EMA Research –Only 33% of enterprises enforce AI agent least privilege access
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
BlogContact Us
Cequence Security
Financial Services
2023-predictions-staying-one-step-ahead-in-api-protection,api-security-2024-predictions,api-security-financial-services,api-security-lacking-for-ecosystem-and-third-party-apis,api-security-breaches,cfpb-announces-major-open-banking-proposed-rule,ffiec-api-security-guidance,financial-aggregators-a-vehicle-for-credential-exploitation,financial-services-api-protection,financial-services-customer-stops-millions-of-api-based-account-takeover-attacks-ato,guest-blog-api-security-off-to-a-booming-start-but-were-not-done-yet,reaching-a-tipping-point-in-identity-verification,regulations-and-standards-drive-need-for-api-security,revised-payment-services-directive-psd2,shield-right-while-shifting-left-to-eliminate-fdx-api-security-gaps-at-runtime,tales-from-the-front-lines-protecting-financial-services-mobile-application-apis-from-automated-attacks,the-open-banking-api-security-imperative,unpacking-the-new-cfpb-rule-on-open-banking
financial-services
Current Events
api-breach-duolingo,api-security-need-to-know-lessons-learned-from-the-peloton-security-incident,disney-account-takeovers-how-the-information-is-used-2
current-events
Industry Reports
api-layer-attacks-2026-dbir,best-in-class-api-security,dbir-api-security,new-api-threat-research-shows-that-shadow-apis-are-the-top-threat-vector,survey-highlights-api-business-value-and-api-security-balancing-act,verizon-2025-dbir-review,verizon-dbir-insights,when-does-comparison-shopping-become-malicious
industry-reports
OWASP
2023-predictions-staying-one-step-ahead-in-api-protection,api-breach-duolingo,api-protection-and-cloud-native-application-protection-platforms-cnapp,api-security-financial-services,api-security-meets-government-regulators,api-security-need-to-know-top-5-authentication-pitfalls,api-security101,api-security-breaches,cfpb-announces-major-open-banking-proposed-rule,connected-car-safety-and-api-security,evolution-of-owasp-api-top-10,owasp-api-risks-cant-be-blocked-but-can-be-fixed,owasp-api-vulnerabilities-exploited-to-bypass-api-security,tales-from-the-front-lines-how-third-party-apis-simplify-enumeration-attacks,top-7-selection-criteria-for-automated-bot-prevention-solutions,unpacking-the-new-cfpb-rule-on-open-banking,zero-trust-api-security-model
owasp
Product News
a-winning-trifecta-api-gateways-api-security-and-api-protection,advance-your-api-security-with-amazon-api-gateway-api-sentinel,ai-agent-prompt-injection-credential-theft,api-protection-in-heterogeneous-environments,application-security-in-kubernetes-why-we-joined-cncf,cequence-achieves-pci-dss-3-2-and-soc-2-compliance,cequence-end-of-year-product-recap-strengthening-your-api-security,cequence-security-awarded-best-enterprise-cybersecurity-solution-of-the-year,cequence-securitys-unified-api-protection-solution-wins-three-2023-globee-awards,cequence-unified-api-protection-wins-2023-cyber-top-20-award,cequence-api-security-and-hpe-greenlake,complete-api-security-coverage-with-proxy-and-service-mesh-integration,complete-api-security-with-cequence-uap-and-cdn-integrations,groundbreaking-api-security-generative-ai,sinet16-innovators-award-validates-api-security-and-bot-management-belong-together
cequence-product-news
CQ Prime Threat Research
a-defenders-view-of-log4j-in-automated-attacks,anatomy-of-a-retail-shopping-bot,api-security-need-to-know-excessive-data-exposure,api-threat-research-validates-robust-api-security,bot-as-a-service-the-consumerization-of-botting,cequence-blocks-credential-stuffing-attack,fake-account-creation-its-fraud-by-any-other-name,heres-why-javascript-based-bot-detection-doesnt-work-is-your-site-listed-here,hidden-dangers-of-untrusted-mcp-servers,how-this-cool-sneakerhead-mom-beat-the-bots,long4j,long4j-findings-confirm-log4j-vulnerability-patching-gaps,moving-from-threat-hunting-to-threat-catching,multi-tenant-saas-authentication-bypass-or-works-as-designed,network-iq-how-the-largest-api-threat-database-protects-your-apis,new-api-research-shows-62-growth-in-atos-targeting-login-apis,new-report-big-breaches-breed-bad-bots,reality-check-automated-shopping-bots-are-a-business-problem,romance-scams-plague-dating-apps,state-of-api-security-activity,the-api-security-conversation-that-the-verizon-data-breach-report-missed,what-are-api-keys-and-why-do-i-need-api-key-security
cq-prime-threat-research
About Cequence
3-steps-to-shielding-right-while-shifting-left-for-api-protection,agentic-ai-monetization,are-api-threat-protection-and-bot-management-related,cequence-achieves-aws-security-competency-status,cequence-announces-ml-based-security-enhancements,cequence-security-awarded-best-enterprise-cybersecurity-solution-of-the-year,cequence-security-named-a-2021-tag-cyber-distinguished-vendor,cequence-securitys-unified-api-protection-solution-wins-three-2023-globee-awards,cequence-unified-api-protection-wins-2023-cyber-top-20-award,cfpb-announces-major-open-banking-proposed-rule,comprehensive-api-protection,enabling-retail-deals-and-repelling-the-steals,ffiec-api-security-guidance,guest-blog-api-security-off-to-a-booming-start-but-were-not-done-yet,hand-sanitizer-samples-face-masks-and-api-security-an-rsa-2020-recap,industry-recognition-for-api-sentinel-kuppingercole,javascript-injection-good-for-fraud-detection-bad-for-security-2,making-a-build-vs-buy-bot-prevention-decision,organizations-are-changing-application-security-must-change-too,predictions-2021-getting-an-edge-against-the-bots,prep-the-halls-readying-your-retail-environment-for-the-holiday-rush,reaching-a-tipping-point-in-identity-verification,rsa-conference-2023-api-security,safeguarding-financial-health-why-cfos-should-prioritize-api-security,shield-right-while-shifting-left-to-eliminate-fdx-api-security-gaps-at-runtime,sinet16-innovators-award-validates-api-security-and-bot-management-belong-together,some-recent-api-security-related-gaffes-and-how-they-might-have-been-avoided,ten-things-your-api-security-solution-must-do-part-i,ten-things-your-api-security-solution-must-do-part-ii,the-analyst-perspective-observations-from-cequences-2021-api-specification-survey,unified-api-protection,unpacking-the-new-cfpb-rule-on-open-banking,what-happens-when-your-entire-company-learns-ai-together-we-found-out,why-do-i-need-api-security-if-i-have-a-waf-and-api-gateway,why-unified-api-protection
about-cequence
Customer Case Studies
api-security-case-study,application-security-solving-the-hardest-problem-first,balancing-bot-detection-with-customer-experience,cequence-unified-api-protection-squashes-phishing-campaign-in-a-matter-of-hours-time-to-value,customer-story-zoosk-security,financial-aggregators-a-vehicle-for-credential-exploitation,flash-sales-and-sneaker-drops,gift-card-and-loyalty-program-abuse,poshmark-api-protection-case-study,sms-pumping-fraud,tales-from-the-front-lines-protecting-financial-services-mobile-application-apis-from-automated-attacks,tales-from-the-front-lines-retail-customer-stops-200k-gift-card-fraud-scheme
customer-case-studies
API Security
2026-verizon-dbir-bots-web-app-attacks-agentic-ai,a-year-in-review-in-one-word-momentum,agentic-ai-application-protection-platform-waap,announcing-api-sentinel,announcing-cequence-waap,announcing-general-availability-of-cequence-api-sentinel-2-0,announcing-unified-api-protection-v2-0,api-layer-attacks-2026-dbir,api-security-api10-defined-as-bots-abusing-well-formed-apis,api-security-lacking-for-ecosystem-and-third-party-apis,api-security-need-to-know-lessons-learned-from-the-peloton-security-incident,api-security-threat-research-retail-holiday-report-2023,app-instrumentation,attack-detection-and-threat-hunting-common-topics,automating-attacks-with-chatgpt,better-bot-management,bola-attack-protection-telecom,business-logic-abuse,canadas-largest-retail-pizza-chain-moves-from-reactive-to-proactive-api-protection-with-cequence,cequence-achieves-pci-dss-3-2-and-soc-2-compliance,cequence-and-software-ag-partner-to-deliver-end-to-end-api-security,cequence-api-security-at-black-hat-2024,cequence-end-of-year-product-recap-strengthening-your-api-security,cequence-named-to-cyber-66-list,cequence-q4fy26-momentum-agentic-ai-security,cequence-security-makes-its-rsa-debut-2,cequence-unified-api-protection-squashes-phishing-campaign-in-a-matter-of-hours-time-to-value,cequence-api-security-and-hpe-greenlake,chatgpt-for-api-security,comprehensive-api-protection,discover-public-api-attack-surface-with-new-api-spyder,end-to-end-api-security,financial-services-api-protection,gartner-recognition-when-it-rains-it-pours,gift-card-and-loyalty-program-abuse,hey-api-what-you-token,how-a-broken-object-level-authorization-vulnerability-exposed-sensitive-data-api-security-report,how-automated-api-attacks-are-the-digital-equivalent-of-mockingbirds,how-bola-leads-to-enumeration-and-ato-attacks,idor-vulnerability,introducing-api-bites-from-cequence-security,iocs-in-your-apis,kasa-camera-vulnerability-discovery,leading-telecom-slashed-account-takeovers,looking-for-a-silver-tail-replacement,mergers-and-acquisitions-in-api-security-and-bot-management,new-api-threat-research-shows-that-shadow-apis-are-the-top-threat-vector,owasp-api-security-top-10-a-framework-for-improving-your-api-security-efforts,owasp-api-security-top-10-from-a-real-world-perspective,owasp-api-vulnerabilities-exploited-to-bypass-api-security,owasp-appsec-training-day-api-attacks-beyond-the-owasp-api-top-10,owasp-top-10-lists-end-state-or-starting-point,prying-eye-vulnerability-direct-to-api-enumeration-attack-enables-snooping,regulations-and-standards-drive-need-for-api-security,tales-from-the-front-lines-attackers-on-lockdown-focus-on-apis,tales-from-the-front-lines-attackers-target-apis-with-get-based-atos,tales-from-the-front-lines-protecting-financial-services-mobile-application-apis-from-automated-attacks,tales-from-the-frontlines-api-sentinel-drives-security-collaboration,the-cequence-security-blog-top-5-posts-of-2020,the-danger-of-web-scraping-and-how-to-prevent-it,ulta-beauty-reduces-costs-by-blocking-api-based-enumeration-attacks,unified-api-protection-7-3,unified-api-protection-for-telcos-customer-testimonial,unified-api-protection-recognized-kuppingercole,whats-new-cequence-api-security-platform-further-advances-end-to-end-vulnerability-and-automated-attack-mitigation,whats-new-cequence-unified-api-protection-siem-integration
api-security
Bot Management
2022-predictions-protecting-an-api-centric-world,2025-api-security-predictions,2026-verizon-dbir-bots-web-app-attacks-agentic-ai,a-defenders-view-of-log4j-in-automated-attacks,agentic-ai-api-security,agentic-ai-application-protection-platform-waap,agentic-ai-security-behavioral-analysis,ai-agents-are-bots-api-defense,analysis-preventing-fake-account-creation-and-romance-scams-2,announcing-cequence-waap,api-0day-response-a-moveit-story,api-breach-duolingo,api-layer-attacks-2026-dbir,api-protection-and-cloud-native-application-protection-platforms-cnapp,api-protection-in-heterogeneous-environments,api-protection-in-telecommunication-protected-in-less-than-30-minutes,api-security-2024-predictions,api-security-api10-defined-as-bots-abusing-well-formed-apis,api-security-in-your-operational-technology-ot,api-security-lacking-for-ecosystem-and-third-party-apis,api-security-podcast-how-apis-enable-digital-transformation-and-automated-attacks,api-security-threat-research-retail-holiday-report-2023,api-threat-detection,api-threat-prevention,api-threat-research-validates-robust-api-security,are-api-threat-protection-and-bot-management-related,are-these-13-scary-security-gaps-in-your-apis,automating-api-security,aws-vpc-traffic-mirroring-integration-coming-soon-2,beyond-magecart-understanding-the-risks-and-impacts-of-third-party-javascript,block-api-attacks,bot-attacks-one-week-in-the-life-of-a-customer,bulletproof-proxies-the-evolving-cybercriminal-infrastructure,bulletproof-proxy-market-update,business-impacts-of-api-security-breaches,canadas-largest-retail-pizza-chain-moves-from-reactive-to-proactive-api-protection-with-cequence,cequence-security-awarded-best-enterprise-cybersecurity-solution-of-the-year,cequence-securitys-unified-api-protection-solution-wins-three-2023-globee-awards,cequence-unified-api-protection-wins-2023-cyber-top-20-award,creating-credential-stuffing-resistant-applications,dbir-api-security,disney-account-takeovers-how-the-information-is-used-2,ffiec-api-security-guidance,financial-services-api-protection,forrester-bot-management-wave-2022,fortune-500-retailer-saves-1-7-million-by-eliminating-account-take-overs-2,heres-why-online-holiday-inventory-is-often-gone-before-you-get-there-3,how-shadow-apis-simplify-automated-attacks,implementing-a-dynamic-sampling-strategy-in-spark-streaming,industry-recognition-for-runtime-application-security-omdia-research,introducing-cq-prime-the-cequence-security-threat-research-team,moving-fast-without-api-guardrails,old-habits-die-hard-industrial-controls-credential-sharing-and-password-spraying,pci-dss-4-compliance-api-security,poshmark-api-protection-case-study,rsocks-takedown,simplifying-bot-prevention-with-cdn-integration,sinet16-innovators-award-validates-api-security-and-bot-management-belong-together,state-of-api-security-activity,survey-highlights-api-business-value-and-api-security-balancing-act,tales-from-the-front-lines-a-long-weekend-ruined-for-whom-2,tales-from-the-front-lines-attackers-on-lockdown-focus-on-apis,tales-from-the-front-lines-attackers-target-apis-with-get-based-atos,tales-from-the-front-lines-how-third-party-apis-simplify-enumeration-attacks,tales-from-the-front-lines-large-retailer-achieves-near-immediate-time-to-value,tales-from-the-front-lines-maintaining-detection-efficacy-and-your-cool-in-the-summer-heat,tales-from-the-front-lines-protected-in-just-33-minutes,tales-from-the-front-lines-retailer-prepares-for-holiday-bot-battle-in-a-matter-of-weeks,tales-from-the-front-lines-why-simple-attacks-like-content-scraping-are-the-hardest-to-block,tales-from-the-frontlines-increasingly-sophisticated-cat-and-mouse-games,ten-things-your-api-security-solution-must-do-part-ii,the-critical-role-real-time-protection-plays-in-api-security,the-rise-fall-of-single-request-bots-2,threat-advisory-recent-high-volume-bot-traffic-from-ipvanish-vpn-against-retailers,unified-api-protection,unified-api-protection-7-3,using-an-api-security-checklist-what-should-you-look-for,verifiable-ai-agent-identification,verizon-dbir-insights,what-are-fake-accounts-and-how-can-they-be-worth-44-billion,what-is-account-takeover-ato,what-is-api-threat-detection,what-is-api-threat-mitigation,what-sets-cequence-apart-from-anyone-else,why-unified-api-protection,your-bot-problem-may-be-an-api-problem
bot-management
AI
2026-verizon-dbir-bots-web-app-attacks-agentic-ai,agentic-ai-api-security,agentic-ai-monetization,agentic-commerce-bot-defense,ai-gateway-introduction,automating-attacks-with-chatgpt,beyond-captcha-biometric-verification-bot-detection,bot-defense-pricing-success-penalty,chatgpt-for-api-security,the-genai-gold-rush
ai
Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.

FEATURED BLOG

AI Security Blog

Introducing Agent Trust: Managing Agents with Identity Plus Behavior

AI agent identity verification proves who an agent is. Agent Trust adds behavioral analysis so security teams can govern what it does.
Read More
Introducing Agent Trust: Managing Agents with Identity Plus Behavior
A stylized image representing an agent with a banner across it that reads TRUSTED.
AI

Introducing Agent Trust: Managing Agents with Identity Plus Behavior

September 24, 2026

Read Blog
AI agent identity verification proves who an agent is. Agent Trust adds behavioral analysis so security teams can govern what it does.
A stylized illustration of a key with lines going through it representing agentic traffic.
AI

Beyond Identity – Agentic AI Requires Governing Actions and Behavior

September 17, 2026

5

Read Blog
Starting in late December 2025, a single attacker convinced Claude Code that a hacking campaign against nine Mexican government agencies and a financial institution was an authorized penetration test. The account was real and properly authenticated throughout: the attacker never stole any credentials and never had to break an authentication check to make any of […]
A stylized image representing a mapping of Cequence AI Gateway controls to the OWASP Top 10 for Agentic Applications
AI

Mapping Cequence AI Gateway Controls to OWASP’s Top 10 for Agentic Applications

September 10, 2026

7

Read Blog
Hidden instructions embedded in a shared document were enough to turn a Microsoft 365 Copilot session into a channel for exfiltrating sensitive data, an incident now known as “EchoLeak” — no phishing email, no malicious click, just a document the agent was already trusted to read. Incidents like this are why the OWASP Gen AI […]
EMA Agents Without Guardrails research report cover
AI

Agents Without Guardrails: Why Agentic AI Governance Must Focus on Behavior, Not Just Identity

August 31, 2026

7

Read Blog
Enterprises have spent decades building security around a familiar question: Who are you? Identity and access management (IAM), authentication, service accounts, OAuth tokens, and role-based access controls all start there. Establish identity, assign permissions, and control access. Agentic AI changes the equation. AI agents do not simply access systems. They reason, select tools, call APIs, retrieve […]
An illustration of a gift box with a bow and an ENTER TO WIN sign on it and icons representing bots are attacking the box and how Cequence stopped a sweepstakes attack
Bot Management

Inside a Sophisticated, Automated Sweepstakes Attack — and How Cequence Stopped It

August 27, 2026

7

Read Blog
Some attacks announce themselves with malformed requests and datacenter IP ranges. The most dangerous ones look exactly like your best customers. Cequence recently encountered an incident of the latter kind alongside a major consumer brand — a large, patient, and genuinely sophisticated automated abuse campaign against a high-value prize sweepstakes — and the telemetry is […]
An illustration of a fingerprint with a check on it surrounded by failed CAPTCHA symbols.
Bot Management

CAPTCHA Has Fallen Behind – Biometric Check is Built for Today’s Traffic

August 20, 2026

5

Read Blog
Key Takeaways Most bot management vendors still fall back on CAPTCHA or SMS codes when traffic looks suspicious — friction that AI now defeats more reliably than the humans it was built to test. A 2023 UC Irvine study found bots solving CAPTCHA at 99.8% accuracy against a 50–84% human range. CAPTCHA is a browser […]
A stylized graphic of squiggly lines representing network traffic and AI agents being discovered.
AI

Shadow AI: You Can’t Govern What You Can’t See

August 13, 2026

5

Read Blog
Your company’s agentic AI footprint is bigger than you think Ask a security team to count the AI agents running in their environment and you’ll get a reasonable answer: the sanctioned Copilot deployment, a Claude rollout, a handful of MCP servers the platform team stood up for Microsoft 365 and Atlassian. But when a global […]
An illustration of several cubes with checkmarks on them representing tasks to be done.
API Security

Operationalizing API Security: The Right Order for Rolling Out Detection and Remediation

August 6, 2026

8

Read Blog
API security solutions have plenty of table-stakes capabilities by now: discovery, inventory, a rule engine, dashboards. A successful rollout hinges on whether the product can actually be turned on in stages at scale — one category validated before the next, one traffic source confirmed before the next — instead of forcing a team into turning […]
An illustration of balls representing AI agents breaking through a wall, representing containment.
AI

What the Hugging Face Breach Teaches Us About Agentic AI Governance

July 31, 2026

8

Read Blog
An OpenAI agent broke into Hugging Face’s production infrastructure, and every security control in its path allowed it. The headline reads like science fiction; the mechanics don’t. A long chain of individually permitted actions added up to a full intrusion, and noticing the chain wasn’t any control’s job. How the breach unfolded OpenAI was measuring […]
An illustration of a 2.5-dimensional block with the letters “LLM” on it and connections from all sides.
AI

Eliminate Model Access Exposure with Cequence AI Gateway’s LLM Governance

July 30, 2026

6

Read Blog
One governed path for every tool call, API request, agent interaction, and LLM prompt Enterprises have started to govern the tools and APIs that AI agents use, but many still leave a critical path exposed: the agent’s direct connection to a large language model (LLM). That connection often carries a provider credential, accepts untrusted prompt […]
An illustration of a box with the top slightly ajar and an AI agent inside.
AI

AI Agents Are Digital Insiders. Treat Them Like It.

July 23, 2026

6

Read Blog
Picture the quietest hour in your environment — 3 a.m., nobody logged in, dashboards calm. And yet your AI agent is wide awake: reading records, calling APIs, moving data between systems, deciding what to do next and then doing it. Now here’s the part that should give you pause. Every one of those actions is […]
A stylized graphic of agents in the cloud and a cityscape beneath with an AI Gateway governance layer in between.
AI

The Insider Has Left the Building: Agentic Governance Beyond Managed Devices

July 9, 2026

6

Read Blog
On July 7, Anthropic moved Claude Cowork to the cloud. The agent now runs on web and mobile, keeps working in the background with no device online, and acts across your files, email, calendar, and connected tools until the job is done. A few weeks earlier, OpenAI shipped Workspace Agents, Codex-powered agents that run inside […]
A collage of various items with the words SOLD OUT underneath each.
Bot Management

When the Drop Becomes the Target: Defending Limited-Edition Hype Sales from Scalper Bots

July 7, 2026

7

Read Blog
~2x Reduction in fraudulent account takeovers ~70 IPs each firing 500+ requests in a single 30-minute window ~1 in 5 malicious requests to the inventory-availability endpoint blocked at peak ZERO downtime or added friction for genuine shoppers A limited-edition collectible. A fixed launch time. A small, unpredictable amount of stock that sells out in minutes. […]
The Cequence logomark inside a globe on top of a Cequence dashboard.
API Security

The API security expert you don’t have to hire

June 30, 2026

9

Read Blog
Cequence Platform 9.0 embeds an AI assistant and exposes the full platform via MCP, so every team gets the expertise it needs and every agent gets the access it earns. AI agents are changing how customers interact with applications. Shopping, banking, claims processing, network configuration — workflows that once required a human to navigate a […]
An abstract image that looks like a topographic map.
Bot Management

Introducing Intent Graph: Adaptive Behavioral Fingerprinting to Stop the Most Sophisticated Bot Attacks

June 26, 2026

8

Read Blog
Behavioral intent: the attack signal that survives every evasion attempt Every security team eventually hits the same uncomfortable realization: the signals they rely on to detect malicious activity can be faked. IP addresses rotate. User-agent strings are trivial to spoof. Even structural fingerprints, which once represented a real leap forward in bot detection, can be […]
A stylized image of an AI agent contained in a glass dome.
AI

Agent Containment: Definition, Risks, and Techniques

June 25, 2026

10

Read Blog
Anthropic recently published a detailed account of how it contains Claude across its products, including the vulnerabilities its own defenses missed. The article surfaces a discipline most enterprises will need long before they finish their first agentic AI project: agent containment. AI agents now write code, query databases, file tickets, and update records, and every […]
A stylized reservation page.
Bot Management

How a Travel Industry Business Reduced Automated API Abuse and Streamlined Security Operations

June 18, 2026

4

Read Blog
How intelligent bot management helped a large travel industry organization improve operational stability and gain visibility into automated activity targeting its digital reservation ecosystem. The Challenge: Managing Automated Activity at Scale Operating a large-scale digital reservation platform means processing millions of API transactions every day. For this travel industry business, the scale and accessibility of […]
The word WAAP with a spotlight on it on a teal background.
AI

Agentic AI Is Making Application Protection a Platform Problem

June 17, 2026

7

Read Blog
For years, security teams charged with protecting applications, APIs, and data have debated which threats matter most. Bots. APIs. Web application attacks. DDoS campaigns. Entire markets have emerged around each category, with specialized tools designed to address specific attack vectors. Today, agentic AI is making those distinctions increasingly irrelevant. Autonomous systems won’t limit themselves to […]
A stylized image with lines in the background representing traffic and balls on top representing AI agents.
AI

When AI Agents Become Bots: A Field Report from the Authentication Layer

June 16, 2026

5

Read Blog
Security vendors and their customers have spent considerable time debating where to draw the line between “legitimate” AI agents and “malicious” bots. A 31-day campaign against a major consumer platform’s authentication infrastructure settled the argument. In the context of unauthorized API access at machine speed, the two can be the same problem. The threat wore […]
A picture of a sphere with blue dots representing LLMs and red lines representing attacks.
AI

Why the Security Controls Built Into LLMs Aren’t Enough

June 11, 2026

5

Read Blog
LLM vendors are increasingly building security features and guardrails into their models. However, the controls inside the model are designed for a contained, request-response world. A user sends a prompt, and the model returns a response. LLM security focuses on making that response safe. Agentic AI shows us how insufficient those model-based controls are. Today, […]
A stylized image of a brick wall with some bricks separated and with locks on them.
AI

When the Token Theft Hides in Plain Sight: Why Agent Containment Stops the Claude Code MCP Attack

June 10, 2026

6

Read Blog
Researchers at Mitiga Labs recently demonstrated a five-step attack that quietly hijacks Claude Code’s Model Context Protocol (MCP) traffic and steals the OAuth bearer tokens that grant access to platforms like Jira, Confluence, and GitHub. The attack needs no privilege escalation, no memory corruption, and no new CVE. It abuses the way an agentic developer […]
3 pointed aqua blue pillars; the center pillar has a Cequence logo.
About Cequence

The Market Arrived. We Were Already Here: Cequence Posts Record Quarter on Surging Agentic AI Security Demand

June 9, 2026

6

Read Blog
There’s a moment in every technology cycle when the market stops asking “what if” and starts asking “how fast.” For agentic AI security, that moment is now. And for Cequence, Q4 FY26 made one thing unmistakably clear: the decade of work we put into building the right platform, at the right depth, is paying off […]
A red line going up and to the right with dollar signs underneath and bots underneath that.
Bot Management

The Success Penalty: Why Bot Defense Pricing Is Breaking

June 4, 2026

8

Read Blog
Your business didn’t grow 40%. Your customers didn’t grow 40%. Your revenue didn’t grow 40%. But your bot traffic did. And if your bot defense contract is priced on total traffic, your bill can grow right along with it. That’s the uncomfortable reality hiding inside a lot of security pricing models. The customer gets attacked […]
Diagram showing the difference between CDN-layer AI bot traffic and API layer attacks in 2026, with residential proxy as primary threat vector
CQ Prime Threat Research

2026 Verizon DBIR: AI Bot Threats vs. API Layer Attacks

June 3, 2026

5

Read Blog
Every year, the Verizon Data Breach Investigations Report gives the security industry a shared set of facts to argue about. This year’s edition is no different, and the AI threat numbers are already getting plenty of attention. AI bot traffic is growing 21% month-over-month. Bot-driven crawlers are reshaping how content gets consumed. And a new, […]
Several spheres representing AI agents chart different paths while one radiates red concentric circles representing behavior.
AI

Agents are the new channel. Behavior is still the only signal that matters.

June 2, 2026

10

Read Blog
Every few years, the enterprise opens a new channel. The web. Mobile. APIs. Each one expanded the surface where customers could transact, and each one brought threats the previous generation of security tools wasn’t designed to handle. Agents are that next channel — and the transition is moving faster than most security teams realize. Traffic […]
A stylized image of a sphere with concentric circles around it representing barriers.
AI

A Reference Architecture for Containing Agents: What Cequence Built and Anthropic Arrived At Independently

June 1, 2026

17

Read Blog
Two searches are running hot in every enterprise security team right now. One is for prompt injection detection. The other is for a gateway that handles agent tool access through delegated identity. Both are reasonable instincts. Both aim at the wrong boundary. In the space of a month, Anthropic spelled out the same lesson twice. […]
Cequence team members gathered together at the company AI Gateway hackathon during Sales Kick-off
AI

What Happens When Your Entire Company Learns AI Together? We Found Out.

May 28, 2026

5

Read Blog
Creative Ideas Born from Shared Challenges At Cequence, we did something a little unusual at our Sales Kick-off this year. We ran a company-wide AI hackathon — and the rule was simple: everyone participates, not just engineers. Sales. Marketing. Finance. HR. Operations. Support. Every discipline, every function. Engineering was there too, but only to help […]
A checkmark in a box wiht multiple boxes behind it representing Cequence Zero Trust Agentic AI
AI

Agentic AI Does Not Mean Abandoning Zero Trust

May 26, 2026

6

Read Blog
For the last several years, security leaders have wrestled with a difficult question: how do you embrace AI-driven progress without creating massive new security risks? As one of the founding fathers of zero trust, Dr. Chase Cunningham delivers an important answer that he shares in his new research paper, Agentic Zero Trust: Extending the Zero […]
A image of the cover of the Verizon 2026 DBIR for report contributors with the words “Contributor – Verizon 2026 Data Breach Investigations Report” on a red background.
CQ Prime Threat Research

What the Verizon 2026 DBIR says about bots, APIs, and the AI threat surge

May 19, 2026

5

Read Blog
The Verizon 2026 Data Breach Investigations Report (DBIR) lands with some numbers that are hard to sit with if you’re in the business of defending web applications, APIs, and data. AI-driven bot traffic is growing at a pace most organizations aren’t equipped to handle. Web application attacks are often successful, for the same reasons they’ve […]
A stylized image of an agent with some tasks succeeding and some blocked.
AI

Least Privilege Access for AI Agents: The Control You’re Missing

May 12, 2026

6

Read Blog
What is least privilege access for AI agents? Least privilege access for AI agents means restricting each agent’s tool access, API permissions, and data scope to only what its specific task requires, nothing more. It is the same principle security teams apply to human users and service accounts, adapted for systems that are non-deterministic, act […]
Encoded prompt injection: why LLM guardrails are the wrong layer
AI

Encoded Prompt Injection: Why LLM Guardrails Are the Wrong Layer

May 7, 2026

6

Read Blog
A tweet in Morse code drained an AI wallet via Bankrbot. Encoded prompt injection defeats LLM monitoring. The durable fix is at the action layer, where authorization is deterministic and behavior is observable.
Cequence-Blog-TelecomATO
Bot Management

How a Leading Telecom Slashed Account Takeovers by ~75% — Without Changing a Line of App Code

May 6, 2026

7

Read Blog
~75% Reduction in fraudulent account takeovers <4 weeks Time to measurable, sustained impact 0 App code changes required 100s Applications and APIs protected When a major telecommunications provider’s anti-fraud team reached out to their internal Cequence champions with an unsolicited note of thanks, the data behind it told a remarkable story. In just a matter […]
Why enterprises need an MCP gateway, not native connectors
AI

Why Enterprises Need an MCP Gateway, Not Native Connectors

April 30, 2026

6

Read Blog
Anthropic’s case for MCP gateways at AI Engineer validates the architectural path Cequence has been on. Why native connectors don’t scale for enterprises.
A stylized image with multicolored lines representing data going through various squares representing gateways.
AI

LLM Proxies vs. MCP Gateways: What’s the Difference?

April 28, 2026

6

Read Blog
As enterprise adoption of generative AI accelerates, so does the number of new components showing up in architecture diagrams. Among the common are LLM proxies and MCP gateways. They are often grouped together because they both sit between applications and AI systems, and both introduce a level of abstraction that is intended to simplify development […]
CIS MCP Companion Guide v1.0 cover image
AI

CIS MCP Security Guide: How to Govern AI Agent Access in Enterprise Environments

April 23, 2026

8

Read Blog
The risk profile of enterprise AI changes dramatically between pilot and production. It is one thing to experiment in a sandbox; it is another to let AI agents reach into enterprise tools, internal data sources, and operational systems. That is why the newly released Model Context Protocol (MCP) Companion Guide from the Center for Internet Security matters. […]
A stylized image of a person putting their finger on a button with fingerprint and checkmark on it.
Bot Management

Beyond CAPTCHA: Biometric Trust Verification and the Agentic Future

April 21, 2026

9

Read Blog
Key Takeaways CAPTCHA and SMS verification are no longer reliable — ML models solve image CAPTCHAs more accurately than humans, and SMS farms exploit carrier vulnerabilities. Biometric Check uses hardware-bound cryptographic attestation via a device’s Secure Enclave to confirm human presence — no codes, no puzzles, under a second. It’s the first bot verification mechanism […]
A stylized image of an ai-powered bot.
Bot Management

What the Rest of the Industry Isn’t Telling You About AI-Powered Bot Attacks

April 17, 2026

9

Read Blog
I sat in on one of the most packed rooms at RH-ISAC this week. The session on AI-powered bot attacks drew one of the biggest crowds of the summit. The content was solid. Side-by-side log examples, a clear framing of the detection challenge, a reasonable takeaway about smarter client-side controls. Two things have been sitting […]
A stylized image of a vault with four lock icons surrounding it representing prompt injection
AI

Even the Best AI Agents Leak Secrets. Prompt Injection Is Why.

April 16, 2026

7

Read Blog
Researchers hijacked Claude, Gemini, and Copilot AI agents to steal API keys via prompt injection. The technique is unsolved across the industry. Here is why credential indirection at the gateway layer is the architectural fix.
Why Anthropic says model security is not enough for AI agents
AI

Why Anthropic Says Model Security Isn’t Enough for AI Agents

April 13, 2026

7

Read Blog
Anthropic says AI agent security requires defenses beyond the model. See how Cequence AI Gateway and Agent Personas close the gap.
Mythos will not fix this: why behavioral security still matters
AI

Mythos Won’t Fix This: Why Behavioral Security Still Matters

April 13, 2026

7

Read Blog
Anthropic Mythos finds code vulnerabilities, but behavioral security stops the abuse that fully patched APIs still face from bad actors and rogue agents.
A stylized graphic of API traffic with bots identified in the traffic.
Bot Management

API Bot Management: Purpose-Built Defense for a Purpose-Built Threat

April 7, 2026

5

Read Blog
The most effective bot attacks don’t look like attacks. They arrive as ordinary traffic; seemingly normal requests with valid headers and at reasonable volumes. They often operate undetected until the damage is already done. By the time security teams notice, inventory has been hoarded, data has been scraped, accounts have been compromised, or revenue has […]
A stylized lock closed around traffic between agents and applications.
AI

What is AI Gateway Security? Addressing New AI Security Risks

April 2, 2026

6

Read Blog
The conversation around AI security often starts in the wrong place. Most teams focus on the model; how it behaves, what it generates, and whether it can be manipulated. But in real-world deployments, the model is only part of the story. What really matters is what AI agents are actually allowed to do once it’s […]
A stylized image of an AI agent able to access some tools but not others.
AI

Introducing Agent Personas – The Missing Agentic Security Layer

March 12, 2026

12

Read Blog
Announcing Agent Personas in the Cequence AI Gateway, which allow organizations and employees to manage AI agent privileges at a granular level. It provides the ability to control, monitor, and govern what an AI agent is allowed to do within a system, including data access, tool calls, system actions, and delegated authority, the specific LLM […]
Image showing Cequence partnering with TM Forum
Bot Management

Securing Telecom’s Agentic Future

March 3, 2026

5

Read Blog
Why Cequence Is Co-Chairing TM Forum’s AI-Native Blueprint Initiative This past Sunday, at Mobile World Congress in Barcelona, TM Forum officially named Cequence Security as Co-Chair of its AI-Native Blueprint Initiative, specifically leading the Agentic Interaction Security workstream. For those of us who spend our days thinking about application and data security, and the emerging […]
A stylized image of two airline seats spinning to represent airline seat spinning fraud
Bot Management

Airline Seat Spinning: An Illustration of Sophisticated Fraud

February 24, 2026

6

Read Blog
Undermining Revenue, Trust, and Operational Integrity For airline CIOs, CISOs, and revenue platform leaders, malicious bots are no longer just a nuisance. They are a direct assault on revenue integrity and customer trust. One of the most damaging and least understood manifestations of this threat is a practice known as seat spinning. Seat spinning is […]
Illustration of security guardrails for AI enablement.
AI

Security Guardrails: The Foundation of Agentic AI Governance

February 19, 2026

5

Read Blog
Key Takeaways: Your enterprise needs strong guardrails for AI agents. Unlike GenAI, agentic systems access data, modify records, and trigger transactions, which makes bolted-on security a recipe for failure. AI guardrails are the foundation, not a feature. Identity scoping, behavioral monitoring, and runtime enforcement need to be embedded at the architecture layer, not added after […]
A conceptual illustration of the missing pieces when lacking a strong security partner.
AI

What the Right Agentic AI Gateway Offers and What Other Solutions Miss

February 12, 2026

6

Read Blog
Agentic AI projects are rapidly moving from experimentation to being deployed in enterprises everywhere. Autonomous agents that can reason, plan, and act promise significant revenue growth and productivity gains. At the same time, they expose organizations to new operational and security risks that many teams are not prepared to manage. The data is sobering. Recent […]
A stylized image of a shopping bag on the screen of a laptop.
AI

Are You Ready for AI Shopping Bots? The Case for Verifiable AI Agent Identification

February 10, 2026

11

Read Blog
Key Takeaways: AI shopping agents are on the rise. A growing percentage of AI agents can autonomously browse, compare, and buy on behalf of users. Verifiable identity for bots is essential. Sites need to verify agent identities with tools like Web Bot Auth; a way for bots to send verifiable, cryptographically signed HTTP requests. Not […]
A photo of Cequence’s Sydney Weber next to the CRN Channel Chiefs logo on a teal background.
About Cequence

Cequence’s Channel-First Approach Recognized with CRN Channel Chiefs Honor

February 2, 2026

3

Read Blog
At Cequence, our go-to-market strategy is built around strong partner relationships backed by clear structure and consistent execution, with the ultimate goal of creating better outcomes for customers and sustainable growth for everyone involved. That philosophy was recently reflected externally when Sydney Weber, Director of Channel Sales at Cequence, was named to CRN’s 2026 Channel […]
A stylized lock on a dark teal background.
AI

Security in the Age of Autonomous AI

January 22, 2026

5

Read Blog
AI is no longer an experimental technology tucked away with research teams. It’s embedded in production systems, customer-facing applications, internal tools, and developer workflows. As organizations race to adopt AI for efficiency, insight, and automation, security teams are discovering a hard truth: AI changes the threat model just as much as it changes the business. […]
A stylized image of a swallow (bird) breaking free from a cage.
AI

What Enterprise Leaders Are Really Saying About Agentic AI Adoption

January 13, 2026

5

Read Blog
What We’ve Learned by Talking to Prospects and Customers Agentic AI has moved from hype to prototype to production remarkably quickly. Across industries, organizations are actively piloting AI agents to automate workflows, make better use of internal data, and interact with a variety of systems. The intent to adopt is clear. What’s less clear, at […]
Stylized version of the OpenAPI logo on a background of smaller OpenAPI logos.
API Security

What Is OpenAPI and How Does It Improve API Security?

December 16, 2025

8

Read Blog
APIs can be vulnerable without proper, up-to-date documentation. The OpenAPI specification framework is one of several tools organizations can adopt to improve API security through higher quality, more consistent coding. At the heart of API specification frameworks is an emphasis on documentation. Documenting topics such as how the API should function, what field inputs should […]
The Cequence AI Gateway logo in a box surrounded by lines representing connections to applications on a dark teal background.
Product News

New AI Gateway Features for Enterprise Readiness

December 12, 2025

3

Read Blog
December 2025 AI Gateway Product Update Since the announcement of the Cequence AI Gateway in July 2025, we’ve seen dramatic interest and rapid adoption as organizations endeavor to move their agentic AI projects from prototypes to production in a rapid, secure manner. Two of the foundational principles behind the development of the AI Gateway were […]
A stylized image with the words “500 Technology Fast 500 2025 NORTH AMERICA 30 YEARS OF INNOVATION Deloitte.” surrounded by wavy lines.
About Cequence

Cequence Momentum: Growth, Innovation, and the Future of Secure AI

December 4, 2025

4

Read Blog
Cequence’s trajectory over the past few years tells a clear story: steady growth driven by innovation and a laser focus on solving customers’ real security challenges. That progress earned yet another recognition this November when Deloitte named Cequence one of North America’s fastest-growing technology companies, ranking #128 on the 2025 Deloitte Technology Fast 500™. We […]
A stylized image of bots attacking APIs
API Security

Your Bot Problem Might Actually Be an API Problem

November 18, 2025

6

Read Blog
Why Bot Attacks Are No Longer Just a Web Problem Organizations have assumed bot threats lived mostly at the web layer as malicious scripts scraping content and hammering websites, mobile apps, and login pages. That’s still true, but no longer encompasses the entire problem. Today’s automated attacks increasingly exploit APIs, the very connectors that power […]
The OWASP logo on a teal background between two pieces of broken pipe, representing owasp api security top 10 Risks Can't Be Blocked, But Can Be Fixed
API Security

OWASP API Top 10 Risks Can’t Be Blocked, But They Can Be Fixed

November 11, 2025

6

Read Blog
A question Cequence frequently hears from security teams just beginning their API security program journey is “how do we block OWASP API Top 10 issues?” – but that’s not the right question. It’s an understandable assumption. After all, security teams are trained to think in terms of detection and blocking – stop the bad traffic, […]
An image of a finger pressed against glass and being analyzed to identify the person.
API Security

Zero Trust API Security: What It Is and Why It Matters

November 4, 2025

7

Read Blog
In the realm of cybersecurity, the Zero Trust model has emerged as a potent strategy to counteract the ever-evolving landscape of threats. The model’s core principle is simple: “Never trust, always verify.” This concept is particularly relevant when applied to API security, where the stakes are high due to the sensitive nature of data being […]
The Cequence logomark, a stylized right angle bracket, against a platinum background.
About Cequence

Setting the Platinum Standard for API Security: Analysts Name Cequence an API Security Leader

October 30, 2025

4

Read Blog
In an industry where trust is measured by independent validation, Cequence has once again emerged as the clear standard-bearer for API security. This year, the company has been recognized as a leader by not one, but two leading analyst firms — Enterprise Management Associates (EMA) and KuppingerCole — each affirming Cequence’s leadership in innovation, maturity, […]
A stylized image of a road blocked by a bot icon.
Bot Management

Digital Experience at Risk: How Bots Are Breaking Customer Journeys

October 21, 2025

5

Read Blog
The Digital Experience Under Threat A good digital experience drives brand loyalty and revenue. Today’s customer journeys span multiple touchpoints including web, mobile, and APIs, and increasingly rely on AI-driven personalization to deliver instant relevance. Every interaction feeds data into algorithms that predict intent and streamline conversion. Unfortunately, attackers and their bot armies have learned […]
Stylized image of a target being struck in the center, depicting API Security Breaches
API Security

The Cost of API Security Breaches – and How to Prevent Them

October 14, 2025

6

Read Blog
API Breach Impact: Enterprise vs. Mid-Market Organizations APIs have become the backbone of modern digital ecosystems and one of the fastest-growing sources of data breaches. As organizations rely more on APIs to connect systems, deliver services, and drive innovation, attackers increasingly exploit vulnerabilities in these interfaces to access sensitive data or disrupt operations. No organization […]
API Threat Mitigation
API Security

What is API Threat Mitigation?

October 9, 2025

3

Read Blog
API threat mitigation protects APIs against advanced threats that, if left alone, can result in fraud, data loss, and business disruption. If left unsecured, attackers can exploit API vulnerabilities, launch bot attack and business logic abuse impacting API security, governance, and compliance. Therefore, API threat mitigation is a critical element to any end-to-end API protection […]
A stylized image of an MCP server being attacked by red lasers.
AI

Protecting Your AI Agents from Untrusted MCP Servers

September 30, 2025

9

Read Blog
Key Takeaways: MCP servers are the new attack surface. Rogue servers, compromised integrations, and prompt injection can silently hijack your AI agents’ workflows. Agents can’t tell they’re being manipulated. A malicious MCP server can embed hidden instructions mid-workflow, exfiltrating data without a single red flag. The fix: a trusted MCP registry. Vet what your agents […]
A stylized image of 3 databases being injected by syringes
Bot Management

Defending Against SQL Injection Attacks

September 23, 2025

5

Read Blog
What Are SQL Injection Attacks? In the evolving landscape of application-layer threats, SQL injection remains one of the most persistent and damaging attacks. Despite being a well-documented issue, SQL injection continues to plague modern web applications, APIs, and backend systems. SQL injection allows an attacker to manipulate the SQL queries an application sends to its […]
An illustration of an eye representing API Security and Bot Management Enabling Agentic AI
AI

API Security and Bot Management Enable Agentic AI

September 18, 2025

6

Read Blog
Not often in the startup world are you able to witness your product line over time consistently fulfill the vision that the company was founded upon. Here at Cequence, we’re doing exactly that. We started a decade ago helping enterprises protect their applications from malicious bots, architecting the original solution to be network based for […]
A stylized pipe representing internet traffic with lots of bad traffic, represented by red lines, going through it.
Bot Management

Preventing DDoS Attacks

September 16, 2025

4

Read Blog
What Are DDoS Attacks? Cybersecurity professionals face many threats, but Distributed Denial-of-Service (DDoS) attacks stand out for their simplicity, destructiveness, and persistence. A DDoS attack uses multiple compromised devices to overwhelm a target system with malicious traffic, rendering services unavailable to legitimate users. Each device sends requests, collectively flooding a server, network, or service to […]
A stylized image of OAuth tokens being scanned and stolen.
Bot Management

The Salesloft Breach: In the AI Era, IP Reputation Monitoring Still Matters for Authentication Tokens

September 11, 2025

6

Read Blog
The August 2025 Salesloft Drift breach impacted over 700 organizations when threat actor UNC6395 used compromised OAuth tokens to systematically exfiltrate data from Salesforce instances. The attackers leveraged legitimate authentication credentials, stolen from the Salesloft AI Chatbot to masquerade as trusted integrations, bypassing traditional security controls entirely. The IP Infrastructure Pattern Analysis of published IOCs […]
Agentic AI Boost
AI

Deploy AI Agents Faster and Safer with Secure MCP Servers

September 4, 2025

8

Read Blog
Cequence is a pioneering leader in the bot management and API security space. Protecting over 10 billion daily API transactions has put us in a position to learn a tremendous amount about the business context – seeing how users, both human and synthetic, interact with applications and APIs. This experience has enabled us to build […]
A stylized image of a malicious bot attacking shoppers and the need for bot management
Bot Management

When Does Comparison Shopping Become a Retail Bot Threat?

August 26, 2025

4

Read Blog
Comparison shopping is a proven and accepted practice within the retail industry. Pre-internet era versions meant shoppers would physically visit the retailers to get their “bottom line” price. Early online comparison shopping meant you could use search to find the desired product and compare vendors from the comfort of your own home, only physically venturing […]
A stylized image of a disconnected power plug representing the AI gap and the need for agentic AI
AI

The Enterprise AI Gap: Why Your Expensive AI Licenses Are Going to Waste

August 18, 2025

6

Read Blog
Enterprise architects face a familiar and frustrating scenario: Your organization has invested heavily in AI licenses—Claude for Teams, ChatGPT Enterprise, Copilot for Business—responding to C-suite and Board directives to “accelerate AI adoption.” Yet months later, usage metrics show these powerful tools sitting idle, with adoption rates hovering in the single digits. The problem isn’t the […]
API Threat Prevention
API Security

API Threat Protection: Part 3 of How to Prevent API Attacks

July 29, 2025

6

Read Blog
This is part three of our three-part API Threat Protection series. In part one, we talked about the modern approach to API discovery, and in part two, detecting API threats. We’ve learned that there’s a need for real-time, automated prevention measures to block API threats, and that’s the final step in the Unified API Protection […]
Cequence AI Gateway - the path to adopting Agentic AI
Product News

Cequence AI Gateway: The Easy, Fast, Safe Path to Adopting Agentic AI

July 22, 2025

6

Read Blog
With the advent of agentic AI and the promise of newfound workforce productivity and customer engagement, it’s no surprise that organizations are rapidly engaging in projects to bring that promise to light. Unfortunately, many of these projects end up consuming massive amounts of development time and resources, producing a result that is more “prototype” than […]
A stylized picture of a lock with the Cequence logo on it surrounded by concentric circles.
Product News

Introducing Cequence Web Application and API Protection – WAAP

July 3, 2025

5

Read Blog
Cequence has added a powerful Web Application Firewall (WAF) and highly-scalable DDoS protection to our Cequence API Security and Bot Management products to offer a best-of-breed cloud WAAP. Increasingly, our customers have asked if we could provide WAF and DDoS capabilities in addition to our API security and bot management offerings for vendor consolidation, cost […]
Chat GPT and API Security
Bot Management

How Can Generative AI Be Used in Cybersecurity?

June 19, 2025

5

Read Blog
The rapid adoption of generative AI (GenAI) such as ChatGPT and Claude got us thinking about how it may or may not impact API security. As more and more people use GenAI to perform complex searches, for “vibe coding,” or even to write blog posts (but not this one!), they’re often doing so in business […]
An illustration of a phone with a stethoscope connected to it representing the need for API Security for healthcare
API Security

API Security in Healthcare: Protecting Health Data from API Attacks

June 12, 2025

6

Read Blog
The healthcare industry deals with a mountain of highly sensitive data, whether it be patient health information, insurance details, or financial information – all of which are valuable to cybercriminals. Bad actors can use this information for everything from identity theft to insurance fraud. Implementing a strong API security program is critical to protect APIs […]
An image of bots in the background with squares with checkmarks on them representing a list of automated bot prevention solutions that Cequence offers
Bot Management

Top 7 Selection Criteria for Automated Bot Prevention Solutions

June 5, 2025

10

Read Blog
What to Look for in a Bot Management Solution: Top 7 Selection Criteria How to Ensure Long-Term Protection Against Today’s Evolving Automated Attacks Today, bots are becoming more than just a security threat. Their contributions to very real lost revenue and customer dissatisfaction are now getting noticed in the boardroom. Many businesses are coming around […]
A clear box with 3D letters “AI” inside, with a ribbon underneath with “API” repeating across the ribbon representing Agentic AI
API Security

Why Agentic AI Demands a Different Approach to API Security

June 3, 2025

6

Read Blog
Key Takeaways: Agentic AI is a different challenge than GenAI. These systems don’t just generate content; they perceive, reason, and act autonomously, which means your API attack surface is much more consequential. Your APIs are now AI attack surfaces. Agents interact with your systems via APIs, making them prime targets for credential stuffing, data scraping, […]
A photo of a woman with a backpack in a denim shirt typing on a smartphone.
API Security

Poshmark Prevents Automated Account Takeover Fraud

May 20, 2025

4

Read Blog
Poshmark increased API security using the Cequence Unified API Protection (UAP) solution to block automated account takeover (ATO) attacks that were overwhelming their online marketplace. Poshmark is a leading social commerce marketplace that enables users to buy and sell new and secondhand styles for women, men, kids, homes, and more. Founded in 2011 in Redwood City, […]
prevent web scraping attacks
Bot Management

How to Prevent Web Scraping Attacks and Block Malicious Bots

May 13, 2025

7

Read Blog
Many of today’s hyper-connected organizations are faced with the challenge of how to detect and prevent web scraping attacks in an efficient and scalable manner. In this blog, we’ll share how a comprehensive approach involving API security and bot management can help mitigate this problem that leverages behavioral fingerprinting to continuously track sophisticated attacks, supported by […]
Image with teal gradient background with the Cequence and Skyfire logo.
Bot Management

AI Agent Monetization Is Here: Turning Bot Traffic Into Trusted Revenue

May 8, 2025

4

Read Blog
AI Agent Monetization Is Here As AI agents take on increasingly complex tasks like shopping, booking, and executing transactions, they’re also becoming major drivers of web traffic. According to Gartner, 70% of organizations will be using AI agents to handle customer interactions by 2025, up from just 20% in 2020. This evolution presents a new […]
A stylized street sign with the classic CAPCHA line quadrants representing alternatives to classic CAPCHA using bot management
Bot Management

Accurate and Effective Bot Management – Without CAPTCHA

May 1, 2025

5

Read Blog
It’s Time to End Unnecessary, Poor User Experiences Does the user experience have to suffer to achieve effective bot management? The answer to this important question is a resounding “no”. Security teams rightfully want to ensure that users are properly authenticated before being authorized to access, enter, or edit sensitive information. Malicious bots must be […]
A screenshot of the cover of the Verizon 2025 Data Breach Investigations Report
API Security

Verizon 2025 DBIR Review

April 23, 2025

5

Read Blog
It’s here, the 18th annual Verizon 2025 Data Breach Investigations Report (DBIR) which contains a comprehensive look at the current state of cybercrime. Cybersecurity professionals around the world will soon be brewing some coffee and preparing to dig into the beautifully-written (and sometimes funny!) report, which weighs in this year at a svelte 117 pages. […]
An image of an API in a square with diagonal lines and a vertical line over the API representing API discovery and security gaps
API Security

Why Comprehensive API Discovery Requires Both Domain-Based and Runtime Techniques

April 15, 2025

5

Read Blog
Why Comprehensive API Discovery Requires Both Domain-Based and Runtime Techniques The API attack surface is growing—and adversaries know it. Moving to the cloud, DevOps, and application modernization all lead to the proliferation of APIs. Resulting shadow APIs, deprecated endpoints, undocumented integrations, and increasing use of AI provide ideal entry points for attackers. Securing APIs starts […]
A stylized image of diagonal lines with asterisks inside going from left to right on the screen representing brute force attacks and credential stuffing
Bot Management

Understanding Brute Force Attacks

April 8, 2025

5

Read Blog
The firehose of security incidents – data breaches, ransomware, and supply chain attacks – often obscures the methods that attackers use to create these incidents. One of the most common is brute force attacks, which are a type of authentication-related attack that leads to account takeovers (ATO) and ultimately theft or fraud. So, what is […]
PCI DSS 4.0 API compliance requirements
API Security

Achieving PCI DSS 4.0.1 Compliance with API Security

April 4, 2025

12

Read Blog
When it comes to financial services, retail, or any other industry that handles credit card information, Application Programming Interfaces (APIs) play a pivotal role in connecting systems, enabling seamless transactions, and facilitating real-time data exchange. For organizations handling payment card information, adherence to the Payment Card Industry Data Security Standard (PCI DSS) 4.0.1 is essential […]
A stylized lock with a checkmark on it, surrounded by concentric circles with an AWS partner logo representing Cequence's AWS security competency achievement
Product News

Cequence Marks Another Milestone with AWS Security Competency Achievement

April 3, 2025

3

Read Blog
As businesses embrace the cloud, their attack surface expands accordingly. Cloud workloads are built on APIs, and Cequence’s expertise in API security and bot management means the company and its products are uniquely positioned to protect those APIs and the workloads that depend on them. AWS Security Competency We’re proud to announce that Cequence has […]
A stylized graphic of a point of sale machine with several credit cards and coins representing PCI DSS 4.0 compliance
CQ Prime Threat Research

PCI DSS 4.0 Compliance Requires a New Approach to API Security

March 27, 2025

4

Read Blog
Retailers, Financial Services, and the API Security Wake-Up Call With the PCI DSS 4.0 compliance deadline fast approaching, Cequence threat researchers have uncovered troubling data: 66.5% of malicious traffic is targeting retailers. And attackers aren’t just after payment data. They’re weaponizing APIs to exploit every stage of the digital buying process. The conclusions in this […]
A stylized image of a phone with a retail store-type awning with a lock in front of it and bots below it representing effective Bot Management and E-Commerce Security
Bot Management

Effective Bot Management and E-Commerce Security: Protecting Retailers from Online Fraud

March 20, 2025

5

Read Blog
E-commerce thrives on real customer engagement, yet malicious bots regularly threaten to disrupt this digital ecosystem. To combat these ever-evolving attacks, retail businesses must implement modern bot management. Bot management refers to the deployment of security measures to detect, mitigate, and prevent malicious bot activity. Without robust bot defense, businesses suffer revenue loss, compromised security, […]
An image with Bots on it representing Better Bot Management
Bot Management

Automated Antagonists: The Quest for Better Bot Management

March 4, 2025

5

Read Blog
A New Approach to Bot Management Bots are a part of life on the internet for today’s businesses. In some ways, the internet has made it easier for criminals to steal information or commit fraud – bots are used to automate attacks that would typically be performed manually in the real world. For example, while […]
A bot background with gradient hearts circling the Cequence logo representing a large credential stuffing bot attack that was stopped
Bot Management

Cequence Stops a Massive Credential Stuffing Bot Attack

February 25, 2025

4

Read Blog
Over the last few years, Cequence has seen a trend of larger and increasingly distributed attacks. In 2024, Cequence identified and blocked one of the largest application business logic abuse attacks on record. These massive attacks often coincide with common holidays such as Black Friday and the Christmas shopping season. The latest large-scale attack Cequence […]
A stylized pair of sim cards with a circular arrow between them on a dark blue and light blue background, bisected diagonally representing SIM swapping
API Security

SIM Swapping and How to Prevent it

January 9, 2025

5

Read Blog
SIM swapping attacks have been a threat for years, but gained mainstream attention in 2019 when hackers took over the cellular account of Twitter CEO Jack Dorsey. Because we use our cell phone number as an authentication method for a variety of online services and applications, this type of attack is far more insidious than […]
Crystal ball with hands over it representing 2025 API Security Predictions
API Security

2025 Predictions: What Lies Ahead for API Security and Bot Management

December 19, 2024

5

Read Blog
Ah, it’s that time of year again. As the clock ticks closer to 2025, companies everywhere are dusting off their crystal balls to forecast what the new year might bring. Yes, we know — another set of predictions in a sea of predictions. But here’s the thing: these exercises aren’t just for show. They’re a […]
E-commerce cybercrime cost business in the holiday season.
Bot Management

How Much Will Cybercrime Cost Your E-Commerce Business This Season?

December 12, 2024

4

Read Blog
The 2024 holiday season has seen explosive growth in e-commerce, with transaction volumes more than doubling from 5.1 billion in 2023 to 10.4 billion this year. While this highlights the strength of online shopping, it also points to a parallel increase in malicious activity. Reports indicate that 34.62% of transactions in 2024 were flagged as […]
SMS pumping fraud stylized graphic of a cellphone with text bubbles.
Bot Management

Decoding SMS Pumping Fraud: Protecting Your Communications

December 10, 2024

8

Read Blog
In the digital-first world, SMS messaging remains a common security mechanism for second factor and other verification communication. Whether verifying accounts through one-time passwords (OTPs), notifying customers about transactions, or sharing promotions, organizations across industries often rely on SMS as a reliable channel. Yet, this trust has been exploited by cybercriminals through SMS pumping fraud, […]
Cequence Security recognized as one of the fastest-growing companies in North America in the 2024 Deloitte Technology Fast 500™
About Cequence

Cequence Security Makes the 2024 Deloitte Technology Fast 500™

December 3, 2024

4

Read Blog
Cequence Security was recently named to the 2024 Deloitte Technology Fast 500™, a prestigious ranking of the fastest-growing companies in North America. This recognition highlights the growth and innovation we’ve demonstrated over the past three years, positioning Cequence alongside some of the most impactful and forward-thinking companies in the tech industry. With a 397% growth […]
An open banking stylized graphic depicting a laptop, a phone, a building, and 2 credit cards.
API Security

Protecting Open Banking APIs: Best Practices

November 19, 2024

7

Read Blog
Empowering Consumers While Protecting APIs The U.S. Consumer Financial Protection Bureau (CFPB) recently mandated digital interfaces (APIs) to promote secure, authorized data-sharing between financial institutions and third-party applications. These APIs empower consumers, offering more control over their financial data across banking, budgeting, and investment platforms. However, this also introduces heightened privacy and security concerns, making […]
A stylized image of credit cards with their details blurred or starred out. Depicting Sensitive Data Masking in API Security
API Security

Sensitive Data Masking in API Security

November 14, 2024

5

Read Blog
Digital transformation and the proliferation of APIs has made it easier to share data of all kinds internally and externally, including sensitive data. As more and more applications communicate with each other, organizations need a reliable way to protect sensitive data between environments of varying security and trust levels without disrupting business processes. Whether data […]
A stylized image of credit cards leaking their credit card numbers representing carding attacks
Bot Management

Preventing Carding Attacks Through Effective Bot Management

November 12, 2024

4

Read Blog
Credit card fraud is an ongoing challenge for companies across industries, particularly in today’s digital landscape where automated bot attacks are becoming increasingly prevalent. Cequence recently assisted a prominent customer in mitigating a sophisticated attack that involved testing stolen credit cards. Attackers used bots to perform small transactions to validate stolen credit cards, aiming to […]
API Security: Key Insights from Development to Runtime
API Security

Unpacking API Security from Development to Runtime: Key Insights for Cybersecurity Pros

November 7, 2024

5

Read Blog
In today’s fast-paced digital ecosystem, APIs are the lifeblood connecting an ever-growing universe of applications and systems, driving efficiency and agility for modern organizations. But as APIs continue to proliferate, they introduce new risks that cybersecurity teams must navigate with precision and purpose. The Enterprise Strategy Group (ESG) has released a new report, “API Security […]
API Security - stylized picture of a ballot box with a ballot and a large checkmark being dropped into it representing API security in the election season
CQ Prime Threat Research

Leading the Way in API Security: Which U.S. States Are Setting the Standard?

October 31, 2024

5

Read Blog
With just days to go before the U.S. election, securing our digital landscape is more critical than ever. Our latest infographic, Vote for API Security: Which States Are Leading the Charge?, provides an in-depth analysis of state-by-state API infrastructures, highlighting both strengths and vulnerabilities. Cequence analyzed the public-facing attack surface of each state in the […]
AWS Retail Competency - A stylized row of shopping baskets with the AWS Partner logo representing AWS retail competency status
Product News

Cequence Achieves Prestigious AWS Retail Competency Status

October 31, 2024

3

Read Blog
Today’s businesses are increasingly cloud-forward and becoming more agile than ever, and the retail vertical in particular has embraced this digital transformation. Amazon Web Services (AWS) and Cequence have partnered to offer a unique set of solutions ideally suited for retailers looking to ensure application and API security. The integrated solutions combine the world’s most […]

Get an Attacker’s View
into Your Organization


Schedule A Demo