Connect with us

Tech News

Qualys launches AI-powered Web Application Scanning (WAS) with API security

Published

on

Web Application Scanning

Qualys has announced the launch of its API security platform that leverages AI-powered scanning and deep learning-based web malware detection to secure web apps and APIs across the entire attack surface, including on-premises web servers, databases, hybrid, multi-cloud environments, API gateways, containerized architectures, and microservices.

APIs are integral to digital transformation initiatives across industries. The latest data indicates that over 83% of web traffic now comprises API traffic, highlighting their critical role in modern web applications using microservices, cloud, and hybrid environments. However, this also underscores the vulnerabilities that accompany their widespread adoption. 

“Many organizations use a variety of security tools, such as SAST, DAST, SCA, or point solutions for API security that often operate in isolation, without a unified platform to integrate their findings. Moreover, the absence of integration between these tools leads to a fragmented view of the application security posture and results in uncoordinated efforts and gaps in security coverage. Similarly, SAST & DAST tools offer limited coverage for API-specific issues and focus predominantly on code vulnerabilities,” commented Kunal Modasiya, Vice President, Product Management, CyberSecurity Asset Management, Qualys. “Mainly, these solutions fail to extend their assessment to the runtime or environmental threats where APIs operate and provide visibility into the vulnerabilities of the underlying infrastructure hosting these APIs, leaving significant security gaps at the network and host levels.”

Qualys API security addresses and allows organizations to:

  • Measure API risks across all attack surfaces with a unified view of API security by discovering & monitoring every API asset across diverse environments, enabling better decision-making and faster response times.
  • Communicate API risks like OWASP API Top 10 vulnerabilities & drift from OpenAPI specs with real-time threat detection and response, minimizing the risk window and enhancing overall security.
  • Eliminate API risks with integrated workflows supporting Shift-Left & Shift-Right practices, bridging the gap between IT and security teams, promoting seamless collaboration, and improving operational efficiency.

Key features of Qualys API

1. Comprehensive API discovery and inventory management

Qualys WAS with API Security automatically identifies and catalogs all APIs within an organization’s network, including internal, external, undocumented, rogue, and shadow APIs. Whether APIs are deployed in multi-cloud environments (AWS, Azure), containerized architectures (Kubernetes), or API gateways (Apigee, Mulesoft), Qualys’ continuous discovery ensures an updated inventory across all platforms, preventing unauthorized access points and shadow APIs.

2. API vulnerability testing & AI-powered scanning

Qualys provides comprehensive API vulnerability testing using 200+ prebuilt signatures to detect API-specific security vulnerabilities, including those listed in the OWASP API Top 10, such as rate limiting, authentication & authorization issues, PII collection, and sensitive data exposure. Moreover, for large applications, Qualys combines the power of deep learning and AI-assisted clustering to perform efficient vulnerability scans. This smart clustering mechanism targets critical areas, achieving a 96% detection rate with an 80% reduction in scan time.

3. API compliance monitoring

Qualys performs both active and passive compliance monitoring to identify and address any drift or inconsistencies in API implementation and documentation in adherence to the OpenAPI Specification (OAS v3). Clear, standardized API documentation, in adherence to OAS, ensures that shared documentation is easily understood by recipients, simplifies security assessments and enforcement, and enhances the accuracy of code, benefiting both automated tools and human developers. Qualys also continuously monitors APIs for compliance with industry standards such as PCI-DSS, GDPR, and HIPAA to ensure that APIs remain compliant with evolving regulations, avoiding potential fines and enhancing data protection.

4. API risk prioritization with TruRisk

Qualys leverages its proprietary TruRisk scoring system, which integrates multiple factors such as severity, exploitability, business context, and asset criticality to prioritize risks based on overall business impact, ensuring that the most critical vulnerabilities are addressed first. It also categorizes risks based on the OWASP API Top 10, helping organizations focus on the most prevalent and severe API security threats.

