AZ-EDGIO
22.2.2024 14:01:35 CET | Business Wire | Press release
Edgio (NASDAQ: EGIO), the platform of choice for speed, security, and simplicity at the edge, found that web application attacks continued to increase and evolve in the fourth quarter of 2023, as reported in its new Edgio Quarterly Attack Trends Report in which the company analyzed 5.2 billion attack requests. Edgio found that the most prevalent attack mitigated was path traversal. A successful path traversal attack allows a threat actor to access files on a web server, and has surpassed the prior #1 threat, SQL injection, a common attack vector that often uses malicious SQL statements to attempt to exfiltrate sensitive data from databases behind applications.
Edgio’s report explains how path traversal attacks can lead to deep system intrusions posing a significant threat to an organization’s infrastructure and the confidentiality, integrity, and availability of data delivered over the Internet. These attacks can result in unauthorized access to content, the loss of personally identifiable information (PII), the dissemination of private/copyrighted information, or even remote code execution. Unmitigated attacks can lead to even more serious consequences, such as the deployment of ransomware or other malicious software.
“As one of the leading edge-computing providers, Edgio has unparalleled visibility into the threats facing web applications today,” said Tom Gorup, Vice President of Security for Edgio. “We are assembling our knowledge and expertise into a quarterly read-out to enable enterprises to better protect their web infrastructure and applications. As more businesses become dependent on their digital assets, it’s critical this knowledge is shared to build a safer Internet.”
The report looked at malicious requests and the different types of blocking, categorizing protection into three categories: access control rules, managed rulesets, and custom signatures. Of those that were focused on access controls, over 76% of mitigated requests were based on IP, user-agent, and country matches, highlighting just how much bad traffic can be eliminated with basic blocklisting tactics. With managed rulesets, Edgio saw a wide range of threat types blocked, with path traversal, SQL injection and cross-site scripting (XSS) attacks leading the way when it comes to OWASP attacks.
In addition, Edgio was able to review web application firewall (WAF) request denials by country of origin, while noting that attackers often leverage local resources to launch attacks in order to evade geofencing tactics. This could explain why attacks coordinated from advanced threat actors in more prominent countries did not crack Edgio’s Top 10 for the quarter.
Top countries by malicious request origin, making up nearly 62% of all requests denied, include:
- United States – 26.3%
- France – 17.4%
- Germany – 9.4%
- Russia – 8.8%
Edgio found that WAF customers used access control features to allow or deny specific request methods, using their knowledge of their own applications to inform their security controls and lower risk. The report indicates that attackers frequently leverage request methods like HEAD that return app and infrastructure information that can be used by the attacker for reconnaissance purposes and to craft a malicious payload.
Based on deep parsing of attack payloads, Edgio found that 98% of all malicious payloads fell into JavaScript Object Notation (JSON) and URL encoded form categories (used for storing and transporting data) but cautioned security teams to remain vigilant as attackers evolve in their selection of payload content types.
Best practices for digital asset protection: proactively stop threats against websites and applications
Based on its findings, Edgio recommends the following methods to best protect digital assets, including websites and applications:
- Ensure your WAF provides a layered defense to protect organizations against the known bad, application-specific, and emerging threats. A complete solution will show a distribution of enforcement across access control rules, managed rulesets, and custom signatures.
- Blocklists are still an effective and low-cost part of a layered security approach to safeguard Internet-facing assets. Organizations should also take advantage of threat intelligence feeds to further harden their security posture against known bad actors.
- While managed rules are often maintained and updated by your WAF provider, it is not advisable to use a ‘set it and forget’ approach. As an application evolves and new functionalities are developed, policy reviews and analysis of managed ruleset enforcement is recommended. It is best to ensure rules are closely aligned with business application needs.
- Organizations should take the time to understand where they are doing business and where they aren’t allowed to do business. Block the countries or sub-regions that bring no value to a brand to reduce their attack surface. Blocking embargoed countries is a great starting point, but don’t rely on this approach as a catch all for bad actors.
- Know the application and use this knowledge to inform security solutions, like a WAF, to limit the application request methods or content types based on application needs.
To obtain a full copy of the report, click here.
About Edgio
Edgio (NASDAQCM: EGIO) helps companies deliver online experiences and content faster, safer and with more control. Our developer-friendly, globally scaled edge network, combined with our fully integrated application and media solutions, provides a single platform for delivering high-performing, secure web properties and streaming content. Companies can deliver content quicker and more securely through this fully integrated platform and end-to-end edge services, boosting overall revenue and business value. To learn more, visit edg.io and follow us on Twitter, LinkedIn and Facebook.
To view this piece of content from cts.businesswire.com, please give your consent at the top of this page.
View source version on businesswire.com: https://www.businesswire.com/news/home/20240222674952/en/
About Business Wire
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
ATB Therapeutics Appoints Mark Throsby as CEO to Lead Next Phase of Growth19.5.2026 08:00:00 CEST | Press release
ATB Therapeutics (“ATB” or the “Company”), a biopharmaceutical company advancing next-generation antibody-based therapies for oncology and immunology, today announced the appointment of Mark Throsby, PhD, as Chief Executive Officer. The leadership transition marks an important milestone as the Company continues its evolution from a startup into a development-stage biopharmaceutical company. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260513198633/en/ ATB Therapeutics Appoints Mark Throsby as CEO to Lead Next Phase of Growth Mark Throsby has served as Executive Chairman and Chief Scientific Officer since 2024, during which time he supported the Company’s growth, including the successful closing of its Series A financing, the expansion of the scientific team, and the advancement of its therapeutic programs. In his new role, he will lead ATB’s strategy and senior leadership team as the Company prepares to enter clinical deve
TREASoURcE Shows How Circular Economy Solutions Can Move Beyond Pilots Across Sectors and Regions19.5.2026 07:00:00 CEST | Press release
Across Europe, many circular economy solutions struggle to move beyond isolated pilots and into real-world deployment at scale. New approaches are needed that combine technical feasibility, market relevance and citizen engagement, while remaining adaptable to local contexts. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260518914041/en/ TREASoURcE addressed circular economy challenges across energy, plastics and biobased side streams, combining technical solutions with stakeholder and citizen engagement. The EU-funded TREASoURcE project provides evidence that systemic, citizen-engaged circular economy solutions can be developed, tested and prepared for replication across regions. Using a common regional approach, the project combined real-life demonstrations, cross-value chain collaboration and early consideration of transferability to translate circular economy concepts into practical solutions in the fields of energy, mat
Azafaros Strengthens Leadership Team With Appointment of Amy Sullivan as Chief Financial Officer19.5.2026 07:00:00 CEST | Press release
Experienced biotech finance leader with over 30 years’ experience in capital markets and strategyProven track record in fundraising, M&A and company transformationCompany is currently running two pivotal Phase 3 studies with nizubaglustat in GM1/ GM2 gangliosidoses and Niemann-Pick type C disease Azafaros, a private company building a portfolio to become a leader in Lysosomal Storage Disorders and focused on addressing neurological symptoms, today announced that Amy Sullivan has joined the company as Chief Financial Officer. Ms. Sullivan brings more than 30 years’ experience in the life sciences sector, with expertise in capital raising, corporate strategy and communications. She joins Azafaros from IO Biotech, where she served as Chief Financial Officer. “Amy is a highly accomplished financial leader with a strong track record of supporting growth-stage biotech companies,” said Stefano Portolano, Chief Executive Officer at Azafaros. “Her expertise in financing, strategic positioning a
Shufti Recognised as Dual Leader in Liminal's 2026 Age Verification and Age Estimation Indexes, with Exceptional Ratings Across Both Benchmarks19.5.2026 07:00:00 CEST | Press release
Liminal’s independent buyer-led research positions Shufti among the highest-scoring vendors on Product Execution, Strategy, and Market Presence, citing its risk-based age assurance, sub-second inference, and privacy-preserving on-device capabilities. Shufti has been named a Leader in both the Age Verification and Age Estimation categories of Liminal’s 2026 Index Report, receiving an Exceptional rating for Market Presence across both. Liminal, an actionable intelligence firm, evaluates identity verification vendors across Product Execution, Strategy, and Market Presence, assessing scalability, accuracy, fraud resistance, innovation, and user experience. Out of 189 vendors assessed in the Age Verification Index, only 17 achieved Leader status. Shufti was among them and exceeded the leadership threshold with a 64% Product Execution score and a 92% Strategy score. In Age Estimation, Shufti again ranked among 17 Leaders from 80 evaluated vendors, exceeding leadership thresholds across core
Tennis World Champion Carlos Alcaraz Becomes Global Brand Ambassador for Ant International19.5.2026 05:10:00 CEST | Press release
Global tennis icon Carlos Alcaraz has become the new Global Brand Ambassador for Ant International, a leading global digital payment, digitisation and financial technology provider, and its key brands. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260518952984/en/ (L-R) Ant International CEO Peng Yang and Carlos Alcaraz celebrate Global Brand Ambassador partnership This collaboration underscores Ant International’s commitment to enabling inclusive growth across global markets through a relentless pursuit of world-leading AI-powered payment and fintech solutions for businesses and individuals – a vision that mirrors the fierce energy and inspiration Carlos Alcaraz brings to every match. “Carlos is not only a sporting champion, but the very personification of the core values of tennis for fans worldwide: boundless ambition, unwavering dedication, scalpel precision in delivery, and sportsmanship both on and off the court,” sai
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom
