Unlock stock picks and a broker-level newsfeed that powers Wall Street.

F5 Strengthens Security Capabilities in the F5 Application Delivery and Security Platform

In This Article:

  • Enhancements include cloud-native protection, web application scanning for LLM vulnerabilities, expanded API discovery tools, and enhanced client-side detection

  • F5’s Application Delivery and Security Platform named to 2025 Vendor Vision Report from analyst firm EMA; singled out for robust AI-driven security architecture and API protection capabilities

  • F5’s 2025 State of Application Strategy Report reveals expanded AI and API sprawl significantly impacts enterprise cybersecurity strategies

SEATTLE, April 22, 2025--(BUSINESS WIRE)--F5 (NASDAQ: FFIV), the global leader in delivering and securing every app and API, today unveiled broad cybersecurity enhancements to the F5 Application Delivery and Security Platform (ADSP) that significantly improve organizations’ ability to identify and remediate vulnerabilities and threats to AI and other modern applications. These new enhancements enable enterprises to strengthen security for business-critical applications in an increasingly risky threat landscape. The F5 ADSP is the industry’s only platform that fully converges high-performance load balancing and traffic management with advanced app and API security capabilities.

The F5 ADSP is the most complete application security offering for enterprises looking to address the increasingly complex cybersecurity challenges inherent in today’s AI-driven hybrid multicloud world. Similar to Endpoint Protection Platforms (EPP) built to secure endpoints and Secure Access Service Edge (SASE) platforms built to secure network access, F5’s ADSP is built to consolidate disparate tools for securing apps and APIs into a single comprehensive platform, enabling organizations to simplify their security footprint while offering broader protection against enhanced threats.

New cybersecurity capabilities for the F5 ADSP include:

  • Cloud-Native Protection with F5 NGINXaaS for Azure with NGINX App Protect: NGINX App Protect as an add-on to NGINXaaS (NGINX as a Service) is now available for Azure deployments. NGINX App Protect is a modern application security solution designed to provide robust protection against an array of threats, including sophisticated attacks, data breaches, and other malicious activities. By integrating NGINX App Protect with NGINXaaS, customers have access to advanced threat protection against modern threats such as the OWASP Top Ten vulnerabilities and zero-day attacks, real-time traffic inspection, and automated security policy management.

  • Scan LLMs for Vulnerabilities: The F5 ADSP now features web app scanning functionality that has been purpose-built to scan for, identify, and assess security vulnerabilities in large language model (LLM) deployments. This new functionality enables organizations to scan LLMs and run penetration testing to uncover LLM-specific vulnerabilities that map to the OWASP Top Ten for LLM Applications.

  • Expanded API Discovery Tools: APIs have become the connective tissue for most of today’s digital experiences, and the explosion of API use has made it difficult for security teams to keep pace. Unmonitored and unprotected APIs lead to substantial security exposure, opening organizations to threats such as injection attacks, data exfiltration, unauthorized access, and denial-of-service (DoS) attacks. F5 has expanded its powerful API discovery tools for use across the ADSP platform to include all F5 BIG-IP deployments, enabling organizations to get full API visibility for applications that utilize BIG-IP. This allows organizations to easily identify exposed APIs for applications in production, without having to migrate them to the F5 Distributed Cloud Console.

  • Enhanced Client-Side Defense Capabilities for Greater Compliance: As threat actors search for new attack vectors, client-side browser-based attacks are becoming increasingly prevalent. The latest revision of the Payment Card Industry Data Security Standard (PCI DSS) v4.0 now requires businesses to have client-side protections deployed to mitigate the risks associated with data exfiltration and malicious JavaScript attacks. F5’s enhanced client-side defense capabilities bolster defense postures by delivering greater visibility into malicious scripts and the actions that they are taking—identifying risky scripts and where they send data.