Fortra today announced a significant update to its managed application firewall (WAF) solution that aims to reduce client-side risk and protect users from data-stealing attacks in the browser, as outlined in new requirements in PCI DSS 4.0.
Fortra Managed WAF now includes enhanced client-side protection controls to eliminate reflected and inline cross-site scripting (XSS) attacks. This additional security helps Fortra customers meet and exceed PCI DSS 4.0 XSS controls in requirements 6.4.3 and 11.6.1, protecting users’ payment information from in-browser data-stealing attacks like Magecart.
A WAF is an essential element of a security strategy for any organization with a web presence and APIs. Fortra solves the most significant challenge of optimizing the protection provided by a WAF through its managed services for SMEs to Fortune 500 customers.
Fortra Managed WAF enforces the execution of active items in the browser, regardless of whether they are delivered via inline, first, or third-party scripts. With this release, Fortra Managed WAF closes a gap that still is prevalent in competitors’ WAFs where they are unable to comprehensively address inline script integrity enforcement, a delivery mechanism used by most websites.
“Most WAFs offer client-side protection inventory running scripts and only alert when a significant change to script behavior is detected,” said Rob Pollard, Managing Director, Fortra’s Alert Logic. “Fortra Managed WAF leverages modern browser security features to either alert or automatically block unauthorized or modified scripts from executing. This results in a higher level of security and data protection, giving organizations comprehensive control of their web supply chain attack surface.”
Learn more about the enhancements to Fortra Managed WAF through a free demo.