AZ-EDGIO
22.2.2024 14:01:35 CET | Business Wire | Press release
Edgio (NASDAQ: EGIO), the platform of choice for speed, security, and simplicity at the edge, found that web application attacks continued to increase and evolve in the fourth quarter of 2023, as reported in its new Edgio Quarterly Attack Trends Report in which the company analyzed 5.2 billion attack requests. Edgio found that the most prevalent attack mitigated was path traversal. A successful path traversal attack allows a threat actor to access files on a web server, and has surpassed the prior #1 threat, SQL injection, a common attack vector that often uses malicious SQL statements to attempt to exfiltrate sensitive data from databases behind applications.
Edgio’s report explains how path traversal attacks can lead to deep system intrusions posing a significant threat to an organization’s infrastructure and the confidentiality, integrity, and availability of data delivered over the Internet. These attacks can result in unauthorized access to content, the loss of personally identifiable information (PII), the dissemination of private/copyrighted information, or even remote code execution. Unmitigated attacks can lead to even more serious consequences, such as the deployment of ransomware or other malicious software.
“As one of the leading edge-computing providers, Edgio has unparalleled visibility into the threats facing web applications today,” said Tom Gorup, Vice President of Security for Edgio. “We are assembling our knowledge and expertise into a quarterly read-out to enable enterprises to better protect their web infrastructure and applications. As more businesses become dependent on their digital assets, it’s critical this knowledge is shared to build a safer Internet.”
The report looked at malicious requests and the different types of blocking, categorizing protection into three categories: access control rules, managed rulesets, and custom signatures. Of those that were focused on access controls, over 76% of mitigated requests were based on IP, user-agent, and country matches, highlighting just how much bad traffic can be eliminated with basic blocklisting tactics. With managed rulesets, Edgio saw a wide range of threat types blocked, with path traversal, SQL injection and cross-site scripting (XSS) attacks leading the way when it comes to OWASP attacks.
In addition, Edgio was able to review web application firewall (WAF) request denials by country of origin, while noting that attackers often leverage local resources to launch attacks in order to evade geofencing tactics. This could explain why attacks coordinated from advanced threat actors in more prominent countries did not crack Edgio’s Top 10 for the quarter.
Top countries by malicious request origin, making up nearly 62% of all requests denied, include:
- United States – 26.3%
- France – 17.4%
- Germany – 9.4%
- Russia – 8.8%
Edgio found that WAF customers used access control features to allow or deny specific request methods, using their knowledge of their own applications to inform their security controls and lower risk. The report indicates that attackers frequently leverage request methods like HEAD that return app and infrastructure information that can be used by the attacker for reconnaissance purposes and to craft a malicious payload.
Based on deep parsing of attack payloads, Edgio found that 98% of all malicious payloads fell into JavaScript Object Notation (JSON) and URL encoded form categories (used for storing and transporting data) but cautioned security teams to remain vigilant as attackers evolve in their selection of payload content types.
Best practices for digital asset protection: proactively stop threats against websites and applications
Based on its findings, Edgio recommends the following methods to best protect digital assets, including websites and applications:
- Ensure your WAF provides a layered defense to protect organizations against the known bad, application-specific, and emerging threats. A complete solution will show a distribution of enforcement across access control rules, managed rulesets, and custom signatures.
- Blocklists are still an effective and low-cost part of a layered security approach to safeguard Internet-facing assets. Organizations should also take advantage of threat intelligence feeds to further harden their security posture against known bad actors.
- While managed rules are often maintained and updated by your WAF provider, it is not advisable to use a ‘set it and forget’ approach. As an application evolves and new functionalities are developed, policy reviews and analysis of managed ruleset enforcement is recommended. It is best to ensure rules are closely aligned with business application needs.
- Organizations should take the time to understand where they are doing business and where they aren’t allowed to do business. Block the countries or sub-regions that bring no value to a brand to reduce their attack surface. Blocking embargoed countries is a great starting point, but don’t rely on this approach as a catch all for bad actors.
- Know the application and use this knowledge to inform security solutions, like a WAF, to limit the application request methods or content types based on application needs.
To obtain a full copy of the report, click here.
About Edgio
Edgio (NASDAQCM: EGIO) helps companies deliver online experiences and content faster, safer and with more control. Our developer-friendly, globally scaled edge network, combined with our fully integrated application and media solutions, provides a single platform for delivering high-performing, secure web properties and streaming content. Companies can deliver content quicker and more securely through this fully integrated platform and end-to-end edge services, boosting overall revenue and business value. To learn more, visit edg.io and follow us on Twitter, LinkedIn and Facebook.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20240222674952/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Honoring the World’s Most Exceptional Tourism Destinations: Nominations Now Open for the Second TOURISE Awards2.9.2026 15:55:00 CEST | Press release
The TOURISE Awards showcase the globe's most influential destinations, highlighting the richness of culture, the power of human connection, and groundbreaking advancements in travel. Six categories are open for nominations, including a new award for Best Wellness Destination, plus a flagship Best Overall Destination award selected by the jury. Winners will be honored at the TOURISE Awards ceremony, held in conjunction with the TOURISE Summit in Riyadh, March 23-25, 2027. The second cycle of the TOURISE Awards officially launched today as a continuing global benchmark celebrating premier tourism destinations. The TOURISE Awards set a new global benchmark in 2025, celebrating destinations that deliver distinctive, purpose-driven travel experiences. In 2027, TOURISE will celebrate the destinations shaping tomorrow’s tourism; that deliver value across the entire journey, align with traveler purpose, and set new global standards for how the world travels, connects, and grows. Nominations ar
ABB Extends Engagement with Wipro to Deliver and Enhance Global Digital Workplace Services2.9.2026 15:30:00 CEST | Press release
Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO), a leading AI-powered technology services and consulting company, has renewed its long-standing Digital Workplace Services contract with ABB, a global technology leader in electrification and automation. Building on an established relationship spanning multiple years, Wipro will continue delivering end-to-end AI-enabled Digital Workplace Services for ABB's global operations while further enhancing employee experience through advanced automation, AI-powered service capabilities, and workplace modernization initiatives. Powered by Wipro Intelligence™, the unified suite of AI platforms, solutions and transformative offerings, this engagement will modernize ABB’s digital workplace with AI-led, experience-centric capabilities delivered through Wipro’s AI Live Workspace™ and Digital Workplace Services offerings and operationalized through WINGS, Wipro’s AI-powered delivery platform for operations. Through SmartOps, Wipro’s AIOps capability,
Egon Zehnder Names Ayşe Güçlü Onur Global Human Resources Practice Leader2.9.2026 15:00:00 CEST | Press release
Egon Zehnder has appointed Ayşe Güçlü Onur as Global Leader of its Human Resources Practice. This appointment comes as companies and boards increasingly look to CHROs to help shape business strategy, lead transformation, build leadership pipelines, and navigate major shifts in culture and the workforce. "CHROs used to be evaluated by how well they supported the business. Today, the best drive it," said Onur. "Our role is to help CHROs move from a seat at the table to a hand in business growth. We help them connect leadership decisions, talent, and culture directly to elevated performance. That's the shift Egon Zehnder is built to guide with our leadership advisory services." Egon Zehnder’s Human Resources Practice partners with companies to discover, develop, and transform future-ready CHROs, helping them shape the future of the function. This includes executive search, leadership assessment and development, board effectiveness, culture, succession planning, organizational transformati
Safe Software to Increase Global Headcount by Over 15% as Demand for AI-Ready Data Grows2.9.2026 15:00:00 CEST | Press release
The FME creator is recruiting for more than 60 roles across the UK, US and Canada before the end of December, less than a year after crossing $100M in revenue Safe Software, the creator of FME, the only All-Data, Any-AI enterprise integration platform with true support for spatial data, today announced it is recruiting for more than 60 roles throughout the remainder of 2026. The hiring will take the company past 400 employees, increasing headcount by over 15%, with new positions across the United Kingdom, the United States and Canada. The expansion follows a year in which Safe crossed $100 million in annual revenue, growing close to 20 percent year over year and moving ahead of schedule on its target of $250 million by 2028. The company also grew its employee base by over 20% in the same period. "The incredible growth that we’ve seen over the last 30+ years at Safe has always been a testament to the great people behind what we do," said Don Murray, Co-Founder and CEO of Safe Software.
Owkin to License K Pro AI Scientist and Multimodal Oncology and Immunology Datato Boehringer Ingelheim2.9.2026 14:00:00 CEST | Press release
Owkin, the agentic AI company striving to transform drug discovery and development for biopharma, today announced a license agreement with Boehringer Ingelheim for K Pro, Owkin’s AI Scientist, together with multimodal patient data, aiming to speed up the discovery process across multiple indications in oncology and immunology. This agreement builds upon an initial pilot undertaken by Owkin with Boehringer in 2025. In that pilot Owkin delivered deep spatial insights into the tumor microenvironment of a gene target through its MOSAIC dataset. Under the new agreement, Owkin will license multimodal oncology data to Boehringer and will generate new multimodal data in immunology. Owkin licenses, sources and generates multimodal patient data in collaboration with its global patient data network. Boehringer Ingelheim’s teams will access and analyze this data through K Pro, which provides a single environment to interrogate data and run reproducible analyses. K Pro’s reasoning capabilities supp
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
