Connect with us

Tech News

Qualys launches AI-powered Web Application Scanning (WAS) with API security

Published

on

Web Application Scanning

Qualys has announced the launch of its API security platform that leverages AI-powered scanning and deep learning-based web malware detection to secure web apps and APIs across the entire attack surface, including on-premises web servers, databases, hybrid, multi-cloud environments, API gateways, containerized architectures, and microservices.

APIs are integral to digital transformation initiatives across industries. The latest data indicates that over 83% of web traffic now comprises API traffic, highlighting their critical role in modern web applications using microservices, cloud, and hybrid environments. However, this also underscores the vulnerabilities that accompany their widespread adoption. 

“Many organizations use a variety of security tools, such as SAST, DAST, SCA, or point solutions for API security that often operate in isolation, without a unified platform to integrate their findings. Moreover, the absence of integration between these tools leads to a fragmented view of the application security posture and results in uncoordinated efforts and gaps in security coverage. Similarly, SAST & DAST tools offer limited coverage for API-specific issues and focus predominantly on code vulnerabilities,” commented Kunal Modasiya, Vice President, Product Management, CyberSecurity Asset Management, Qualys. “Mainly, these solutions fail to extend their assessment to the runtime or environmental threats where APIs operate and provide visibility into the vulnerabilities of the underlying infrastructure hosting these APIs, leaving significant security gaps at the network and host levels.”

Qualys API security addresses and allows organizations to:

  • Measure API risks across all attack surfaces with a unified view of API security by discovering & monitoring every API asset across diverse environments, enabling better decision-making and faster response times.
  • Communicate API risks like OWASP API Top 10 vulnerabilities & drift from OpenAPI specs with real-time threat detection and response, minimizing the risk window and enhancing overall security.
  • Eliminate API risks with integrated workflows supporting Shift-Left & Shift-Right practices, bridging the gap between IT and security teams, promoting seamless collaboration, and improving operational efficiency.

Key features of Qualys API

1. Comprehensive API discovery and inventory management

Qualys WAS with API Security automatically identifies and catalogs all APIs within an organization’s network, including internal, external, undocumented, rogue, and shadow APIs. Whether APIs are deployed in multi-cloud environments (AWS, Azure), containerized architectures (Kubernetes), or API gateways (Apigee, Mulesoft), Qualys’ continuous discovery ensures an updated inventory across all platforms, preventing unauthorized access points and shadow APIs.

2. API vulnerability testing & AI-powered scanning

Qualys provides comprehensive API vulnerability testing using 200+ prebuilt signatures to detect API-specific security vulnerabilities, including those listed in the OWASP API Top 10, such as rate limiting, authentication & authorization issues, PII collection, and sensitive data exposure. Moreover, for large applications, Qualys combines the power of deep learning and AI-assisted clustering to perform efficient vulnerability scans. This smart clustering mechanism targets critical areas, achieving a 96% detection rate with an 80% reduction in scan time.

3. API compliance monitoring

Qualys performs both active and passive compliance monitoring to identify and address any drift or inconsistencies in API implementation and documentation in adherence to the OpenAPI Specification (OAS v3). Clear, standardized API documentation, in adherence to OAS, ensures that shared documentation is easily understood by recipients, simplifies security assessments and enforcement, and enhances the accuracy of code, benefiting both automated tools and human developers. Qualys also continuously monitors APIs for compliance with industry standards such as PCI-DSS, GDPR, and HIPAA to ensure that APIs remain compliant with evolving regulations, avoiding potential fines and enhancing data protection.

4. API risk prioritization with TruRisk

Qualys leverages its proprietary TruRisk scoring system, which integrates multiple factors such as severity, exploitability, business context, and asset criticality to prioritize risks based on overall business impact, ensuring that the most critical vulnerabilities are addressed first. It also categorizes risks based on the OWASP API Top 10, helping organizations focus on the most prevalent and severe API security threats.

5. Seamless integration with Shift-Left and Shift-Right workflows

Qualys integrates seamlessly with existing CI/CD tools (e.g., Bamboo, TeamCity, Github, Jenkins, Azure DevOps) and IT ticketing systems (e.g., Jira, ServiceNow), supporting both shift-left and shift-right security practices. This facilitates automated security testing and real-time threat detection and response without disrupting development workflows. By bridging the gaps between IT and security teams, Qualys ensures smoother operational transitions, improving API security practices and reducing the risk window.

Tech News

ATERMES and IEC secure Landmark Contract to Deploy AI-Powered Bird Repelling System at Lahore Airport

Published

on

A close-up view of ATERMES' SURICATE AI-enabled multi-sensor surveillance camera system, featuring an optical lens and sensor housing.

ATERMES, a French leader in advanced surveillance and security solutions, announces in partnership with The Imperial Electric Company (IEC), the award of a major contract by the Pakistan Airports Authority (PAA) for the deployment of a state-of-the-art Bird Repelling System (BRS) at Lahore International Airport.

This milestone project represents a first-of-its-kind integrated solution combining SURICATE, ATERMES’ advanced AI-enabled multi-sensor surveillance system, with acoustic and laser deterrence technologies. The system delivers a fully automated, intelligent, and environmentally friendly approach to mitigating bird-strike risks; one of aviation’s most persistent safety challenges.

The SURICATE system, developed by ATERMES in France, brings together cutting-edge optronics, embedded AI, and edge computing to continuously monitor airfields, identify potential avian threats in real time, and automatically activate deterrence mechanisms.

Once a bird threat is detected by the system’s deep-learning algorithms, SURICATE autonomously triggers the surrounding acoustic and laser repellers, driving the birds away from critical flight zones such as runways and taxiways.

This unique synergy between AI-based detection and automated multi-modal deterrence marks a turning point in airport security and environmental protection. Unlike traditional manual or time-based repelling systems, the BRS for Lahore Airport operates only when necessary, optimizing energy use and minimizing disturbance to the surrounding ecosystem.

Lionel Thomas, Chairman of ATERMES, stated: “This project is not just about technology; it’s about redefining how airports ensure safety through intelligence. By merging AI, optics, and deterrence, we’re transforming bird control into a predictive, autonomous, and eco-responsible process.”

Sajid Jamal, Executive Director of The Imperial Electric Company, added: “Our partnership with ATERMES reflects Pakistan’s growing commitment to embracing advanced, AI-driven safety systems. Lahore will become the first airport in the region equipped with such an integrated and intelligent Bird Repelling System.”

The project underscores a strong collaboration between France and Pakistan in technological innovation. ATERMES will provide the detection and control systems, while IEC, a key player in Pakistan’s engineering and infrastructure sectors, will oversee integration, installation, and local support. Together, they will ensure the delivery of a robust, scalable, and sustainable system that sets a benchmark for other international airports in the region.

Continue Reading

Tech News

Ramco Systems Celebrates 20 Years in the Middle East, Unveils Vision for the Future at Milestone Event

Published

on


Doubles down on AI-native applications and localized innovation to shape enterprise technology in the region


Ramco Systems, aglobal enterprise software company offering next-generation SaaS-enabled platforms and products, celebrated two decades of powering enterprise transformation in the Middle East. To mark this milestone, Ramco hosted Ramco@20 – Experience That Matters, a full-day event in Dubai designed to showcase its regional journey, highlight cutting-edge innovations, and bring customers and industry leaders together for forward-looking discussions.

The first half of Ramco@20 convened senior HR and payroll leaders from across the region for a thought leadership forum on the future of employee experience. Industry leaders discussed how enterprises in the Middle East are moving beyond traditional HR process optimization toward more intelligent, intuitive, and employee-centric models of workforce management. Conversations explored balancing automation with empathy, using AI thoughtfully, and elevating payroll as a trust-building touchpoint.

The second half welcomed a large gathering of customers across business units – Global Payroll, Aviation MRO, ERP, Services Resource Planning and Logistics – along with partners, and industry influencers, for a celebration honouring the relationships that have defined Ramco’s two-decade journey. Ramco’s leadership unveiled its technology vision: shifting from Systems of Record to Systems of Intelligence through AI-native applications, agentic workflows, and conversational UX. The leadership’s address also emphasized its investments in platform modernization and localized initiatives, while outlining a roadmap to further strengthen Ramco’s focus for the next 20 years.

Abinav Raja, Managing Director, Ramco Systems, said, “The Middle East has been a cornerstone of Ramco’s growth story for two decades and has shaped our thinking in profound ways. The region’s appetite for transformation has inspired us to design solutions that combine global best practices with local relevance. This milestone is built on the trust and partnership of our customers, and our commitment is clear: double down on AI-native, API-first applications that incorporate special features aligned with the region, platform modernization, and customer-centricity. We are shaping the future of enterprise technology with solutions enabling businesses to focus on what truly matters: growth and people.”

Sandesh Bilagi, Chief Operating Officer, Ramco Systems, said, “Our presence in the Middle East has been built on strong partnerships and a commitment to delivering outcomes. This region is not merely a market for us, but also a proving ground for ideas that redefine global enterprise technology.  The presence of all our business units in this region makes the Middle East a key pillar and reflects the confidence our customers have placed in us for twenty years.“

“Our investments in agentic AI, conversational UX, and platform innovation are designed to deliver enterprise applications that are intuitive, secure, scalable and integrate regional nuances,” Bilagi added. “We also focus on customer-focused initiatives like local deployment and training because every digital journey is, at its core, a human journey. The region is setting global benchmarks, and we are proud partners of the next era of enterprise innovation.”

Over the past two decades, Ramco has partnered with leading enterprises across the region, enabling digital transformation through innovative solutions. Its work in the Middle East has been shaped by sectors and functions that demand precision at scale – payroll, aviation, manufacturing, conglomerates, trading, infrastructure, professional services and logistics – giving Ramco an execution depth that continues to define its competitiveness in the region.

Continue Reading

Tech News

Vertiv and Caterpillar announce Energy Optimization Collaboration to Expand End-to-End Power and Cooling Offerings for AI Data Centers

Published

on

Vertiv, a global leader in critical digital infrastructure, and Caterpillar Inc. (NYSE: CAT), a global leader in power systems, today announced the signing of a strategic undertaking to collaborate on advanced energy optimization solutions for data centers. This initiative will integrate Vertiv’s power distribution and cooling portfolio with Caterpillar’s, and its subsidiary Solar Turbines’, product and expertise in power generation and CCHP (Combined Cooling, Heat and Power) to deliver pre-designed architectures that simplify deployment, accelerate time-to-power and optimize performance for data center operations.

A Powerful Collaboration:

This collaboration directly addresses the growing demand for on-site energy solutions that deliver reliable power and cooling. Together, the companies are able to offer a fully integrated solution with validated interfaces and performance, enabling customers to accelerate design, installation and deployment.

  • Caterpillar and Solar Turbines will supply power generation solutions, such as natural gas turbines and reciprocating engines, to deliver dependable, scalable electric power and thermal energy for CCHP.
  • Vertiv will provide a complete portfolio of power and cooling solutions and services, packaged as modular, pre-designed blocks, to shorten design cycles and standardize deployment.

The Customer Advantages:

  • Accelerates Time-to-Power – by utilizing predesigned, modular reference architectures to speed up deployment time.
  • Lowers PUE (Power Usage Effectiveness) – enables improved energy efficiency and carbon footprint because the system is optimized end-to-end: power, cooling, distribution and dynamic load management, compared to traditional design.
  • Global lifecycle support – the offering is backed by the trusted, global service and support networks of both Vertiv and Caterpillar.

“This collaboration with Caterpillar and Solar Turbines is a cornerstone of our Bring Your Own Power & Cooling (BYOP&C) strategy and aligns seamlessly with our grid-to-chip framework by offering resilient, on-site power generation solutions. This is optimal for customers looking to reduce or eliminate grid dependence,” said Gio Albertazzi, CEO, at Vertiv. “By combining our complementary technologies, portfolios and expertise, we are enabling coordinated integration. Our pre-engineered, interoperability-tested building blocks let customers execute design, build and deploy concurrently, with predictable system performance.”

“As AI-driven workloads continue to accelerate, the demand for robust and scalable power infrastructure and cooling is becoming increasingly critical,” said Jason Kaiser, group president of Caterpillar Power & Energy. “Our collaboration with Vertiv will enable us to deliver integrated, on-site energy solutions that lower PUE and meet customers’ evolving needs.”

This initiative directly addresses the growing demand for on-site energy solutions and offers a coordinated, customer-first approach to solution design and implementation. The Vertiv and Caterpillar Memorandum of Understanding (MOU) represents a pivotal step in further refining this ecosystem, enabling customers to overcome energy constraints and deploy optimized AI centers.

Continue Reading

Trending

Copyright © 2023 | The Integrator