F5 Launches AI-Powered Security & Virtual Patching to Block Zero-Day Threats in Minutes

2 Sources

Share

F5 unveiled AI-powered security innovations including virtual patching and an advanced web application firewall achieving 98% threat detection efficacy with just 1% false positives. The solution blocks zero-day threats in minutes as frontier AI collapses exploit windows to hours, partnering with CrowdStrike to extend runtime security across network infrastructure.

F5 Accelerates Virtual Patching as AI Shrinks Exploit Windows

F5 announced major innovations in AI-powered security and virtual patching designed to counter a fundamental shift in cybersecurity: automated scanners now weaponize newly disclosed vulnerabilities within hours, often before patches can be deployed

2

. The company's AI-powered web application firewall achieved 98% threat detection efficacy while reducing false positives to just 1% in internal testing, giving security teams the confidence to convert scanner findings into enforced protection in minutes rather than weeks

2

. This development addresses a critical gap as CrowdStrike's threat research found AI-enabled adversary activity rose 89% year over year, with average breakout time down to 29 minutes and the fastest recorded intrusion at just 27 seconds

1

.

Runtime Security Delivers Real-Time Protection Against Zero-Day Threats

The urgency behind virtual patching stems from frontier AI collapsing the time between vulnerability disclosure and active exploitation. Kunal Anand, Chief Product Officer at F5, explained that the old model of waiting for code to be rewritten, tested, and redeployed cannot keep pace with AI-driven cyber threats

2

. F5's solution puts protection directly into the data path, identifying and blocking exploits in minutes by shielding applications from known flaws at the network layer while permanent fixes are tested and rolled out

1

. The AI-powered web application firewall evaluates requests inline using real-time machine learning classification and a neural network risk engine to assign a risk score to each request as it arrives, allowing defense against zero-day attempts, injection attacks, and polymorphic exploit chains that change shape on every attempt

2

.

CrowdStrike Partnership Extends Protection to Network Infrastructure

F5 and CrowdStrike embedded the Falcon sensor directly onto F5's BIG-IP appliances, treating network traffic the same way CrowdStrike treats laptops or cloud workloads. More than 200 customers were already running the integration before the companies formalized it, with performance overhead measured at just 1% to 2%

1

. John Maddison, chief marketing officer at F5, noted that customers are willing to accept this minimal overhead for the security gains, marking a shift from the traditional trade-off between high performance and comprehensive traffic inspection

1

. This partnership positions network appliances as endpoints within the broader cybersecurity ecosystem, extending runtime security capabilities across hybrid environments.

Source: SiliconANGLE

Source: SiliconANGLE

Anomaly Detection and Agentic Threat Intelligence Enhance WAF Capabilities

F5 enhanced its WAF for Distributed Cloud with anomaly detection, an intelligent, self-learning capability that continuously analyzes each application's unique traffic patterns, establishing norms and flagging meaningful deviations that could signal pending attacks

2

. The system builds per-application statistical baselines and scores incoming requests in real time against those baselines to identify attacks while minimizing false positives. Additionally, new agentic threat intelligence capabilities, built on technology from F5's acquisition of Fletch, combine external intelligence on emerging and actively exploited threats with what F5 observes reaching customer applications, providing security teams with context on which threats are real, relevant to their environment, and actionable

2

.

Broader AI Security Strategy Includes Gateway Guardrails

Beyond traditional application security, F5 is applying AI-powered security to newer challenges including guardrails for AI gateways, with a partnership announced with Salesforce MuleSoft

1

. Maddison emphasized that all protections sitting in CDNs or WAFs will need to be AI-powered going forward, capable of analyzing traffic patterns, destinations, and intent to produce real-time protection against threats

1

. The focus shifts from simply collecting threat information to intelligent remediation, as machine learning enables dynamic risk scoring rather than relying on known signatures. Virtual patching gives organizations something increasingly scarce in cybersecurity: time to understand risk, protect the business, and fix underlying vulnerabilities without forcing teams into a permanent state of crisis

2

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved