Business Wire

Imperva Application Security Integrates API Detection and Response, Setting A New Standard in API Security

24.6.2025 09:00:00 CEST | Business Wire | Press release

Share

First unified, single-pane-of-glass platform to deliver real-time detection and mitigation of API threats, including Broken Object Level Authorization (BOLA) and other advanced business logic threats Offers flexible deployment across cloud and on-premise environments, with a privacy-forward design to secure APIs at scale.

Thales today announced new detection and response capabilities in the Imperva Application Security platform to protect against business logic attacks, such as Broken Object Level Authorization (BOLA) – the leading threat in the OWASP API Security Top 10. By integrating real-time detection with automated mitigation of risky APIs, BOLA attacks, unauthenticated APIs, and deprecated APIs, Imperva Application Security platform delivers comprehensive protection against unauthorized data exposure and other complex business logic vulnerabilities across cloud and on-premises environments.

APIs have become the backbone of modern applications, enabling businesses to seamlessly connect services, optimize operations, and deliver personalized experiences at scale. According to Imperva Threat Research, APIs accounted for 71% of all web traffic. More recently, the team observed a sharp rise in API-directed attacks, with 44% of advanced bot traffic targeting APIs, compared to just 10% targeting web applications. This shift underscores how attackers are increasingly exploiting API endpoints that manage sensitive and high-value data.

Why BOLA is a Critical Business Risk

BOLA occurs when APIs fail to properly verify whether users are authorized to access specific data objects. This allows attackers to manipulate requests and gain unauthorized access to sensitive information. As the leading OWASP Top 10 API threat, BOLA exposes businesses to significant risks, including data breaches, compliance failures, and loss of customer trust.

“API security is no longer optional it’s fundamental to maintaining business continuity and trust,” said Tim Chang, Global Vice President and General Manager of Application Securityat Thales. “Imperva Application Security bridges the gap by delivering a fully unified platform that identifies business logic threats and actively blocks malicious sessions, setting a new benchmark for API protection.”

Empowering Enterprises with a Unified, Flexible, and Privacy-First Solution

Imperva Application Security integrates advanced threat detection engines with automated inline responses and flexible deployment options, enabling security teams to detect and respond to API attacks like BOLA without slowing development or disrupting the user experience. For customers who want to protect their API infrastructure, Imperva Application Security delivers the following benefits:

  • Unified Platform Architecture: Manage API discovery, risk assessment, detection, and mitigation in a single console, eliminating tool sprawl and operational friction across cloud and on-premises environments.
  • Real-Time BOLA Detection: Hybrid behavioral and rule-based engines analyze API request patterns, scoring anomalies, and flagging endpoints for immediate action.
  • Automated Response and Remediation: Integration with Imperva Cloud WAF and WAF Gateway enables a variety of response actions, including inline mitigation actions such as automatically blocking malicious API traffic in real-time. Integration with security automation tools ensures rapid incident orchestration.

Advancing the Imperva Security Anywhere Vision

The integration of API detection and response into Imperva Application Security is foundational to the Imperva Security Anywhere vision, which provides scalable, end-to-end protection for applications and APIs across any environment. This unified solution provides enterprises with a comprehensive view of automated threats targeting APIs and the necessary tools to protect those APIs.

Detection and response to deprecated APIs, unauthenticated APIs, and BOLA attacks are now available as part of Imperva Application Security.

About Thales

Thales (Euronext Paris: HO) is a global leader in advanced technologies for the Defence, Aerospace, and Cyber & Digital sectors. Its portfolio of innovative products and services addresses several major challenges: sovereignty, security, sustainability and inclusion.

The Group invests more than €4 billion per year in Research & Development in key areas, particularly for critical environments, such as Artificial Intelligence, cybersecurity, quantum and cloud technologies.

Thales has more than 83,000 employees in 68 countries. In 2024, the Group generated sales of €20.6 billion.

PLEASE VISIT

Thales Group

Cloud Protection & Licensing Solutions | Thales Group

Cybersecurity Solutions | Thales Group

View source version on businesswire.com: https://www.businesswire.com/news/home/20250624052385/en/

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Galderma Shareholders Approve All Annual General Meeting Proposals22.4.2026 17:45:00 CEST | Press release

Galderma Group AG (SIX:GALD), the pure-play dermatology category leader, announced that shareholders approved all proposals put forward by the Board of Directors at its Annual General Meeting (AGM), held earlier today via live webcast. This includes the payment of a gross dividend of 0.35 CHF per dividend-bearing share1, to be distributed out of reserves from capital contributions. Shareholders approved the election of Harry Kirsch as independent member of the Board of Directors, as well as the election of Samuel du Retail and Delphine Viguier-Hovasse, representatives of L’Oréal, as non-independent members of the Board. In addition, Thomas Ebeling (Chair), Daniel Browne, Maria Teresa Hilado, Karen Lee Ling, Roberto Marques, Sherilyn McCoy and Dr. Flemming Ørnskov were re-elected to the Board. The AGM also approved the company’s 2025 Annual Financial Statements, Non-Financial Report and Compensation Report. Detailed voting results and the official minutes will be published on Galderma's

Altrove and Bloomineral Named Winners of the 2026 Grand Prix ACF AutoTech22.4.2026 15:21:00 CEST | Press release

IoT.Bzh receives the inaugural Industrialization Prize at the 9th edition of the international automotive startup competition Altrove and Bloomineral have been crowned winners of the 2026 Grand Prix ACF AutoTech, the international startup competition recognizing the best of automotive innovation. The ninth edition was held on Wednesday, April 15 at the Automobile Club de France in Paris, where IoT.Bzh also received the first-ever Industrialization Prize. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260422236542/en/ Picture of the end of the event with the winners : Bloomineral, Altrove and Iot.Bzh + all the Jury Members from French Automotive OEM and Tier1 Hosted by competition founder Richard de Cabrol and Simon Degiovanni, the evening gathered more than 250 leaders from the automotive, technology, digital, business and media sectors, with attendees joining both on-site and online. Six finalist startups, selected from mor

I/ONX Shatters the Host Tax: New Symphony SixtyFour Architecture Delivers 50% TCO Savings Across AI Inference and Fine-Tuning Lifecycle22.4.2026 15:00:00 CEST | Press release

Eliminating infrastructure overhead of legacy designs, I/ONX debuts a scaled AI inference and fine-tuning stack that cuts power by up to 30kW per rack and reduces cost of rack-scale deployments by up to 70% I/ONX High Performance Compute (HPC), a leading provider of heterogeneous AI systems, today announced the global launch of the Symphony SixtyFour, a high-density platform designed to collapse the physical and economic footprint of AI inference and fine-tuning infrastructure. By supporting up to 64 accelerators on a single node, I/ONX eliminates the redundant Host Tax—the massive overhead in power, hardware, and licensing that negatively impacts ROI in enterprise AI. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260422485327/en/ I/ONX Introduces Symphony SixtyFour: The Host Tax is Over. Save 30-50% on your AI Infrastructure Costs. While inference now accounts for 90% of enterprise AI workloads, enterprises are entirely li

Thales Introduces Imperva for Google Cloud, Bringing Its Enterprise-Grade Application Security Capabilities Directly into Google Cloud22.4.2026 15:00:00 CEST | Press release

New offering eliminates the need to choose between cloud-native performance and advanced security as enterprises scale modern applications Thales today announced the Controlled Availability of Imperva for Google Cloud, bringing the industry's most trusted application security platform directly into Google Cloud. Designed to operate within Google Cloud, the new offering enables organizations to protect web applications and APIs by leveraging Google Cloud’s Service Extension traffic, preserving existing pipelines, integrations, and monitoring workflows. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260422746638/en/ ©Thales As enterprises accelerate cloud adoption, development teams increasingly standardize on native cloud services to improve speed and reduce operational complexity. Many security solutions, however, require external routing that introduces latency and friction. At the same time, native cloud security tools oft

ClickHouse Expands Strategic Collaboration with Google Cloud, Bringing Deeper Integration, Cloud Flexibility, and Next-Generation Performance22.4.2026 15:00:00 CEST | Press release

ClickHouse, a leader in real-time analytics, data warehousing, observability, and AI/ML, today at Google Next 26 announced a significant expansion of its strategic collaboration with Google Cloud. The announcement encompasses four major milestones: native integration with Google Cloud Lakehouse, the availability of ClickHouse's Bring Your Own Cloud (BYOC), the migration of ClickHouse Cloud on Google Cloud to Google's custom Arm-based Axion processors, and a new integration between the ClickHouse MCP server and Google Antigravity. These advancements deliver deeper interoperability across the data ecosystem, extend deployment flexibility for security-conscious enterprises, and unlock meaningful gains in query performance and cost efficiency for joint customers worldwide. This expansion builds on ClickHouse's growing presence within the Google Cloud ecosystem, where thousands of data-intensive organizations rely on ClickHouse Cloud to power real-time observability, business intelligence,

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye