New anomaly signal: INSECURE-AUTH

ngwaf-announcementsadded

We have introduced an anomaly signal (INSECURE-AUTH) that allows you to detect when insecure authentication methods are used (such as the JSON Web Tokens with the None Algorithm). Want to learn more? For full descriptions of this and all other system signals, check out our system signals documentation.

Prior change: Protection from CVE-2024-5806 (Progress MOVEit Transfer Authentication Bypass Vulnerability)

Following change: Next-Gen WAF configuration via the Fastly control panel