2 Sources
[1]
Virtual patching closes the AI patch window gap
Virtual patching closes the gap as AI erases the patch window Patch Tuesday used to buy defenders a short head start. Now the exploit often lands before the patch does, since automated scanners can weaponize a newly disclosed vulnerability within hours. That inversion is pushing security teams toward virtual patching: shielding an application from a known flaw at the network layer while the real fix is tested and rolled out. John Maddison (pictured), chief marketing officer and head of technology alliances at F5 Inc., has spent two years at the application delivery and security vendor, which turns 30 this year. F5's customers are increasingly demanding that kind of protection as the gap between vulnerability disclosure and exploitation collapses, Maddison noted. "What you need now is AI-powered security that can look at the traffic, where it's going, what it's trying to get to, and produce protection in real time to stop things like zero days," Maddison said. "All the protections that sit in what we call CDNs or WAFs are going to be AI-powered. They have to be going forward." Maddison spoke with theCUBE's Dave Vellante and Rebecca Knight at Fal.Con, during an exclusive broadcast on theCUBE, SiliconANGLE Media's livestreaming studio. They discussed why virtual patching is replacing signature-based defenses and how F5's partnership with CrowdStrike treats network appliances as endpoints. (* Disclosure below.) Virtual patching fills the gap CrowdStrike leaves at the network layer F5 and CrowdStrike embed the Falcon sensor directly onto F5's BIG-IP appliances, the hardware that sits at the network perimeter, so CrowdStrike can treat that traffic the same way it treats a laptop or cloud workload. More than 200 customers were already running the integration before the companies formalized it, with performance overhead measured at just 1% to 2%. "We measured it at 1 to 2%, and they're perfectly willing to deal with that for the security that gets added to it," Maddison said. "That was always the trade-off between security and networking, high performance versus checking everything that comes through." The urgency is measurable. CrowdStrike's own threat research found AI-enabled adversary activity rose 89% year over year, with average breakout time down to 29 minutes and the fastest recorded intrusion at 27 seconds. Maddison said F5 is applying the same approach to a newer problem: guardrails for AI gateways, including a partnership announced this week with Salesforce Inc.'s MuleSoft. "It's more around what you do with the information, how you remediate, versus the information itself," Maddison said. "Because everyone has the information already." Here's the complete video interview, part of SiliconANGLE's and theCUBE's coverage of the Fal.Con event: ( * Disclosure: TheCUBE is a paid media partner for the Fal.Con event. Neither CrowdStrike, the sponsor of theCUBE's event coverage, nor other sponsors have editorial control over content on theCUBE or SiliconANGLE.)
[2]
F5 accelerates virtual patching to manage emerging cyber risks with AI-powered WAF and runtime security
Frontier AI turns vulnerabilities into exploits in hours; F5 enables security teams to maintain availability, governance, and operational stability by blocking threats in minutes F5 today announced innovations to block frontier AI-driven threats in the data path and enable faster virtual patching, giving security leaders time to make intelligent risk-based decisions rather than reactive operational compromises. With new features such as anomaly detection and agentic threat intelligence, F5's AI-powered web application firewall (WAF) is uniquely capable in delivering real-time protections because of its strategic position in customers' infrastructure. Enhancements to F5 WAF for Distributed Cloud and virtual patching provide the precision needed to confidently block active exploits at the request level. "Frontier AI has collapsed the time between vulnerability discovery and active exploitation," said Kunal Anand, Chief Product Officer at F5. "The old model of waiting for code to be rewritten, tested, and redeployed cannot keep pace. F5 puts protection directly into the data path, where we can identify and block exploits in minutes. Virtual patching gives organizations something increasingly scarce in cybersecurity: time. Time to understand the risk, protect the business, and fix the underlying vulnerability without forcing teams into a permanent state of crisis." F5 blocks exploits with runtime security, enabling customers to quickly deploy virtual patches. Introduced earlier this year, F5's AI-powered WAF has already seen strong customer adoption. In internal F5 testing, the solution delivered 98% threat detection efficacy while reducing false positives to 1%, extending the F5 Application Delivery and Security Platform (ADSP) and giving teams confidence to convert scanner findings into enforced protection in minutes rather than weeks. F5 has enhanced its capabilities, adding anomaly detection and agentic threat intelligence to a WAF solution that evaluates requests inline using real-time machine learning classification and a neural network risk engine to assign a risk score to each request as it arrives. Scoring risk dynamically, rather than matching known signatures, allows the WAF to help defend against zero-day attempts, injection attacks, and polymorphic exploit chains that change shape on every attempt. In tailoring infrastructures for a post-Mythos world, F5 helps customers evolve their AI cybersecurity capabilities: Continually analyze traffic for attack signals Built directly into F5 WAF for Distributed Cloud, innovative anomaly detection is an intelligent, self-learning capability that continuously analyzes each application's unique traffic patterns, establishing traffic norms and flagging meaningful deviations that could signal a pending attack. It builds per-application statistical baselines and, in real time, scores incoming requests against baselines to identify attacks and false positives. Anomaly detection provides security teams with more accurate protection for their apps without adding complexity. Prioritize potential exploits with agentic threat intelligence Security teams do not lack alerts. They lack context. New agentic threat intelligence capabilities, built on technology from the acquisition of Fletch, combine external intelligence on emerging and actively exploited threats with what F5 sees reaching customer applications. Teams get one view of which threats are real, which are relevant to their environment, and what to do about each one, with recommended mitigations that can be applied immediately as virtual patches. Enforce virtual patches in minutes Protection cannot wait for a code release. F5 also delivers automated virtual patching with F5 Distributed Cloud Web App Scanning (WAS). The solution identifies exposed vulnerabilities, unprotected APIs, and business logic flaws to trigger targeted virtual patches at runtime. For hybrid environments, these timely virtual patching capabilities also extend to F5 WAF for BIG-IP. Customers can apply existing signatures or write custom rules scoped to a specific CVE, attack path, method, header, or parameter across environments. Balance business risk with emerging threats False positives are the reason most WAFs sit in passive monitoring mode. F5 WAF for Distributed Cloud, through AI-powered risk-based scoring, reduces false positives to 1%, giving SecOps the confidence to start blocking risky traffic sooner without affecting application availability. Virtual patching using F5 WAF for Distributed Cloud then acts as a safety valve, holding protection in place while developers build, test, and release a permanent fix inside standard change controls. Extend remediation to the F5 estate While virtual patching holds the line in the request path, F5 Insight for ADSP accelerates patching of the underlying infrastructure. F5 Insight gives operations teams supported update and patching workflows across F5 hardware and software environments with readiness checks, taking advantage of F5's updated hardened release cadence. Together, these capabilities mitigate exposure in minutes and remediate the fleet on a preferred schedule. New AI-powered WAF capabilities are available now on Distributed Cloud as part of the F5 ADSP. Virtual patching capabilities, along with the integration between F5 Distributed Cloud WAS and F5 WAF for BIG-IP, are also available today. Agentic threat intelligence and anomaly detection are rolling out to F5 WAF for Distributed Cloud customers, with broader availability continuing over the coming months.
Share
Copy Link
F5 unveiled AI-powered security innovations including virtual patching and an advanced web application firewall achieving 98% threat detection efficacy with just 1% false positives. The solution blocks zero-day threats in minutes as frontier AI collapses exploit windows to hours, partnering with CrowdStrike to extend runtime security across network infrastructure.
F5 announced major innovations in AI-powered security and virtual patching designed to counter a fundamental shift in cybersecurity: automated scanners now weaponize newly disclosed vulnerabilities within hours, often before patches can be deployed
2
. The company's AI-powered web application firewall achieved 98% threat detection efficacy while reducing false positives to just 1% in internal testing, giving security teams the confidence to convert scanner findings into enforced protection in minutes rather than weeks2
. This development addresses a critical gap as CrowdStrike's threat research found AI-enabled adversary activity rose 89% year over year, with average breakout time down to 29 minutes and the fastest recorded intrusion at just 27 seconds1
.The urgency behind virtual patching stems from frontier AI collapsing the time between vulnerability disclosure and active exploitation. Kunal Anand, Chief Product Officer at F5, explained that the old model of waiting for code to be rewritten, tested, and redeployed cannot keep pace with AI-driven cyber threats
2
. F5's solution puts protection directly into the data path, identifying and blocking exploits in minutes by shielding applications from known flaws at the network layer while permanent fixes are tested and rolled out1
. The AI-powered web application firewall evaluates requests inline using real-time machine learning classification and a neural network risk engine to assign a risk score to each request as it arrives, allowing defense against zero-day attempts, injection attacks, and polymorphic exploit chains that change shape on every attempt2
.F5 and CrowdStrike embedded the Falcon sensor directly onto F5's BIG-IP appliances, treating network traffic the same way CrowdStrike treats laptops or cloud workloads. More than 200 customers were already running the integration before the companies formalized it, with performance overhead measured at just 1% to 2%
1
. John Maddison, chief marketing officer at F5, noted that customers are willing to accept this minimal overhead for the security gains, marking a shift from the traditional trade-off between high performance and comprehensive traffic inspection1
. This partnership positions network appliances as endpoints within the broader cybersecurity ecosystem, extending runtime security capabilities across hybrid environments.
Source: SiliconANGLE
Related Stories
F5 enhanced its WAF for Distributed Cloud with anomaly detection, an intelligent, self-learning capability that continuously analyzes each application's unique traffic patterns, establishing norms and flagging meaningful deviations that could signal pending attacks
2
. The system builds per-application statistical baselines and scores incoming requests in real time against those baselines to identify attacks while minimizing false positives. Additionally, new agentic threat intelligence capabilities, built on technology from F5's acquisition of Fletch, combine external intelligence on emerging and actively exploited threats with what F5 observes reaching customer applications, providing security teams with context on which threats are real, relevant to their environment, and actionable2
.Beyond traditional application security, F5 is applying AI-powered security to newer challenges including guardrails for AI gateways, with a partnership announced with Salesforce MuleSoft
1
. Maddison emphasized that all protections sitting in CDNs or WAFs will need to be AI-powered going forward, capable of analyzing traffic patterns, destinations, and intent to produce real-time protection against threats1
. The focus shifts from simply collecting threat information to intelligent remediation, as machine learning enables dynamic risk scoring rather than relying on known signatures. Virtual patching gives organizations something increasingly scarce in cybersecurity: time to understand risk, protect the business, and fix underlying vulnerabilities without forcing teams into a permanent state of crisis2
.Summarized by
Navi
[1]
17 Jul 2025•Technology

12 Mar 2026•Technology

27 Feb 2025•Technology
