Website protection
that just works

WAF-FW blocks attacks, bad bots and abuse before they reach your site. Your site stays online, you see everything on a live dashboard, and you get an alert the moment something tries.

A live traffic dashboard showing blocked requests
Protection standing in front of a website around the clock
Website protection, switched on

Protection that keeps your
site online and out of trouble

WAF-FW sits in front of your website and checks every visitor in real time. Attacks, bad bots and abuse are stopped before they ever reach you, so real customers get through fast and the rest never do.

There is nothing to install and nothing for you to run. It is delivered as a service, always on and updating itself against new threats, with a live dashboard and instant alerts so you always know exactly what was blocked and when.

Learn More
What you get

Protection built for real websites

Everything runs in front of your site as a service. There is nothing for you to install, patch or babysit.

Attack blocking

Harmful requests are stopped in real time, before they ever reach your pages.

Read More
Bad-bot filtering

Scrapers, fake signups and credential stuffing are caught while real customers pass straight through.

Read More
DDoS and flood defense

Sudden request floods are soaked up automatically, so your site stays online when it matters most.

Read More
Abuse and rate control

Repeat offenders and abusive spikes are slowed and blocked before they can do any harm.

Read More
Live traffic dashboard

See who is visiting and what was blocked, live, without digging through server logs.

Read More
Instant alerts

Get told the moment something is blocked, so you are never the last to know.

Read More
In practice

How WAF-FW protects you

The same threats hit every site on the internet. Here is what WAF-FW stops before it ever reaches you.

Exploit attempts stopped before reaching your site
Blocked exploit attempts

Every request is inspected in real time. Injection attempts, path traversal and other malicious payloads are recognised and stopped at the edge, so they never touch your application or your data. Legitimate visitors are never slowed down.

Protection standing in front of a website
FAQs

Questions & Answers

Everything you need to know about keeping your site protected with WAF-FW, in plain language.

News

Latest updates and security notes

Product news and plain-language write-ups on the threats we see and block.

CaptiveCrunch Turns Hotel Wi-Fi Into a Launchpad for Russian Espionage
3rd Aug 2026 WAF-FW
CaptiveCrunch Turns Hotel Wi-Fi Into a Launchpad for Russian Espionage

Microsoft says a sub-cluster of the Russian state-linked Midnight Blizzard group is manipulating traffic on hotel and other hospitality networks. The CaptiveCrunch campaign redirects travelers to phishing pages and fake update prompts that can deliver credential-stealing malware and remote access tools. ([microsoft.com](https://www.microsoft.com/en-us/security/blog/2026/07/31/captivecrunch-midnight-blizzard-targets-travelers-worldwide-for-malware-delivery-and-credential-theft/))

Poisoned Adform Script Turned Customer Websites Into Crypto Address Swappers
3rd Aug 2026 WAF-FW
Poisoned Adform Script Turned Customer Websites Into Crypto Address Swappers

Attackers compromised a JavaScript resource distributed through Adform and used it to replace cryptocurrency wallet addresses inside visitors' browsers. The incident demonstrates how one altered third-party script can silently affect many unrelated websites without requiring each site to be breached individually. ([thehackernews.com](https://thehackernews.com/2026/08/hackers-poison-adform-script-to-swap.html))

COLDCARD Randomness Failure Exposes Bitcoin Wallets to an $88 Million Sweep
3rd Aug 2026 WAF-FW
COLDCARD Randomness Failure Exposes Bitcoin Wallets to an $88 Million Sweep

A firmware integration error caused some COLDCARD hardware wallets to generate recovery seeds with a predictable software-based random number generator. Researchers believe attackers reconstructed vulnerable seeds offline and used them to steal approximately $88.6 million in Bitcoin from thousands of addresses. ([bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/coldcard-wallet-rng-flaw-likely-linked-to-88-million-bitcoin-theft/))