Imperva Application Security Integrates API Detection and Response, Setting A New Standard in API Security
24.6.2025 10:00:00 EEST | Business Wire | Press release
Thales today announced new detection and response capabilities in the Imperva Application Security platform to protect against business logic attacks, such as Broken Object Level Authorization (BOLA) – the leading threat in the OWASP API Security Top 10. By integrating real-time detection with automated mitigation of risky APIs, BOLA attacks, unauthenticated APIs, and deprecated APIs, Imperva Application Security platform delivers comprehensive protection against unauthorized data exposure and other complex business logic vulnerabilities across cloud and on-premises environments.
APIs have become the backbone of modern applications, enabling businesses to seamlessly connect services, optimize operations, and deliver personalized experiences at scale. According to Imperva Threat Research, APIs accounted for 71% of all web traffic. More recently, the team observed a sharp rise in API-directed attacks, with 44% of advanced bot traffic targeting APIs, compared to just 10% targeting web applications. This shift underscores how attackers are increasingly exploiting API endpoints that manage sensitive and high-value data.
Why BOLA is a Critical Business Risk
BOLA occurs when APIs fail to properly verify whether users are authorized to access specific data objects. This allows attackers to manipulate requests and gain unauthorized access to sensitive information. As the leading OWASP Top 10 API threat, BOLA exposes businesses to significant risks, including data breaches, compliance failures, and loss of customer trust.
“API security is no longer optional – it’s fundamental to maintaining business continuity and trust,” said Tim Chang, Global Vice President and General Manager of Application Securityat Thales. “Imperva Application Security bridges the gap by delivering a fully unified platform that identifies business logic threats and actively blocks malicious sessions, setting a new benchmark for API protection.”
Empowering Enterprises with a Unified, Flexible, and Privacy-First Solution
Imperva Application Security integrates advanced threat detection engines with automated inline responses and flexible deployment options, enabling security teams to detect and respond to API attacks like BOLA without slowing development or disrupting the user experience. For customers who want to protect their API infrastructure, Imperva Application Security delivers the following benefits:
- Unified Platform Architecture: Manage API discovery, risk assessment, detection, and mitigation in a single console, eliminating tool sprawl and operational friction across cloud and on-premises environments.
- Real-Time BOLA Detection: Hybrid behavioral and rule-based engines analyze API request patterns, scoring anomalies, and flagging endpoints for immediate action.
- Automated Response and Remediation: Integration with Imperva Cloud WAF and WAF Gateway enables a variety of response actions, including inline mitigation actions such as automatically blocking malicious API traffic in real-time. Integration with security automation tools ensures rapid incident orchestration.
Advancing the Imperva Security Anywhere Vision
The integration of API detection and response into Imperva Application Security is foundational to the Imperva Security Anywhere vision, which provides scalable, end-to-end protection for applications and APIs across any environment. This unified solution provides enterprises with a comprehensive view of automated threats targeting APIs and the necessary tools to protect those APIs.
Detection and response to deprecated APIs, unauthenticated APIs, and BOLA attacks are now available as part of Imperva Application Security.
About Thales
Thales (Euronext Paris: HO) is a global leader in advanced technologies for the Defence, Aerospace, and Cyber & Digital sectors. Its portfolio of innovative products and services addresses several major challenges: sovereignty, security, sustainability and inclusion.
The Group invests more than €4 billion per year in Research & Development in key areas, particularly for critical environments, such as Artificial Intelligence, cybersecurity, quantum and cloud technologies.
Thales has more than 83,000 employees in 68 countries. In 2024, the Group generated sales of €20.6 billion.
PLEASE VISIT
Cloud Protection & Licensing Solutions | Thales Group
Cybersecurity Solutions | Thales Group
View source version on businesswire.com: https://www.businesswire.com/news/home/20250624052385/en/
Contacts
Thales, Media Relations
Security & Cybersecurity
Marion Bonnet
+33 (0)6 60 38 48 92
marion.bonnet@thalesgroup.com
About Business Wire
For more than 50 years, Business Wire has been the global leader in press release distribution and regulatory disclosure.
www.businesswire.com

Subscribe to releases from Business Wire
Subscribe to all the latest releases from Business Wire by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from Business Wire
Enry’s Island Unveils “Enry’s Island Adventures”: Venture Capital Becomes a Videogame and Launches the “Strap” Movement on Kickstarter3.4.2026 10:47:00 EEST | Press release
Enry’s Island SpA (WBAG: EIOS), the world’s first publicly traded Venture Builder, today announced the upcoming Kickstarter launch of Enry’s Island Adventures (EIA), developed by its New York-based portfolio company, Enry’s Island Adventures LLC. This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260402548535/en/ The game is designed to make venture capital accessible to new generations, transforming startup creation into an engaging and social gaming experience. After three years of R&D, EIA introduces a "bleisure" model (business + leisure): players learn to launch and manage startups through gameplay that includes real business KPIs, a customizable and evolving personal island, synchronous and asynchronous multiplayer modes, social events, and community-driven seasonal missions. The “VC revolution”: teaching and democratizing through play "I agree with Elon Musk that the best way to teach is through a video game, and this is
SES Announces Results of the Annual General Meeting2.4.2026 17:49:00 EEST | Press release
SES (the “Company”) held the Annual General Meeting (“AGM”) of Shareholders today in Betzdorf, Luxembourg. Following the recommendations made by the Board of Directors of SES, the shareholders have voted in favor of all resolutions, including the Company’s 2025 annual accounts and the proposed annual dividend of EUR 0.50 per A-share (EUR 0.20 per B-share). The total dividend amount comprises the interim dividend of EUR 0.25 per A-share (EUR 0.10 per B-share), which has already been paid to shareholders on October 16, 2025. The final dividend of EUR 0.25 per A-share (EUR 0.10 per B-share) will be paid to shareholders on April 16, 2026. “I would like to sincerely thank our shareholders for their active engagement, visionary support and continued confidence in SES’ strategy,” said Adel Al-Saleh, CEO of SES. “The outcomes of today’s AGM underscore our shared commitment to a bold multi-orbit approach, with Medium Earth Orbit as the strategic backbone of a dynamically evolving global interco
Forrester: Three Years Into GenAI, Enterprises Are Still Chasing Its True Transformative Value2.4.2026 17:00:00 EEST | Press release
According to Forrester’s (Nasdaq: FORR) latest report, Accelerate Your AI Voyage, most enterprises are struggling to turn growing AI adoption and investment into measurable business impact. One of the key factors holding businesses back is low artificial intelligence quotient (AIQ) — Forrester’s measure of AI aptitude — with many employees lacking a clear understanding of how to use AI. Other barriers include an overemphasis on productivity-focused use cases, difficulty measuring impact, and siloed adoption within individual functions. While these challenges can leave firms frozen in doubt or indecision, the wait-and-see approach to AI adoption is no longer viable. To unlock AI’s full potential, organizations need to focus on four key areas: Define the business outcomes and success metrics for what they want AI to achieve; identify specific use cases for AI deployment aligned to those business outcomes; establish a structured runway to plan, test, and strategically time the deployment
Andersen Consulting Adds Multiplica2.4.2026 16:30:00 EEST | Press release
Andersen Consulting enters into a Collaboration Agreement with Multiplica, a digital consulting firm that helps organizations design, build, and scale impactful digital experiences. Founded in Spain with a presence in Latin America and the U.S., Multiplica focuses on user research and discovery, customer experience research, digital strategy, data modeling and analysis, report automation and data visualization, conversion rate optimization, product design, and user experience design. The firm helps organizations accelerate digital transformation by building digital capabilities, teams, and assets that advance expertise across digital products, consulting, and talent development. Multiplica enables clients to forecast emerging trends in digital experience and transform their businesses through enhanced digital channels and customer engagement. “Collaborating with Andersen Consulting represents an exciting opportunity to extend our reach and impact,” said David Boronat, CEO of Multiplica
Brightfin Unifies Brand Following Proven Optics Merger, Delivering a New Standard for Technology Cost Optimization2.4.2026 16:00:00 EEST | Press release
Brightfin today announced that, following its merger with Proven Optics, the combined company will operate under a single brand: Brightfin. The unified company brings together deep expertise in Technology Expense Management (TEM) and IT Financial Management (ITFM) to help organizations better understand, manage, and reduce total technology spend. Technology spending will exceed $6 Trillion this year, and for most organizations, it remains one of the least understood. CIOs can tell you what they’re spending. Far fewer can tell you whether it’s working. “Over the past several months, we’ve brought these two businesses together around a shared purpose: help enterprise businesses better understand and optimize their technology spend,” said Joel Martins, CEO of Brightfin. “What we are seeing now is a shift. Visibility alone isn’t enough. Teams need to be able to act, tied to real financial outcomes. See Clearly. Spend Better. That is our north star, and that is what our platform is built to
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom