When Home Devices Become Attack Infrastructure
Application teams cannot clean compromised televisions, routers, or household devices. They can stop treating the residential address as proof and control what the relayed request is allowed to do.
Tag
Related Peakhour notes, analysis, and field guidance.
Application teams cannot clean compromised televisions, routers, or household devices. They can stop treating the residential address as proof and control what the relayed request is allowed to do.
Run F5 BIG-IP Advanced WAF in Transparent mode, review staged matches and learning suggestions, and limit each exception to the URL, parameter, cookie or content profile that needs it.
Tune Cloud Armor preconfigured WAF rules with preview traffic, versioned signatures, sensitivity levels, field exclusions and policy priority.
Trace a Cloudflare OWASP anomaly-score block to the rules that raised the score, then choose the right override or exception.
Start Azure Application Gateway WAF in Detection mode, find false positives in Log Analytics, narrow each exclusion and move into Prevention mode.
Use Count overrides, managed-rule labels and rule priority to fix AWS WAF false positives while keeping the rest of the managed rule group in force.
Run Coraza and OWASP CRS on Caddy in DetectionOnly, read the audit log and limit each exclusion to the field and route that need it.
A practical process for running a CRS-based or managed WAF in detection mode, finding repeatable false positives and writing narrow exceptions that survive real application traffic.
WAFs are neither useless nor a security force field. Here is what they are good at, where they fail, and when putting one in front of an application makes sense.
A web application firewall will not fix insecure code. It can still give applications a valuable layer of protection when bugs, bots and attacks reach the front door.
Ten good reasons not to trust a web application firewall—and why most of them are arguments for using one properly, not going without one.
Analysis of attempts to exploit a recent Share Point zero day vulnerability reveal network fingerprinting and classification is a robust defense.
AI agents with reasoning capabilities like DeepSeek are revolutionizing exploit development, marking the end of traditional security approaches based on static rules and patterns.
How Peakhour's contextual security aligns with Visa's data-driven risk management approach in the 2025-2028 Security Roadmap.
An analysis of Visa's Security Roadmap 2025-2028 and how Peakhour's solutions help Australian businesses meet these security objectives.
Anti-detect browsers represent one of the most sophisticated threats facing modern web applications and APIs. Learn how these tools work, why they pose a significant threat to application security, and how modern security platforms can detect and mitigate their use.
Comprehensive analysis of AI-powered cyber threats and how modern application security platforms defend against machine learning-driven attacks. Learn advanced defence strategies for the AI cybersecurity arms race.
Comprehensive guide to enterprise bot management for modern application security platforms. Learn how to protect applications and APIs from sophisticated bot threats including anti-detect browsers, credential stuffing, and automated attacks targeting DevOps environments.
Comprehensive analysis of credential stuffing threats against Australian financial institutions and how application security platforms help meet CPS 234 disclosure requirements whilst preventing account takeover attacks.
Explore strategies to enhance web application security without compromising user experience, focusing on contextual security and adaptive authentication measures.
An analysis of Peakhour's role in addressing key cloud security categories identified in recent industry analysis, demonstrating its comprehensive approach to modern cloud security challenges.
How breached credential checks and risk signals help detect credential stuffing without adding unnecessary login friction.
Comprehensive guide to HTTP security headers for protecting web applications from client-side attacks. Learn essential browser security configurations for modern application security platforms and DevSecOps workflows.
Understand CVSS by examining the Atlassian CVE-2023-22515 and CVE-2023-22518.
An in-depth exploration of EPSS, its data-driven approach to assessing cybersecurity threats, and how it complements CVSS.
ModSecurity's end-of-life marks a pivotal moment in application security evolution. Discover how modern Application Security Platforms are advancing beyond traditional WAF approaches to provide comprehensive protection for web applications and APIs at the edge.
Comprehensive guide to APRA cybersecurity requirements for Australian financial institutions. Learn how application security platforms help meet CPS 234 compliance and Information Security Manual guidelines for protecting financial services infrastructure.
How OpenBullet packages browser and HTTP automation for credential attacks, and which signals defenders can use without treating any one fingerprint as proof.
Comprehensive analysis of security challenges in headless commerce and Single Page Applications. Learn how to protect modern e-commerce APIs and microservices architectures from scraping, fraud, and automated attacks.
Analysis of the Microsoft 365 DDoS attack by Storm-1359 reveals critical lessons for enterprise application security platforms. Learn advanced Layer 7 DDoS protection strategies and rate limiting techniques for modern applications.
Deep dive into Robust Random Cut Forest (RRCF) implementation for real-time anomaly detection in Application Security Platforms. Learn how advanced machine learning algorithms enhance threat detection and automated response capabilities.
Peakhour clients are protected against CVF-2022-26134 Atlassian Confluence RCE
Comprehensive guide to intelligent rate limiting for modern application security platforms. Learn how sophisticated rate limiting protects APIs and web applications from abuse, DDoS attacks, and automated threats whilst maintaining optimal user experience.
How can rate limiting protect your web application and the key items to consider when enabling.
A practical primer for finding where website requests lose time, from cache state and origin work to browser rendering.
How to speed up WordPress by separating public cacheable pages from private, expensive, and abused request paths.
© PEAKHOUR.IO PTY LTD 2026 ABN 76 619 930 826 All rights reserved.