5. Seamless integration with Shift-Left and Shift-Right workflows

Qualys integrates seamlessly with existing CI/CD tools (e.g., Bamboo, TeamCity, Github, Jenkins, Azure DevOps) and IT ticketing systems (e.g., Jira, ServiceNow), supporting both shift-left and shift-right security practices. This facilitates automated security testing and real-time threat detection and response without disrupting development workflows. By bridging the gaps between IT and security teams, Qualys ensures smoother operational transitions, improving API security practices and reducing the risk window.

Tech News

9Z Globant Joins Elite Global Esports Network as Official Partner of the Esports Foundation

Published

on

Globant (NYSE: GLOB), a digitally native company that helps organizations thrive in a digital and AI-powered future, today announced that its 9Z Globant esports organization has been selected as an Official Partner of the Esports Foundation, one of only 40 organizations worldwide to earn this distinction. Beyond the partnership recognition, 9Z Globant has earned its place on the competitive stage through sport merit alone, qualifying for the Esports World Cup 2026, the most prestigious event in global competitive gaming, hosted in Paris.

Founded in Argentina in 2018, 9Z Globant has rapidly grown into a globally recognized brand in esports, combining elite competitive performance, content creation, and a deep-rooted connection with the next generation of fans.

“Saudi Arabia’s investment in esports has created a platform for organizations like 9Z Globant to compete and grow on the world stage. Esports is no longer a niche, it’s a multi-billion dollar industry that moves culture, drives engagement, and builds communities at a scale few sectors can match. Being part of its growth in the Kingdom, alongside an organization that has earned its place on the global stage, is exactly the kind of opportunity that defines what Globant is here to do,” said Federico Pienovi, CEO of MENA & APAC at Globant.

The Esports Foundation Partner Program represents the highest tier of recognition in global competitive gaming, a rigorously curated cohort of organizations proven to shape the industry’s future at scale. While partnership status does not guarantee competition, each of the 25 titles featured at the Esports World Cup demands qualification through its own dedicated competitive circuit, a standard rooted in the Foundation’s guiding principle: Rise Above. 9Z Globant has risen to that challenge: the team has already secured its place on the Paris stage across three premier disciplines: EA SPORTS FC, Overwatch, and Counter-Strike 2. 9Z Globant’s qualification across multiple titles signals the kind of multi-dimensional, high-performance organization that the Esports Foundation was built to elevate.

“Saudi Arabia has established itself as one of the world’s leading hubs for the future of esports. Seeing 9Z Globant join the Esports Foundation ecosystem is a recognition of everything the organization has built over the past few years. At Globant, we’re proud to support that journey and help create new opportunities for players, creators, and fans as competitive gaming continues to grow on a global scale,” said Kevin Janzen, CEO of Gaming & Education AI Studio at Globant.

The Esports World Cup 2026 will bring together the best teams across multiple titles, in front of massive global audiences. “This is bigger than one team, and bigger than one country. 9Z Globant represents a generation of Latin American players, creators, and fans who always knew this moment would come. We have the talent, the hunger, and now the stage to prove it to the world. Competing at the Esports World Cup is the realization of something an entire continent has been building toward,  and we are just getting started,” said Francisco Postiglione, Founder & CEO of 9Z Globant.

Beyond the Esports World Cup, 9Z Globant has cemented its place among global elite competitors. The team recently secured qualification for the Counter-Strike Major,  the most prestigious tournament in one of the world’s most-watched esports titles, making it the only Argentine team to achieve this milestone.

Saudi Arabia has positioned itself as a driving force in global esports, with visionary investment and an extraordinary commitment to elevating competitive gaming worldwide. 9Z Globant’s partnership with the Esports Foundation is a natural convergence: two rising forces in the global gaming world, united by a shared ambition to push boundaries. Looking ahead, 9Z Globant is committed to going beyond competition, actively exploring opportunities through the Foundation’s global network to identify and develop emerging talent, fostering the next generation of players who can compete on the world’s biggest esports stages.

Continue Reading

Tech News

NETSCOUT STRENGTHENS OPERATIONAL RESILIENCE OF CRITICAL INFRASTRUCTURE AGAINST AI-DRIVEN, INTERNET-SCALE DDoS ATTACKS

Published

on

NETSCOUT® (NASDAQ: NTCT), a leading provider of observability, AIOps, cybersecurity, and DDoS attack protection solutions, today announced continued investments in infrastructure and technology to double its Arbor® Cloud DDoS attack mitigation capacity to 33 Tbps, which is aimed at keeping critical digital services available during DDoS attacks, protecting revenue-generating digital operations, supporting always-on AI-driven businesses, and maintaining customer trust.

This capacity enhancement, coupled with NETSCOUT’s recent acquisition of DDoS network and infrastructure, reinforces the company’s commitment to delivering industry-leading cloud-based DDoS defense at global scale. By fully owning and securing end-to-end control over the platform, NETSCOUT has a clear path to scale innovative, resilient services for customers worldwide. Unlike cloud mitigation services that merely add bandwidth, Arbor Cloud combines global mitigation capacity with global threat intelligence, drawing on NETSCOUT’s unparalleled visibility into real-world internet attack activity. Spanning 16 global scrubbing centers, this significant increase in capacity equips customers with the ability to defend against the growing scale, frequency, and sophistication of DDoS attacks by consistently balancing mitigation capacity across all attack vectors in their environments.

According to Markets and Markets, the DDoS protection market size is expected to continue to grow, driven by increasingly sophisticated attacks and accelerated cloud adoption. Today, multi-vector attacks are the norm. Bad actors are launching more simultaneous attacks as well as quick hit and run attacks, forcing shorter response times from defenders. In addition, mega-botnets like Aisuru and Kimwolf have raised the ceiling on attack sizes with a few attacks approaching or exceeding 30 Tbps. Enterprises and service providers have a compelling need right now to improve the protection levels of their critical digital infrastructure.

“With the increased use of AI, threat actors are targeting organizations whose defenses are vulnerable to the new, more complex DDoS attacks designed to take down critical infrastructure,” stated Carlos Morales, SVP and general manager, Arbor Cloud, NETSCOUT. “As enterprises increasingly rely on AI-powered applications and cloud-native services, while at the same time, attack size and complexity continue to rise, implementing automated and proactive defenses for uninterrupted availability has become a business risk imperative. Arbor Cloud plays a key role in achieving that objective.”

Increasing Arbor Cloud capacity provides significant advantages, including:

  • Greater intelligent mitigation capacity – absorbs and blocks larger volumetric and more sophisticated attacks without losing effectiveness.
  • Multiple threat mitigation – handles multiple concurrent targets (e.g., from carpet bombing attacks) or multiple attack vectors simultaneously.
  • Consistent operational performance – protects critical infrastructure, ensuring capacity does not become a constraint as attack size and frequency increase.
  • Faster stabilization post spikes – acts as a shield wall preventing attacks from reaching customer infrastructure and creating collateral damage that lasts well beyond when the actual attack subsides.
  • Operational confidence – provides added assurance for mission-critical sectors, like financial services, hospitals, retail, and the public sector, which require that protection remains available when legitimate traffic surges and cyberattacks occur simultaneously.

Arbor Cloud plays a critical role as part of NETSCOUT’s multi-layered, adaptive DDoS protection, combining on-premises DDoS defense with cloud-based traffic scrubbing services that are tightly integrated via automated cloud signaling. This hybrid design stops attacks as close to the source as possible while seamlessly absorbing loud volumetric attacks in the cloud. Offering comprehensive global protection, Arbor Cloud is supported by a 24×7 Security Operations Center staffed by NETSCOUT’s DDoS protection experts. The capacity expansion is expected to be fully completed by the end of August 2026.

This investment reinforces NETSCOUT’s long-standing leadership in DDoS protection by combining one of the world’s largest dedicated DDoS mitigation networks with decades of cyber defense expertise, industry-leading threat intelligence, and global Internet visibility. As digital infrastructures continue to evolve rapidly, and AI accelerates both innovation and cyber threats, NETSCOUT remains committed to providing organizations with the scale, intelligence, and operational resilience required to confidently protect what matters most.

Continue Reading

Tech News

Dynatrace Brings Autonomous Operations to Enterprise AI, Moving from Insight to Action

Published

on

Dynatrace (NYSE: DT), the leading AI-powered observability platform, announced major advancements to Dynatrace Intelligence that help automatically resolve incidents, prevent disruptions, and accelerate operations while maintaining the human oversight and governance enterprises require.

Building on the introduction of Dynatrace Intelligence earlier this year, Dynatrace is adding new autonomous agents for incident triage and remediation, and no-code custom agent creation capabilities. The platform is also expanding its ecosystem of integrations, bringing insights directly into the tools and workflows teams already use.

AI systems typically lack the real-time context and controls to make reliable decisions, with most AI initiatives promising automation but often unable to deliver on production goals. Dynatrace addresses this by combining agentic AI with deterministic, real-time understanding of complex environments, creating AI that acts on facts, not guesses.

“Our operations teams are under constant pressure to manage increasingly complex environments while maintaining reliability and speed,” said Angel Marchena, Director of Technical Operations at Western Governors University. “Dynatrace helps us reduce manual effort by providing automation that is grounded in real-time context, which allows our teams to focus on higher-value work while improving operational outcomes.”

How Dynatrace Intelligence Works

Dynatrace Intelligence goes beyond providing answers to acting on them automatically. The release introduces:

  • Autonomous SRE Agent: Triggers autonomously on newly detected problems to determine whether they are part of an existing investigation. If confirmed, the agent enriches the investigation with additional insights and updates the detected problem with a reference to the ongoing investigation.
  • Cloud SRE Agent: Coordinates remediation activities and integrates with agents across AWS, Microsoft Azure, and Google Cloud environments, centralizing findings to provide a single auditable record for autonomous operations.
  • Agent Builder: Enables customers to create and deploy custom AI agents without code, extending autonomous operations to workflows unique to their environments.
  • Enhanced Dynatrace Assist: Newcapabilities bring natural-language investigation and agent-ready workflows to even more users.
  • Expanded Integration Ecosystem: New integrations with hyperscalers like AWS, Azure and Google; enterprise platforms like ServiceNow, Atlassian, and PagerDuty; developer tools and leading AI technologies enable teams to resolve and remediate across the systems they already use.

AI That Acts on Answers, Not Guesses

Unlike approaches that rely primarily on probabilistic outputs, Dynatrace Intelligence grounds every action in deterministic, real-time system understanding. Every action is rooted in environment-specific context and designed to be transparent, auditable, and governed – giving enterprises the confidence to automate increasingly complex operational workflows.

“Most observability platforms stop at data – leaving humans to find answers, determine what to do, and execute,” said Steve Tack, Chief Product Officer at Dynatrace. “With these advancements to Dynatrace Intelligence, we’re helping organizations move from understanding problems to resolving them automatically. By grounding agentic AI in deterministic context, Dynatrace enables enterprises to automate operations with confidence while maintaining governance and control.”

“Enterprises investing in AI-driven observability have an opportunity to turn data into intelligence that translates into trusted, autonomous action,” said Stephen Elliot, Group VP, IDC. “The gap between AI-generated insight and safe, governed execution is one of the biggest concerns; customers need a deterministic, real-time context with automation and auditability to drive trusted and reliable outcomes.”

Cloud SRE Agent, Enhanced Dynatrace Assist, and the expanded integration ecosystem are available to SaaS customers on DPS today. Autonomous SRE Agent and Agent Builder are expected to be available in August.

Continue Reading

Trending

Copyright © 2023 | The Integrator