commitment to positioning Saudi Arabia as a central hub for regional connectivity,” stated Amjad Arab, Chief Wholesale and Alliances Officer at Etihad Salam. “By linking the Medusa cable to our robust infrastructure, we’re creating innovative international routes that expand our worldwide presence and meet the surging needs for digital and cloud services in the Kingdom. Through this partnership, we seek to offer enriched connectivity services, experiences and bring the world closer, ultimately empowering businesses to scale and innovative in an increasingly digital landscape.” 

Quote from AFR-IX telecom

“We’re excited to collaborate with Etihad Salam, whose expertise and network complement our objective of providing secure, expansive, and high-performance connectivity from the Mediterranean outward,” said Norman Albi, Chief Executive Officer of AFR-IX. “This partnership elevates reliability and coverage for carriers worldwide, driving forward digital advancement across Europe, Africa, and the Middle East.” 

Continue Reading

Tech News

Infinia Technologies and Satya Retail Launch AI and Blockchain-Powered Retail Transformation at GITEX 2025

Published

on

  • Revolutionizes India’s retail market by empowering merchants with first time real use case of AI and Blockchain
  • SAII is a world’s first initiative set to turn millions of low-tech, high-potential neighbourhood retailers into a data-rich, AI-enabled commerce network



Infinia Technologies, a subsidiary of Sirius International Holding, announced a strategic partnership with Satya Retail, a DS Group affiliate, at GITEX Global 2025, the world’s largest technology and innovation event in Dubai. Through this collaboration, Infinia Technologies aims to leverage its advanced AI operating ecosystem to power Satya Retail’s merchant network with AI-driven analytics, blockchain-based invoicing, and digital financial tools, transforming India’s retail landscape.

By combining Infinia Technologies’ AI and blockchain infrastructure with DS Group’s unmatched distribution expertise and Satya Retail’s deep merchant network, this initiative will create an intelligent, scalable, and inclusive retail ecosystem designed to empower millions of small businesses across the country. The official signing took place today at GITEX Global 2025, in the presence of Arif Khan, CEO of Infinia Technologies, along with Ritesh Kumar, Director at DS Group.

The collaboration marks the launch of SAII – Smart AI Integrator, a world’s first initiative that turns millions of low-tech, high-potential neighbourhood retailers into a data-rich, AI-enabled commerce network. Branded as “The Digital Saathi for Merchants,” SAII provides a single platform for all merchant needs; from blockchain-based e-invoicing and micro-financing to insurance, hyperlocal advertising with two-way data transfer for merchants and vendor network.

For the first time, India’s retailers will receive access to powerful digital capabilities at scale through SAII. It will help merchants operate smarter, improve efficiency, and build deeper partnerships across the supply chain.

Commenting on the announcement, Arif Khan, CEO of Infinia Technologies, said: “This partnership represents a defining moment in how AI and Blockchain can drive real-world impact. This collaboration will positively accelerate India’s digital economy. Through SAII, we’re enabling millions of India’s retailers to access intelligent tools and digital services that were once out of reach, while advancing our mission to take advanced AI from Abu Dhabi to the world. This is only the beginning; we plan to extend the SAII model across Asia, the Middle East, and North Africa, with more projects to be announced soon.”

Ritesh Kumar, Director at DS Group added: “Our collaboration with Infinia Technologies brings together the strength of our retail network and their AI innovation to empower small businesses across India. SAII will help local merchants modernize their operations, access financial and digital tools seamlessly, and become part of a larger connected commerce ecosystem. This is a major step toward building a more inclusive and technology-driven retail economy.”

Continue Reading

Trending

Copyright © 2023 | The Integrator