<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0"><channel><title>Peakhour.IO - Security</title><link>https://www.peakhour.io/</link><description></description><lastBuildDate>Mon, 03 Aug 2026 10:30:00 +1000</lastBuildDate><item><title>A Proxy Takedown Is Not a Security Control</title><link>https://www.peakhour.io/blog/proxy-takedown-is-not-security-control/</link><description>&lt;p&gt;Proxy-network enforcement can reduce supply and protect device owners. Your application still needs current intelligence, behaviour correlation, route-specific controls, and measured request decisions.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Mon, 03 Aug 2026 09:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-08-03:/blog/proxy-takedown-is-not-security-control/</guid><category>Security</category><category>Residential Proxies</category><category>Bot Management</category><category>Fraud Prevention</category><category>Threat Intelligence</category><category>Account Protection</category></item><item><title>When Home Devices Become Attack Infrastructure</title><link>https://www.peakhour.io/blog/application-defence-compromised-home-devices/</link><description>&lt;p&gt;Application teams cannot clean compromised televisions, routers, or household devices. They can stop treating the residential address as proof and control what the relayed request is allowed to do.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Sat, 01 Aug 2026 12:30:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-08-01:/blog/application-defence-compromised-home-devices/</guid><category>Security</category><category>Residential Proxies</category><category>IoT Security</category><category>Bot Management</category><category>Application Security</category><category>Threat Detection</category></item><item><title>Residential Proxies Turn Layer 7 DDoS Into a Route Problem</title><link>https://www.peakhour.io/blog/residential-proxies-layer-7-ddos/</link><description>&lt;p&gt;A distributed pool can keep each residential IP quiet while expensive application routes fail. Mitigation has to follow request cost and behaviour, not only traffic volume.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Sat, 01 Aug 2026 12:20:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-08-01:/blog/residential-proxies-layer-7-ddos/</guid><category>Security</category><category>DDoS</category><category>Residential Proxies</category><category>Rate Limiting</category><category>Bot Management</category><category>Origin Protection</category></item><item><title>Privacy Relay, Corporate VPN, or Residential Proxy?</title><link>https://www.peakhour.io/blog/privacy-relay-vpn-residential-proxy-policy/</link><description>&lt;p&gt;An anonymised connection is not automatically abusive. Security policy should distinguish expected privacy and corporate access from proxy use that appears beside risky behaviour.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Sat, 01 Aug 2026 12:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-08-01:/blog/privacy-relay-vpn-residential-proxy-policy/</guid><category>Security</category><category>Privacy</category><category>Residential Proxies</category><category>VPN</category><category>IP Intelligence</category><category>False Positives</category></item><item><title>What a Residential Proxy Decision Log Should Contain</title><link>https://www.peakhour.io/blog/residential-proxy-decision-logging/</link><description>&lt;p&gt;A useful proxy event records the request, signal provenance, policy, action, and outcome. A timestamp and a risk score are not enough to explain an enforcement decision.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Sat, 01 Aug 2026 11:50:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-08-01:/blog/residential-proxy-decision-logging/</guid><category>Security</category><category>Residential Proxies</category><category>Security Logging</category><category>SIEM</category><category>Bot Management</category><category>Incident Response</category></item><item><title>Keep Your CDN. Add Proxy and Bot Decisions at the Edge.</title><link>https://www.peakhour.io/blog/proxy-bot-decisions-existing-cdn/</link><description>&lt;p&gt;Replacing a CDN is not the only way to improve bot and proxy controls. The harder requirement is preserving trusted client context, enforceable policy, and decision evidence across the request path.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Sat, 01 Aug 2026 11:40:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-08-01:/blog/proxy-bot-decisions-existing-cdn/</guid><category>Security</category><category>Edge Security</category><category>CDN</category><category>Bot Management</category><category>Residential Proxies</category><category>Bring Your Own Edge</category></item><item><title>A Proxy Flag Is Not a Security Policy</title><link>https://www.peakhour.io/blog/proxy-flag-is-not-a-security-policy/</link><description>&lt;p&gt;Residential proxy detection is useful evidence. The security decision still has to account for the route, credentials, client history, behaviour, and cost of getting the action wrong.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Sat, 01 Aug 2026 11:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-08-01:/blog/proxy-flag-is-not-a-security-policy/</guid><category>Security</category><category>Residential Proxies</category><category>Bot Management</category><category>Account Protection</category><category>Risk Scoring</category><category>Edge Security</category></item><item><title>Two Lineages of TLS Fingerprinting: JA3, JA4 and Cisco Mercury</title><link>https://www.peakhour.io/blog/two-lineages-tls-fingerprinting/</link><description>&lt;p&gt;JA4 did not descend from Cisco Mercury. The two projects come from different strands of TLS fingerprinting research and solve different operational problems.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Sun, 26 Jul 2026 09:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-07-26:/blog/two-lineages-tls-fingerprinting/</guid><category>Security</category><category>TLS Fingerprinting</category><category>JA3</category><category>JA4</category><category>Cisco Mercury</category><category>Network Fingerprinting</category><category>Threat Detection</category></item><item><title>Before JA3: How TLS Handshakes Became Fingerprints</title><link>https://www.peakhour.io/blog/before-ja3-tls-fingerprinting-history/</link><description>&lt;p&gt;JA3 made TLS fingerprints easy to log and share, but the technical ideas behind it had already been tested in SSL Labs experiments, a p0f patch and FingerprinTLS.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Sun, 19 Jul 2026 09:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-07-19:/blog/before-ja3-tls-fingerprinting-history/</guid><category>Security</category><category>TLS Fingerprinting</category><category>JA3</category><category>FingerprinTLS</category><category>p0f</category><category>Network Fingerprinting</category><category>Security Research</category></item><item><title>A Network Fingerprint Is a Cohort, Not a Client</title><link>https://www.peakhour.io/blog/fingerprint-is-a-cohort-not-a-client/</link><description>&lt;p&gt;TLS fingerprints group similar protocol implementations. They do not prove which application, device or person made a request.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Mon, 13 Jul 2026 09:28:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-07-13:/blog/fingerprint-is-a-cohort-not-a-client/</guid><category>Security</category><category>TLS Fingerprinting</category><category>JA3</category><category>JA4</category><category>Cisco Mercury</category><category>Network Fingerprinting</category><category>Bot Management</category></item><item><title>From Joy to Mercury and EVE: Following Cisco's Network Fingerprinting Work</title><link>https://www.peakhour.io/blog/from-joy-to-mercury-and-eve/</link><description>&lt;p&gt;Cisco's open-source collectors, fingerprinting research and Encrypted Visibility Engine form a clear lineage, but they are not interchangeable parts of one public system.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Mon, 13 Jul 2026 09:28:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-07-13:/blog/from-joy-to-mercury-and-eve/</guid><category>Security</category><category>Cisco Joy</category><category>Cisco Mercury</category><category>Encrypted Visibility Engine</category><category>TLS Fingerprinting</category><category>Network Fingerprinting</category><category>Encrypted Traffic</category></item><item><title>What an Open Network Fingerprint Database Should Publish</title><link>https://www.peakhour.io/blog/open-network-fingerprint-database-schema/</link><description>&lt;p&gt;A useful open fingerprint database needs provenance, competing labels, raw evidence, format versions and licences—not another unexplained hash list.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Mon, 13 Jul 2026 09:28:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-07-13:/blog/open-network-fingerprint-database-schema/</guid><category>Security</category><category>Network Fingerprinting</category><category>TLS Fingerprinting</category><category>JA4</category><category>Cisco Mercury</category><category>Security Research</category></item><item><title>Public Fingerprint Databases Are Not Ground Truth</title><link>https://www.peakhour.io/blog/public-fingerprint-databases-are-not-ground-truth/</link><description>&lt;p&gt;We reviewed the main public fingerprint resources. The formats are open, but current application labels and auditable ground truth remain scarce.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Mon, 13 Jul 2026 09:28:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-07-13:/blog/public-fingerprint-databases-are-not-ground-truth/</guid><category>Security</category><category>Network Fingerprinting</category><category>TLS Fingerprinting</category><category>JA3</category><category>JA4</category><category>Threat Intelligence</category></item><item><title>Does TLS Fingerprint Canonicalisation Hide Attacker Variation? How to Test It</title><link>https://www.peakhour.io/blog/tls-fingerprint-canonicalisation-attacker-variation/</link><description>&lt;p&gt;Sorting makes TLS fingerprints more stable, but it also removes ordering evidence. Here is how to test whether the discarded variation matters.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Mon, 13 Jul 2026 09:28:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-07-13:/blog/tls-fingerprint-canonicalisation-attacker-variation/</guid><category>Security</category><category>TLS Fingerprinting</category><category>JA4</category><category>Cisco Mercury</category><category>Network Fingerprinting</category><category>Security Research</category></item><item><title>Using Network Fingerprints in Bot and Rate-Limit Decisions</title><link>https://www.peakhour.io/blog/using-network-fingerprints-in-bot-and-rate-limit-decisions/</link><description>&lt;p&gt;A practical way to use network fingerprints for bot and rate-limit decisions without mistaking a shared client cohort for identity.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Mon, 13 Jul 2026 09:28:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-07-13:/blog/using-network-fingerprints-in-bot-and-rate-limit-decisions/</guid><category>Security</category><category>Network Fingerprinting</category><category>TLS Fingerprinting</category><category>JA4</category><category>Bot Management</category><category>Rate Limiting</category></item><item><title>One ClientHello, Three Fingerprints: JA3, JA4 and Mercury</title><link>https://www.peakhour.io/blog/one-clienthello-ja3-ja4-mercury-lab/</link><description>&lt;p&gt;A reproducible lab runs JA3, JA4 and Cisco Mercury against the same TLS ClientHello and compares what each fingerprint preserves.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Sun, 12 Jul 2026 09:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-07-12:/blog/one-clienthello-ja3-ja4-mercury-lab/</guid><category>Security</category><category>TLS Fingerprinting</category><category>JA3</category><category>JA4</category><category>Cisco Mercury</category><category>Network Fingerprinting</category><category>Security Research</category></item><item><title>Edge Security is now a Privacy Compliance Issue</title><link>https://www.peakhour.io/blog/edge-security-and-privacy-compliance/</link><description>&lt;p&gt;Recent guidelines from the Australian government have specified practical measures businesses need to take to protect personal information. Learn more.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dan</dc:creator><pubDate>Thu, 25 Jun 2026 08:13:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2026-06-25:/blog/edge-security-and-privacy-compliance/</guid><category>Security</category><category>Security</category><category>Compliance</category></item><item><title>Anatomy of a Credential Stuffing Attack</title><link>https://www.peakhour.io/blog/anatomy-of-a-credential-stuffing-attack/</link><description>&lt;p&gt;A deep dive into how credential stuffing attacks work, the tools used, and how to build a multi-layered defense.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Mon, 01 Sep 2025 00:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2025-09-01:/blog/anatomy-of-a-credential-stuffing-attack/</guid><category>Security</category><category>Credential Stuffing</category><category>Account Protection</category><category>Fraud Prevention</category><category>Residential Proxies</category><category>DNS</category><category>Threat Detection</category></item><item><title>The Invisibility Cloak</title><link>https://www.peakhour.io/blog/bots-residential-proxies-anti-detect-browsers/</link><description>&lt;p&gt;Residential proxies change the network path while anti-detect browsers change the client presentation. Detection works by finding inconsistencies across the request, not by treating either signal as identity.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Mon, 01 Sep 2025 00:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2025-09-01:/blog/bots-residential-proxies-anti-detect-browsers/</guid><category>Security</category><category>Browser Fingerprinting</category><category>Fingerprinting</category><category>Residential Proxies</category><category>Bot Management</category><category>TLS Fingerprinting</category><category>Credential Stuffing</category></item><item><title>How to Use Bot Management for IAM Use Cases</title><link>https://www.peakhour.io/blog/bot-management-for-iam-use-cases/</link><description>&lt;p&gt;Bots are part of account takeover, fraud, scraping, and other abuse. Identity and access management leaders need a clear business case for bot management, or their organisations face avoidable account takeover losses and will be less prepared for the risks introduced when customers use AI agents.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Wed, 20 Aug 2025 00:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2025-08-20:/blog/bot-management-for-iam-use-cases/</guid><category>Security</category><category>Bot Management</category><category>Account Protection</category><category>Credential Stuffing</category><category>API Security</category><category>Threat Detection</category><category>Fraud Prevention</category></item><item><title>The Negative Impact of Visible CAPTCHAs on Bounce Rates and Conversions</title><link>https://www.peakhour.io/blog/the-negative-impact-of-captchas-on-ecommerce-conversions/</link><description>&lt;p&gt;CAPTCHAs have long been a mainstay of bot management solutions, but the tradeoffs are lower conversions, find out just how bad it is.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dan</dc:creator><pubDate>Wed, 06 Aug 2025 13:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2025-08-06:/blog/the-negative-impact-of-captchas-on-ecommerce-conversions/</guid><category>Security</category><category>Bot Management</category><category>Account Protection</category></item><item><title>Protecting Against a Share Point Zero Day Vulnerability with Network Fingerprinting</title><link>https://www.peakhour.io/blog/protecting-against-share-point-zero-day/</link><description>&lt;p&gt;Analysis of attempts to exploit a recent Share Point zero day vulnerability reveal network fingerprinting and classification is a robust defense.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dan</dc:creator><pubDate>Wed, 23 Jul 2025 13:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2025-07-23:/blog/protecting-against-share-point-zero-day/</guid><category>Security</category><category>Threat Detection</category><category>Credential Stuffing</category><category>Account Protection</category><category>DevSecOps</category><category>DDoS</category><category>Application Security</category></item><item><title>How AI Agents Are Writing Custom Exploits</title><link>https://www.peakhour.io/blog/ai-agents-custom-exploits/</link><description>&lt;p&gt;AI agents with reasoning capabilities like DeepSeek are revolutionizing exploit development, marking the end of traditional security approaches based on static rules and patterns.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Mon, 17 Feb 2025 14:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2025-02-17:/blog/ai-agents-custom-exploits/</guid><category>Security</category><category>Application Security</category><category>Threat Detection</category><category>DevSecOps</category><category>Bot Management</category><category>API Security</category><category>DDoS</category></item><item><title>When Bots Are Your Primary Users</title><link>https://www.peakhour.io/blog/future-of-apis-bot-primary-users/</link><description>&lt;p&gt;An exploration of how AI agents are reshaping API design principles and why we must evolve our approach to serve both machine and human consumers.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Wed, 12 Feb 2025 14:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2025-02-12:/blog/future-of-apis-bot-primary-users/</guid><category>Security</category><category>Bot Management</category><category>API Security</category><category>Machine Learning</category></item><item><title>Why Reasoning Models Like DeepSeek Change Everything</title><link>https://www.peakhour.io/blog/agentic-ai-deepseek-changes-everything/</link><description>&lt;p&gt;How open reasoning models transform automation from rigid scripts to autonomous agents, fundamentally changing our approach to security and digital interactions.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Mon, 03 Feb 2025 08:13:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2025-02-03:/blog/agentic-ai-deepseek-changes-everything/</guid><category>Security</category><category>DevSecOps</category><category>Bot Management</category><category>Credential Stuffing</category><category>Machine Learning</category></item><item><title>Preventing Enumeration Attacks</title><link>https://www.peakhour.io/blog/preventing-enumeration-attacks-visa-roadmap/</link><description>&lt;p&gt;An analysis of how Peakhour's solutions help prevent enumeration attacks, aligning with Visa's Security Roadmap 2025-2028 priorities.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Fri, 24 Jan 2025 00:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2025-01-24:/blog/preventing-enumeration-attacks-visa-roadmap/</guid><category>Security</category><category>Account Protection</category><category>Credential Stuffing</category><category>PCI DSS</category><category>API Security</category><category>Fraud Prevention</category><category>Threat Detection</category></item><item><title>How Bots Contaminate Your A/B Testing Results and Marketing Strategy</title><link>https://www.peakhour.io/blog/protecting-ab-testing-from-bots/</link><description>&lt;p&gt;Bot traffic corrupts A/B testing results, leading to flawed marketing decisions. Learn how to protect your tests and ensure accurate data for strategic planning.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dan</dc:creator><pubDate>Wed, 15 Jan 2025 13:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2025-01-15:/blog/protecting-ab-testing-from-bots/</guid><category>Security</category><category>Bot Management</category></item><item><title>Next-Generation Application Security Defence Strategies</title><link>https://www.peakhour.io/blog/ai-powered-cyber-threats-application-security-defence/</link><description>&lt;p&gt;Comprehensive analysis of AI-powered cyber threats and how modern application security platforms defend against machine learning-driven attacks. Learn advanced defence strategies for the AI cybersecurity arms race.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Fri, 15 Nov 2024 14:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2024-11-15:/blog/ai-powered-cyber-threats-application-security-defence/</guid><category>Security</category><category>Threat Detection</category><category>Machine Learning</category><category>DevSecOps</category><category>Bot Management</category><category>DDoS</category><category>Application Security</category></item><item><title>Addressing Key Cloud Security Categories</title><link>https://www.peakhour.io/blog/peakhour-cloud-security-post-wiz/</link><description>&lt;p&gt;An analysis of Peakhour's role in addressing key cloud security categories identified in recent industry analysis, demonstrating its comprehensive approach to modern cloud security challenges.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Wed, 01 May 2024 10:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2024-05-01:/blog/peakhour-cloud-security-post-wiz/</guid><category>Security</category><category>API Security</category><category>Threat Detection</category><category>Account Protection</category><category>DevSecOps</category><category>Application Security</category><category>CDN</category></item><item><title>The Iconic is the latest Account Takeover victim in the news</title><link>https://www.peakhour.io/blog/account-takeover-fraud-theiconic/</link><description>&lt;p&gt;Popular Australian fashion website TheIconic recently suffered reputational damage from fraudsters placing orders after an account takeover. Learn how this happens and what you can do to stop it.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dan</dc:creator><pubDate>Mon, 15 Jan 2024 13:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2024-01-15:/blog/account-takeover-fraud-theiconic/</guid><category>Security</category><category>Account Protection</category><category>Credential Stuffing</category></item><item><title>HTTP Security Headers</title><link>https://www.peakhour.io/blog/http-security-headers-web-application-protection/</link><description>&lt;p&gt;Comprehensive guide to HTTP security headers for protecting web applications from client-side attacks. Learn essential browser security configurations for modern application security platforms and DevSecOps workflows.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Tue, 28 Nov 2023 14:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2023-11-28:/blog/http-security-headers-web-application-protection/</guid><category>Security</category><category>Application Security</category><category>Account Protection</category><category>API Security</category><category>Credential Stuffing</category><category>Drupal</category><category>DDoS</category></item><item><title>A Tale Of Two Scoring Systems</title><link>https://www.peakhour.io/blog/a-tale-of-two-scoring-systems-and-atlassian-confluence/</link><description>&lt;p&gt;Reviewing the CVSS an EPSS CVE scoring systems in light of the Atlassian Confluence-Aggedon&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Wed, 08 Nov 2023 00:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2023-11-08:/blog/a-tale-of-two-scoring-systems-and-atlassian-confluence/</guid><category>Security</category><category>Credential Stuffing</category><category>Threat Detection</category><category>Account Protection</category><category>DevSecOps</category><category>SOC 2</category></item><item><title>Google Chrome IP Protection vs Apple Private Relay</title><link>https://www.peakhour.io/blog/apple-private-relay-vs-google-ip-protection/</link><description>&lt;p&gt;Apple Private Relay and Chrome IP Protection both reduce IP exposure, but they protect different traffic and should not be treated as residential proxies or automatic fraud signals.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Wed, 25 Oct 2023 13:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2023-10-25:/blog/apple-private-relay-vs-google-ip-protection/</guid><category>Security</category><category>Privacy</category><category>IP Intelligence</category><category>Account Protection</category><category>Fingerprinting</category><category>Bot Management</category></item><item><title>JA4 and JA4+ Network Fingerprinting</title><link>https://www.peakhour.io/blog/overview-of-ja4-network-fingerprinting/</link><description>&lt;p&gt;How JA4 constructs a TLS client fingerprint, what JA4+ names, and which details sorting and hashing discard.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Wed, 25 Oct 2023 13:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2023-10-25:/blog/overview-of-ja4-network-fingerprinting/</guid><category>Security</category><category>TLS Fingerprinting</category><category>Fingerprinting</category><category>Browser Fingerprinting</category><category>TLS</category><category>SOC 2</category><category>Threat Detection</category></item><item><title>Google Chrome's IP Protection and Online Privacy</title><link>https://www.peakhour.io/blog/google-chrome-ip-protection-and-online-privacy/</link><description>&lt;p&gt;Chrome IP Protection masks a user's address for selected third-party requests in Incognito. That is narrower than a VPN and should be treated as privacy infrastructure, not proof of abuse.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Tue, 24 Oct 2023 13:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2023-10-24:/blog/google-chrome-ip-protection-and-online-privacy/</guid><category>Security</category><category>Privacy</category><category>IP Intelligence</category><category>Account Protection</category><category>API Security</category><category>Fingerprinting</category><category>Bot Management</category></item><item><title>ModSecurity’s End-of-Life</title><link>https://www.peakhour.io/blog/modsecurity-eol-modern-application-security-platforms/</link><description>&lt;p&gt;ModSecurity's end-of-life marks a pivotal moment in application security evolution. Discover how modern Application Security Platforms are advancing beyond traditional WAF approaches to provide comprehensive protection for web applications and APIs at the edge.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Mon, 16 Oct 2023 13:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2023-10-16:/blog/modsecurity-eol-modern-application-security-platforms/</guid><category>Security</category><category>Application Security</category><category>DevSecOps</category><category>API Security</category><category>DDoS</category><category>Threat Detection</category><category>SOC 2</category></item><item><title>Understanding the HTTP/2 Rapid Reset Attack</title><link>https://www.peakhour.io/blog/http-rapid-reset-attack/</link><description>&lt;p&gt;A comprehensive breakdown of the HTTP/2 Rapid Reset flaw and guidance on bolstering defences against potential DDoS attacks.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Wed, 11 Oct 2023 00:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2023-10-11:/blog/http-rapid-reset-attack/</guid><category>Security</category><category>DDoS</category><category>Rate Limiting</category><category>DNS</category><category>API Security</category><category>Bot Management</category><category>Threat Detection</category></item><item><title>The Rise of OpenBullet</title><link>https://www.peakhour.io/blog/the-rise-of-openbullet/</link><description>&lt;p&gt;How OpenBullet packages browser and HTTP automation for credential attacks, and which signals defenders can use without treating any one fingerprint as proof.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Fri, 01 Sep 2023 14:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2023-09-01:/blog/the-rise-of-openbullet/</guid><category>Security</category><category>Bot Management</category><category>Application Security</category><category>DevSecOps</category><category>Account Protection</category><category>Credential Stuffing</category><category>Threat Detection</category></item><item><title>Headless Commerce Security</title><link>https://www.peakhour.io/blog/headless-commerce-security-api-protection/</link><description>&lt;p&gt;Comprehensive analysis of security challenges in headless commerce and Single Page Applications. Learn how to protect modern e-commerce APIs and microservices architectures from scraping, fraud, and automated attacks.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">Dan</dc:creator><pubDate>Wed, 28 Jun 2023 00:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2023-06-28:/blog/headless-commerce-security-api-protection/</guid><category>Security</category><category>API Security</category><category>Magento</category><category>Account Protection</category><category>Drupal</category><category>Application Security</category><category>Bot Management</category></item><item><title>Advanced Anomaly Detection</title><link>https://www.peakhour.io/blog/advanced-anomaly-detection-rrcf-application-security/</link><description>&lt;p&gt;Deep dive into Robust Random Cut Forest (RRCF) implementation for real-time anomaly detection in Application Security Platforms. Learn how advanced machine learning algorithms enhance threat detection and automated response capabilities.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Mon, 15 May 2023 13:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2023-05-15:/blog/advanced-anomaly-detection-rrcf-application-security/</guid><category>Security</category><category>Threat Detection</category><category>Anomaly Detection</category><category>DDoS</category><category>DevSecOps</category><category>Bot Management</category><category>Application Security</category></item><item><title>Chrome's TLS Extension Randomisation Experiment</title><link>https://www.peakhour.io/blog/tls-extension-randomisation/</link><description>&lt;p&gt;Does TLS extension randomisation assist in hiding Chrome?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Thu, 02 Feb 2023 13:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2023-02-02:/blog/tls-extension-randomisation/</guid><category>Security</category><category>TLS Fingerprinting</category><category>TLS</category><category>Browser Fingerprinting</category><category>Fingerprinting</category><category>API Security</category></item><item><title>TLS Fingerprinting</title><link>https://www.peakhour.io/blog/tls-fingerprinting/</link><description>&lt;p&gt;What is fingerprinting, and in particular TLS fingerprinting?&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Thu, 02 Feb 2023 13:00:00 +1100</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2023-02-02:/blog/tls-fingerprinting/</guid><category>Security</category><category>TLS Fingerprinting</category><category>Browser Fingerprinting</category><category>Fingerprinting</category><category>TLS</category><category>HTTP</category><category>DDoS</category></item><item><title>IP Threat Intelligence</title><link>https://www.peakhour.io/blog/ip-threat-intelligence/</link><description>&lt;p&gt;Comprehensive guide to IP threat intelligence for modern application security platforms. Learn how managed IP reputation lists and threat intelligence feeds protect applications from known malicious sources and emerging threats.&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Fri, 15 Jul 2022 13:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2022-07-15:/blog/ip-threat-intelligence/</guid><category>Security</category><category>Threat Detection</category><category>DDoS</category><category>Rate Limiting</category><category>API Security</category><category>Bot Management</category><category>Networking</category></item><item><title>CVE-2022-26134</title><link>https://www.peakhour.io/blog/cve202226134-atlassian-confluence/</link><description>&lt;p&gt;Peakhour clients are protected against CVF-2022-26134 Atlassian Confluence RCE&lt;/p&gt;</description><dc:creator xmlns:dc="http://purl.org/dc/elements/1.1/">AC</dc:creator><pubDate>Thu, 02 Jun 2022 00:00:00 +1000</pubDate><guid isPermaLink="false">tag:www.peakhour.io,2022-06-02:/blog/cve202226134-atlassian-confluence/</guid><category>Security</category><category>API Security</category><category>DDoS</category><category>Rate Limiting</category><category>Application Security</category><category>Credential Stuffing</category><category>Features</category></item></channel></rss>