Imperva Application Security Integrates API Detection and Response, Setting A New Standard in API Security
First unified, single-pane-of-glass platform to deliver real-time detection and mitigation of API threats, including Broken Object Level Authorization (BOLA) and other advanced business logic threats Offers flexible deployment across cloud and on-premise environments, with a privacy-forward design to secure APIs at scale.
Thales today announced new detection and response capabilities in the Imperva Application Security platform to protect against business logic attacks, such as Broken Object Level Authorization (BOLA) – the leading threat in the OWASP API Security Top 10. By integrating real-time detection with automated mitigation of risky APIs, BOLA attacks, unauthenticated APIs, and deprecated APIs, Imperva Application Security platform delivers comprehensive protection against unauthorized data exposure and other complex business logic vulnerabilities across cloud and on-premises environments.
APIs have become the backbone of modern applications, enabling businesses to seamlessly connect services, optimize operations, and deliver personalized experiences at scale. According to Imperva Threat Research, APIs accounted for 71% of all web traffic. More recently, the team observed a sharp rise in API-directed attacks, with 44% of advanced bot traffic targeting APIs, compared to just 10% targeting web applications. This shift underscores how attackers are increasingly exploiting API endpoints that manage sensitive and high-value data.
Why BOLA is a Critical Business Risk
BOLA occurs when APIs fail to properly verify whether users are authorized to access specific data objects. This allows attackers to manipulate requests and gain unauthorized access to sensitive information. As the leading OWASP Top 10 API threat, BOLA exposes businesses to significant risks, including data breaches, compliance failures, and loss of customer trust.
“API security is no longer optional – it’s fundamental to maintaining business continuity and trust,” said Tim Chang, Global Vice President and General Manager of Application Securityat Thales. “Imperva Application Security bridges the gap by delivering a fully unified platform that identifies business logic threats and actively blocks malicious sessions, setting a new benchmark for API protection.”
Empowering Enterprises with a Unified, Flexible, and Privacy-First Solution
Imperva Application Security integrates advanced threat detection engines with automated inline responses and flexible deployment options, enabling security teams to detect and respond to API attacks like BOLA without slowing development or disrupting the user experience. For customers who want to protect their API infrastructure, Imperva Application Security delivers the following benefits:
- Unified Platform Architecture: Manage API discovery, risk assessment, detection, and mitigation in a single console, eliminating tool sprawl and operational friction across cloud and on-premises environments.
- Real-Time BOLA Detection: Hybrid behavioral and rule-based engines analyze API request patterns, scoring anomalies, and flagging endpoints for immediate action.
- Automated Response and Remediation: Integration with Imperva Cloud WAF and WAF Gateway enables a variety of response actions, including inline mitigation actions such as automatically blocking malicious API traffic in real-time. Integration with security automation tools ensures rapid incident orchestration.
Advancing the Imperva Security Anywhere Vision
The integration of API detection and response into Imperva Application Security is foundational to the Imperva Security Anywhere vision, which provides scalable, end-to-end protection for applications and APIs across any environment. This unified solution provides enterprises with a comprehensive view of automated threats targeting APIs and the necessary tools to protect those APIs.
Detection and response to deprecated APIs, unauthenticated APIs, and BOLA attacks are now available as part of Imperva Application Security.
About Thales
Thales (Euronext Paris: HO) is a global leader in advanced technologies for the Defence, Aerospace, and Cyber & Digital sectors. Its portfolio of innovative products and services addresses several major challenges: sovereignty, security, sustainability and inclusion.
The Group invests more than €4 billion per year in Research & Development in key areas, particularly for critical environments, such as Artificial Intelligence, cybersecurity, quantum and cloud technologies.
Thales has more than 83,000 employees in 68 countries. In 2024, the Group generated sales of €20.6 billion.
PLEASE VISIT
Cloud Protection & Licensing Solutions | Thales Group
Cybersecurity Solutions | Thales Group
View source version on businesswire.com: https://www.businesswire.com/news/home/20250624052385/en/
Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Less Waste, More Impact: ScottsMiracle-Gro and ProAmpac Advance Insecticide Packaging24.6.2025 18:11:00 CEST | Press release
ProAmpac, a global leader in flexible packaging and material science, has partnered with ScottsMiracle-Gro to introduce a groundbreaking spouted pouch for Ortho Home Defense Max. This new packaging combines the durability of rigid containers with the efficiency of flexible packaging, offering consumers a convenient and more sustainable alternative. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250624640067/en/ ProAmpac partners with ScottsMiracle-Gro to introduce a groundbreaking spouted pouch for Ortho Home Defense Max. “The new Ortho Home Defense Max packaging represents a major step forward in sustainability and consumer convenience,” said Keith Miller, senior packaging engineer at ScottsMiracle-Gro. “By introducing a spouted pouch, we’ve significantly reduced our plastic packaging footprint while ensuring that our customers continue to receive the high-performance pest control solutions they trust.” This design leverage
Agoro Carbon Secures Flagship 12-Year Agreement to Deliver 2.6 Million Soil Carbon Removal Credits to Microsoft24.6.2025 16:30:00 CEST | Press release
One of the most impactful purchases of agriculture-based carbon removals to date, setting a precedent for quality and durability in the soil carbon market. Unlocks significant investment to scale sustainable agriculture, reflecting corporate demand for durable, science-backed soil carbon removals. Affirms Agoro Carbon as a leader in top-tier, science-backed soil carbon removals. Agoro Carbon signed a landmark 12-year offtake agreement to deliver 2.6 million carbon removal credits to Microsoft. This agreement represents one of the largest soil-based carbon removals commitments to date, marking a significant milestone in the advancement of agriculture-driven climate solutions. It unlocks significant investment to scale sustainable agriculture, reflecting corporate demand for durable, science-backed soil carbon removals. The credits will be generated from Agoro Carbon’s U.S. crop and rangeland projects, developed under Verra’s VM0042 Improved Agricultural Land Management methodology. Thes
RS2 Collaborates with Visa to Deliver End-to-End Global Payment Processing Solution24.6.2025 15:55:00 CEST | Press release
RS2, a global provider of payment software and processing solutions, has today announced it will collaborate with Visa, a world leader in digital payments, to offer an end-to-end acceptance infrastructure proposition. The new collaboration will combine Visa’s front-end authorization services, while RS2’s robust infrastructure powers back-end processing. This powerful combination will enable banks, fintechs, and merchants around the world to access a streamlined, scalable, and secure payment platform. Early implementations are underway in Europe and Latin America, with growing interest from financial institutions seeking modern, agile solutions to meet the evolving demands of the global payments landscape. “This partnership marks a pivotal milestone in RS2’s international growth journey,” said Radi Abd El Haj, CEO of RS2. “By merging Visa’s world-class authorization capabilities with our flexible back-end technology, we’re providing customers with a seamless solution that’s designed for
Hytera Wins "Best Use of Critical Communications in Transport" at 2025 ICCAs with MCX Solution24.6.2025 15:00:00 CEST | Press release
Hytera, a leading global provider of professional communications technologies and solutions, was awarded the “Best Use of Critical Communications in Transport” at 2025 International Critical Communications Awards (ICCAs) in Brussels on June 17, for its “HK MTR Light Rail 2.0 with 5G MCX Radio System” project. This marks the fourth consecutive year that Hytera’s MCX solutions have received ICCAs since 2022. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250623863620/en/ The Hytera team accepted the award at the ICCAs 2025 ceremony in Brussels. Hytera deployed the 5G MCX system for the Hong Kong MTR, integrating MCPTT, MCVideo, and MCData over public 5G network. The solution is expected to enhance safety, intelligence, and operational efficiency, supporting smarter and more sustainable transit. In the project, Hytera’s 5G MCX solution demonstrates how mission-critical communication technology can transform urban transit, setti
Amazfit Introduces Balance 2 Smartwatch and Helio Strap for Smarter Training, Better Recovery and Peak Performance24.6.2025 15:00:00 CEST | Press release
Amazfit Smart Wearables Require No Additional Subscription Amazfit, a leading global smart wearable brand owned by Zepp Health (NYSE: ZEPP), a health technology company, today announced the launch and availability of two new performance-focused devices—the Balance 2 smartwatch and the Helio Strap, Amazfit’s first screen-free fitness, recovery, and sleep tracker. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250624910772/en/ Amazfit Introduces Balance 2 Smartwatch and Helio Strap Better Together: A Smarter Training and Recovery System While both devices can be purchased and used individually, it's their combined potential as an all-in-one training and recovery system that truly sets them apart. Balance 2 is a premium multisport training partner that gives users access to advanced performance tracking. When paired with the Helio Strap, the system delivers even greater accuracy in heart rate monitoring, fatigue assessment, and
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom