automatic web application & API security using machine learning

Joined September 2022
23 Photos and videos
šŸŽ¤ We’re excited to join #OWASP #FrankfurtChapter #75 in Germany on 25 Feb. Our Product Manager @chrislutat will show how a machine‑learning approach to Web App & API security delivers preemptive zero‑day protection without signatures. Using a recent major vulnerability as a case study, we’ll demonstrate how this model – integrated with a reverse proxy via the #opensource #openappsec #WAFproject – blocks emerging threats while reducing false positives and operational overhead vs. traditional WAFs… and more. šŸ’” We’re also looking forward to Shannon C. Ryan's talk on ā€œFrom Code to Leadership: Navigating the Tech Landscape as a Woman.ā€ šŸ¤ Thanks to the OWASP Frankfurt leadership team: Jonas, Jasmin, Dan, Dominik. šŸ“ Seats are limited – sign up now: meetup.com/de-de/owasp-frank… #openappsec #opensource #talk #owasp #frankfurt #waf #machinelearning #ai #threatprevention #nginx #kong #envoy #apisix #linux #docker #kubernetes #Checkpoint #itsecurity #websecurity #apisecurity
2
149
šŸ” Zero-Day Protection for React2Shell (CVE-2025-55182) The newly disclosed React2Shell vulnerability poses a serious risk to web applications. open-appsec delivers zero-day protection without relying on signatures or patches — thanks to its machine-learning-based security engine. šŸ“– Dive into the technical details: openappsec.io/post/zero-day-… #openappsec #ZeroDayProtection #CVE202555182 #AppSec #CyberSecurity #WAF #CheckPoint #linux #docker #kubernetes #cyber #nginx #kong #apisix #envoy #envoygateway #zeroday #owasp #opensource #itsecurity #machinelearning #ai #react #react2shell
1
3
399
25 Nov 2025
open-appsec ML/AI-based WAF Now Integrates with Envoy Gateway on Kubernetes! #openappsecĀ WAFĀ [openappsec.io] integration with #EnvoyGateway [gateway.envoyproxy.io] — now available as alpha! This powerful integration brings advanced, #machinelearning-driven web application protection to modern #Kubernetes environments using Envoy Gateway (no more #WAF signatures!). With this integration, you can: āœ… Seamlessly deploy open-appsec WAF agents alongside Envoy Gateway šŸ›”ļø Protect your web APIs and services with intelligent, adaptive #websecurity layers šŸ”„ Leverage continuous learning for proactive #threatprevention āœļø Eliminate reliance on traditional signatures — open-appsec uses ML to detect and block threats dynamically 🧠 Gain AI-based protection - not only against known threats, but also against unknown and emerging attacks šŸŒ #opensource - free community edition available šŸš€ We plan to provide further integration options with Envoy Gateway soon šŸ›”ļø Learn more about the open-appsec WAF project: openappsec.io šŸ”§ Get started now: lnkd.in/eHWUqxUh #openappsec #waf #opensource #envoy #envoygateway #checkpoint #threatprevention #machinelearning #owasp #ai #cyber #websecurity #apisecurity #kubernetes #linux #docker #nginx #kong #apisix #zerodayprotection
2
64
The open-appsec WAF #Meetup Tour is Coming Soon to various cities in Western Europe — and we’d love to meet you in person in Belgium, France, UK and Ireland! Join us for an afternoon packed with practical insights, hands-on demos, and great networking with Web & API Security professionals and enthusiasts. #openappsec (openappsec.io) is an #opensource Web Application & API security project (#WAF) that uses machine learning to deliver pre-emptive protection against #OWASP-Top-10 vulnerabilities and #zeroday attacks. No signatures, no rule-tweaking — just smart, scalable security for your infrastructure. šŸ“Œ What We’ll Cover in the Meetups - How open-appsec #WAF utilizes #machinelearning to protect Web Apps & APIs - Deploying a fully pre-emptive WAF to stop known and unknown zero-day #webattacks - Introducing our new SaaS tool for centrally managing #NGINX deployments - Real-world deployment examples - Live demo open discussion - Q&A, networking, food & drinks šŸ‘„ Who Should Attend - Developers & #DevOps / #DevSecOps professionals - Security engineers - Anyone interested in WAF, Web & #API #Security, and open-source security tools šŸ“ Upcoming Cities & Dates Brussels – September 22, 4 PM → RSVP here: meetup.com/open-appsec-waf-b… Paris – September 23, 4 PM → RSVP here: meetup.com/open-appsec-waf-p… London – September 24, 4 PM → RSVP here: meetup.com/open-appsec-waf-l… Edinburgh – September 25, 4 PM → RSVP here: meetup.com/open-appsec-waf-e… Dublin – September 26, 4 PM → RSVP here: meetup.com/open-appsec-waf-d… Seats are limited — don’t miss your chance to connect with the open-appsec team and your local security community. #openappsec #opensource #waf #meetup #brussels #paris #london #edinburgh #dublin #checkpoint #machinelearning #ai #websecurity #apisecurity #nginx #kong #apisix #istio #envoy #linux #docker #kubernetes #threatprevention #itsecurity #cyber #devops #devsecops #owasp
4
326
31 Jul 2025
New Beta: open-appsec WAF for Kong GatewayĀ is here – featuring native Kong Lua-plugin! šŸ” šŸ›”ļø Get machine learning-powered, signature-free protection against zero-days & OWASP Top 10 — directly at your #Kong gateway. āœ… Kong Gateway OSSĀ & Kong Enterprise āœ… Linux, Docker, and Kubernetes āœ… Declarative configs (GitOps-CD-ready)Ā and central WebUI āœ… Prevents zero-day attacks and known threats like OWASP Top 10 āœ… Preemptively prevented: Log4Shell, Spring4Shell, Text4Shell, MoveIt, … āœ… Lua-based, native Kong plugin āœ… Compatible with Kong Konnect šŸ“˜ Read the full blogĀ openappsec.io/post/introduci… #openappsec #kong #waf #lua #apisecurity #cloudsecurity #cybersecurity #devsecops #nginx #kubernetes #docker #luaplugin #gatewaysecurity #apisix #zeroday #AI #ML #websecurity #owasp #konggateway #kongkonnect #opensource #api #infosec #machinelearning #envoy #itsecurity #checkpoint
1
4
182
24 Jul 2025
šŸš€ Just released: open-appsec now supports Istio Ingress Gateway! If you're running #Kubernetes with #Istio, you can now deploy a machine-learning WAFĀ directly into your Istio Ingress Gateway for real-time protection against web and API attacks — including zero-days. šŸ¤–šŸ›”ļø šŸ‘‡ How it works: 🧱 open-appsec runs as an Envoy filter sidecar container in Istio Ingress Gateway pods āš™ļøĀ Easily deployed via Helm and injected into existing Ingress Gateway šŸ›”ļø True Zero-Day Threat Prevention šŸ”Ā Also protects against OWASP Top 10, command injection, and more 🧠 No signatures — it learns from traffic in your environment šŸ“ŠĀ Optional WebUI for centralized visibility, logs & config šŸ“Ā Or go full GitOps with local management using CRDs Read the full blog: openappsec.io/post/open-apps… #openappsec #waf #checkpoint #opensource #docker #kubernetes #linux #cybersecurity #devsecops #threatprevention #owasp #apisecurity #websecurity #itsecurity #infosec #cyber #web #api #apigateway #machinelearning #owasptop10 #informationsecurity #networksecurity #cloudsecurity #webattack #AI #devops #istio #envoy
2
262
29 Apr 2025
From Kindergarten to PhD - Leveraging open-appsec WAF Machine Learning Levels for a Robust Web Protection Manual WAF tuning can be time-consuming and complex. open-appsec is a machine learning-based WAF that simplifies the process with an automated learning model. In this blog, we explore how open-appsec’s Contextual Machine Learning progresses through different learning levels until it reaches the optimumĀ learning state. Represented through an educational analogy, these levels progress from Kindergarten to PhD, symbolizing the model’s increasing maturity and proficiency. These learning levels provide an interactive, user-friendly experience that guides teams through optimizing their WAF and improving its performance. šŸ”— Read the full blog openappsec.io/post/from-kind… #openappsec #waf #checkpoint #opensource #docker #Kubernetes #linux #CyberSecurityAwareness #devsecops #nginx #threatprevention #owasp #apisecurity #websecurity #itsecurity #infosec #cyber #web #api #apigateway #machinelearning #owasptop10 #informationsecurity #networksecurity #cloudsecurity #webattack #AI #DevOps #kong #apisix #envoyespecial
1
1
120
24 Mar 2025
Payswiff, a leader in digital payment solutions, shared its success story of deploying open-appsec WAF and securing 900 million HTTP requests over the past year. Read more: openappsec.io/post/from-zero… #payswiff #openappsec #opensource #waf #checkpoint #MachineLearning #nginx
1
6
127
22 Jan 2025
šŸš€Exciting news! open-appsec, the ML-based, open-source WAF solution, now supports new Docker-Compose-based deployment (beta) with various new capabilities. Learn more here: openappsec.io/post/open-apps… #opensource #cybersecurity #devsecops #docker #waf #machinelearning #openappsec
6
94
24 Oct 2024
We are thrilled to announce open-appsec WAF new integration with Apache APISIX. Thank you API7 team for hosting our blog and for this amazing collaboration! #openappsec #api7 #apisix #waf #apigateway #docker #Kubernetes #Linux #waf #websecurity #machine_learning #appsecurity
Apache APISIX is excited to announce a new integration between Apache APISIX and open-appsec WAF, combining the power of a dynamic API gateway with cutting-edge machine-learning-based application security. apisix.apache.org/blog/2024/…
2
153