Business Wire

Imperva Application Security Integrates API Detection and Response, Setting A New Standard in API Security

Share

First unified, single-pane-of-glass platform to deliver real-time detection and mitigation of API threats, including Broken Object Level Authorization (BOLA) and other advanced business logic threats Offers flexible deployment across cloud and on-premise environments, with a privacy-forward design to secure APIs at scale.

Thales today announced new detection and response capabilities in the Imperva Application Security platform to protect against business logic attacks, such as Broken Object Level Authorization (BOLA) – the leading threat in the OWASP API Security Top 10. By integrating real-time detection with automated mitigation of risky APIs, BOLA attacks, unauthenticated APIs, and deprecated APIs, Imperva Application Security platform delivers comprehensive protection against unauthorized data exposure and other complex business logic vulnerabilities across cloud and on-premises environments.

APIs have become the backbone of modern applications, enabling businesses to seamlessly connect services, optimize operations, and deliver personalized experiences at scale. According to Imperva Threat Research, APIs accounted for 71% of all web traffic. More recently, the team observed a sharp rise in API-directed attacks, with 44% of advanced bot traffic targeting APIs, compared to just 10% targeting web applications. This shift underscores how attackers are increasingly exploiting API endpoints that manage sensitive and high-value data.

Why BOLA is a Critical Business Risk

BOLA occurs when APIs fail to properly verify whether users are authorized to access specific data objects. This allows attackers to manipulate requests and gain unauthorized access to sensitive information. As the leading OWASP Top 10 API threat, BOLA exposes businesses to significant risks, including data breaches, compliance failures, and loss of customer trust.

“API security is no longer optional it’s fundamental to maintaining business continuity and trust,” said Tim Chang, Global Vice President and General Manager of Application Securityat Thales. “Imperva Application Security bridges the gap by delivering a fully unified platform that identifies business logic threats and actively blocks malicious sessions, setting a new benchmark for API protection.”

Empowering Enterprises with a Unified, Flexible, and Privacy-First Solution

Imperva Application Security integrates advanced threat detection engines with automated inline responses and flexible deployment options, enabling security teams to detect and respond to API attacks like BOLA without slowing development or disrupting the user experience. For customers who want to protect their API infrastructure, Imperva Application Security delivers the following benefits:

  • Unified Platform Architecture: Manage API discovery, risk assessment, detection, and mitigation in a single console, eliminating tool sprawl and operational friction across cloud and on-premises environments.
  • Real-Time BOLA Detection: Hybrid behavioral and rule-based engines analyze API request patterns, scoring anomalies, and flagging endpoints for immediate action.
  • Automated Response and Remediation: Integration with Imperva Cloud WAF and WAF Gateway enables a variety of response actions, including inline mitigation actions such as automatically blocking malicious API traffic in real-time. Integration with security automation tools ensures rapid incident orchestration.

Advancing the Imperva Security Anywhere Vision

The integration of API detection and response into Imperva Application Security is foundational to the Imperva Security Anywhere vision, which provides scalable, end-to-end protection for applications and APIs across any environment. This unified solution provides enterprises with a comprehensive view of automated threats targeting APIs and the necessary tools to protect those APIs.

Detection and response to deprecated APIs, unauthenticated APIs, and BOLA attacks are now available as part of Imperva Application Security.

About Thales

Thales (Euronext Paris: HO) is a global leader in advanced technologies for the Defence, Aerospace, and Cyber & Digital sectors. Its portfolio of innovative products and services addresses several major challenges: sovereignty, security, sustainability and inclusion.

The Group invests more than €4 billion per year in Research & Development in key areas, particularly for critical environments, such as Artificial Intelligence, cybersecurity, quantum and cloud technologies.

Thales has more than 83,000 employees in 68 countries. In 2024, the Group generated sales of €20.6 billion.

PLEASE VISIT

Thales Group

Cloud Protection & Licensing Solutions | Thales Group

Cybersecurity Solutions | Thales Group

View source version on businesswire.com: https://www.businesswire.com/news/home/20250624052385/en/

Subscribe to releases from Business Wire

Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.

Latest releases from Business Wire

Cirium Introduces First AI-Powered Solution for On-Time Performance Analysis24.6.2025 11:00:00 CEST | Press release

Cirium, the global leader in aviation analytics, has launched OTP Improvement AI, a groundbreaking generative AI-powered solution designed to transform how airlines and airports analyze and enhance their On-Time Performance (OTP). This innovative tool addresses long-standing challenges in operational efficiency and disruption management, offering faster, smarter, and more proactive decision-making capabilities. OTP Improvement AI sets itself apart by addressing the specific challenges airlines and airports face, such as the time-intensive nature of traditional OTP analysis and the struggle to manage cascading delays caused by factors like weather or technical issues. By using advanced generative AI, the platform transforms complex data into precise insights, enabling operators to trends, streamline resources, and make swift decisions that minimize delays and improve the overall passenger experience. “Operational disruptions, whether caused by weather, strikes, or unforeseen technical i

Zambon Announces Approval and Launch in China of the Intravenous Formulation of Fluimucil® (N-acetylcysteine)24.6.2025 10:00:00 CEST | Press release

The approval in China is supported by a robust local clinical development program confirming the drug’s safety, tolerability, and efficacy profileThe launch strengthens Zambon's presence in China and marks a significant step in the company’s commitment to global therapeutic innovation in respiratory diseases, reflecting its dedicated focus on both clinical research and patient care Zambon, a multinational chemical-pharmaceutical company founded on the history and values of an Italian family and committed to innovate cure and care to make patients’ lives better, announces the approval by Chinese regulatory authorities and the launch on the Chinese market of the intravenous (IV) formulation of Fluimucil® (N-acetylcysteine). This milestone marks a significant step in the company’s commitment to global therapeutic innovation in respiratory diseases, reflecting its dedicated focus on both clinical research and patient care. Already available in several international markets, Fluimucil® IV r

SWARM Biotactics Raised €13M to Advance Bio-Robotics From Lab to Field24.6.2025 08:43:00 CEST | Press release

SWARM Biotactics, developer of bio-robotic systems based on fully controllable living insects for mission-critical operations, has secured €10 million in seed funding, bringing its total raised to €13 million, including a €3 million pre-seed. The round was backed by a consortium of international investors from Europe, the United States, and Australia, including Vertex Ventures US, Possible Ventures, and Capnamic, who was the first investor in the pre-seed round. Several early backers also increased their stakes in the oversubscribed round. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250623790761/en/ A SWARM Biotactics bio-robotic unit equipped with a custom sensor backpack for intelligence gathering in inaccessible terrain. (Photo: SWARM Biotactics) UNMATCHED ACCESS FOR CRITICAL MISSIONS SWARM Biotactics is creating a new category of robotics: living, intelligent systems designed for environments where machines can’t go—c

Bloom Announces Early 2026 UK Launch, Expanding into Europe with New Garden Pharma as Exclusive Manufacturer24.6.2025 07:05:00 CEST | Press release

The Bloom Brand, a recognized U.S. leader in cannabis vape, is making its international debut in the United Kingdom through an exclusive partnership with New Garden Pharma, a leading European EU-GMP cannabis operator. Together, the two companies will launch Bloom’s award-winning Classic and Live vape collections in the UK in Q1 2026. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20250623573625/en/ This marks Bloom’s first international market expansion, as the company continues its global growth strategy with additional EU markets in development for 2026 and beyond. UK patients will gain access to Bloom’s superior formulations and proprietary hardware systems. For more than a decade, Bloom has built its reputation on delivering terpene-rich, flavor-forward strains paired with reliable technology. The brand has an established and leading presence across leading U.S. markets including California, Illinois, Florida, Michigan, Mi

ACI Worldwide Expands Technology Partnership Ecosystem to Power ACI Connetic24.6.2025 07:00:00 CEST | Press release

ACI’s unified cloud-based payments platform to boost operational resiliency and support increasing non-functional requirements of modern payment systems ACI Worldwide (NASDAQ:ACIW), an original innovator in global payments technology, has expanded its global technology partnership ecosystem to help financial institutions across the globe increase operational resiliency and address evolving regulatory requirements to safeguard the stability of the financial system. Building on strategic partnerships with Microsoft, Red Hat and IBM, ACI is collaborating with MongoDB, a document-oriented NoSQL database, and open source technology NATS from Synadia Communications for the reference architecture of ACI Connetic, ACI’s unified, cloud-native payments platform. These partnerships help extend ACI Connetic far beyond a traditional payments hub, delivering robust, highly functional payment engines to support financial institutions in meeting growingly stringent non-functional requirements and incr

In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.

Visit our pressroom
World GlobeA line styled icon from Orion Icon Library.HiddenA line styled icon from Orion Icon Library.Eye