Back to blog

Follow and Subscribe

Fastly Security Research Team

Fastly Security Research Team

Fastly Security Research Team, Fastly

The Fastly Security Research Team focuses on ensuring our customers have the tools and data available to them to keep their systems secure. They analyze and ultimately help prevent attacks at Fastly scale. The team is a group of behind-the-scenes security experts who are here to help you stay on the cutting edge of the ever-evolving security landscape.

Page 1 of 3

What is Style Smuggler (CVE-2026-75650)?Matthew Mathur, Fastly Security Research Team
CVE-2026-75650 (StyleSmuggler) is a critical SSTI being actively exploited in ecommerce platforms. Learn what it is and how Fastly customers can stay protected.
Security
CVE-2026-82329: JFrog Artifactory Authentication Bypass Exploitation ActivitySimran Khalsa, Fastly Security Research Team
Attacks targeting JFrog Artifactory (CVE-2026-82329) exploded in 72 hours. Fastly threat intelligence breaks down the mass scanning surge—and how our virtual patch protects you today.
An illustration of a yellow, shining shield with a cracking gray shield peeling off of it
What is CVE-2026-66066? Protecting Your Rails App from Active Storage RCEMatthew Mathur, Fastly Security Research Team
Learn about CVE-2026-66066: An arbitrary file read vulnerability in Rails Active Storage. Understand the risks and protect your environment with our virtual patch.
Security
What is CVE-2026-23869? React Server Components Security AlertMatthew Mathur, Fastly Security Research Team
CVE-2026-23869: High-severity denial of service vulnerability in React Server Components. See impacts, affected versions, and get immediate protection with a virtual patch.
SecurityIndustry insights
React2Shell Continued: What to know and do about the 2 latest CVEsFastly Security Research Team
In the wake of the critical severity React2Shell CVEs, two new CVEs exploiting similar Next.js and React components were announced on December 11. Learn more about these new CVEs.
SecurityIndustry insights
AI Bots in Q2 2025: Trends from Fastly's Threat Insights ReportMatthew Mathur, David King, +1
Fastly's Q2 2025 Threat Insights Report uncovers how Meta, OpenAI, and others are shaping web traffic and what organizations need to do to stay in control.
SecurityIndustry insights+1
ToolShell Remote Code Execution in Microsoft SharePoint: CVE-2025-53770 & CVE-2025-53771Simran Khalsa, Matthew Mathur, +1
Microsoft revealed two critical vulnerabilities, CVE-2025-53771 and CVE-2025-53770, actively exploited to compromise SharePoint servers.
Security
TLS configuration icon
OS Command Injection ExplainedMatthew Mathur, Fastly Security Research Team
In this blog, we'll explore the web application vulnerability, OS Command Injection, and how to prevent it.
Security
CVE-2025-29927: Authorization Bypass in Next.jsMatthew Mathur, Fastly Security Research Team
A critical Next.js Vulnerability (CVE-2025-29927) lets attackers bypass authorization. Protect your applications now.
Security
DDoS in FebruaryArun Kumar, David King, +1
Fastly's February 2025 DDoS report reveals a 285% month-over-month surge in DDoS attacks. Learn about key trends, targeted industries, and actionable security guidance.
SecurityIndustry insights
DDoS in JanuaryArun Kumar, David King, +1
Stay informed with Fastly's monthly DDoS report, highlighting a 14.5% rise in attacks. Utilize our data-driven insights to bolster your application's security.
SecurityIndustry insights
DDoS in DecemberSimran Khalsa, David King, +1
Discover the latest trends and actionable insights on application DDoS attacks in December 2024. Strengthen your security with our expert analysis and guidance.
SecurityIndustry insights
Back to Basics of Automated Attacks: Account TakeoverArun Kumar, Fastly Security Research Team
Explore account takeover attacks and mitigations including modern authentication with 2FA/passkeys, and anti-bot measures to enhance account security.
Security
Detection as Code with Fastly's WAF SimulatorSimran Khalsa, Fastly Security Research Team
Being able to test and validate rule behavior is critical to a maintainable WAF. With our WAF Simulator, you can validate rules in a safe simulation environment.
DevOpsEngineering+2
Active exploitation of unauthenticated stored XSS vulnerabilities in WordPress PluginsFastly Security Research Team, Simran Khalsa, +2
We have observed active exploitation attempts targeting three high-severity CVEs: CVE-2024-2194, CVE-2023-6961, and CVE-2023-40000.
SecurityIndustry insights
How to Protect Against Credential Stuffing Arun Kumar, Fastly Security Research Team
In this post, we will discuss a low latency approach to detect these attacks by co-locating the password hashes in a KV Store, along with Compute on Fastly’s edge.
ComputeEdge network+2
An illustration of a yellow, shining shield with a cracking gray shield peeling off of it
Cyber 5 Threat InsightsSimran Khalsa, Charlie Bricknell, +1
To gain a broader understanding of the threat landscape during "Cyber 5" weekend, we analyzed attack activities with a particular focus on commerce sites.
Industry insightsSecurity+1
WAF Simulator: Transforming DevSecOps WorkflowsFastly Security Research Team, Simran Khalsa
We're excited to announce Fastly's new WAF Simulator, which simplifies the testing process and provides the following key benefits.
DevOpsEngineering+1
Patch that Vuln! Identify, Triage, and Qualify CVEsFastly Security Research Team, Simran Khalsa
Vulnerabilities are an unfortunate inevitability. However, when using a WAF there are options for your security teams while waiting for a patch.
SecurityDevOps+1
CVE-2023-30534: Insecure Deserialization in Cacti prior to 1.2.25Fastly Security Research Team, Matthew Mathur
We have discovered two instances of insecure deserialization in Cacti versions prior to 1.2.25, tracked as CVE-2023-30534.
Security