Positive Technologies Discontinues Active Development of PT AF 3, Shifts Focus to PT AF PRO and PT Cloud AF
Positive Technologies is winding down active development of PT Application Firewall 3 and reallocating its main engineering resources to PT AF PRO and the cloud-native PT Cloud AF.
Current customers of the older WAF solution will continue to receive technical support, but the product is unlikely to gain major new features going forward.
Why the strategy is changing
Over the past decade, corporate web infrastructure has expanded dramatically. Organizations that once managed a handful of websites now operate hundreds of applications, APIs, and microservices distributed across on-premises data centers, multiple clouds, branch offices, and subsidiary networks.
At the same time, the threat landscape has evolved. Compromising a web application is frequently no longer the attacker’s final objective but rather a foothold for deeper penetration into internal corporate networks.
According to Positive Technologies data, exploitation of vulnerabilities in internet-accessible web applications remains the most common initial access technique, responsible for 36% of successful attacks against corporate environments.
New flagship: PT AF PRO
The company’s primary focus is now PT AF PRO, a solution developed from scratch over more than six years. It is designed to protect hundreds of applications in highly distributed infrastructures and offers centralized security policy management, remote site connectivity via external agents, and the ability to apply updates without interrupting traffic processing.
Protected applications can be segmented into isolated spaces with dedicated compute resources and granular access controls for security events. This architecture targets large enterprises and holding companies that operate multiple security teams with differing service requirements.
Cloud offering gains priority
The second strategic priority is PT Cloud AF, a cloud-delivered WAF for applications and APIs that eliminates the need to purchase and maintain hardware. Customers can manage the service themselves or delegate configuration and ongoing operations to a partner.
Over the past year, the customer base for PT AF PRO has doubled, reflecting growing demand for scalable, distributed web application protection.
Related articles
Where to Find Scientific Articles and Full Texts in 2026: Russian and International Databases Guide
Finding complete scientific papers often requires navigating multiple platforms because search engines show only titles and abstracts while publishers may demand payment for PDFs. The guide explains the differences between bibliographic databases that help locate publications and full-text repositories that provide actual documents. It covers Russian resources such as CyberLeninka, eLIBRARY.RU with RINC, Math-Net.Ru, and the national platform of scientific journals, along with international tools including Google Scholar, PubMed, arXiv, ACM Digital Library, IEEE Xplore, Scopus, and Web of Science. Additional sections address book catalogs, archives, AI-powered search tools like Consensus, and scientific social networks such as ResearchGate. The material emphasizes that presence in any database does not guarantee quality or validity, urging readers to verify methods, results, and publication status independently. Practical advice is given on locating open-access versions, using library subscriptions, and contacting authors directly.
WAF Connected — What Next? How to Configure Web Application Firewalls for Real Protection Without Disruption
After successful pilot testing, organizations often struggle when scaling WAF protection across dozens or hundreds of applications. Each app brings unique technology stacks, traffic patterns, and legitimate anomalies that can break existing rules. The article stresses starting in monitoring mode rather than blocking to avoid false positives that frustrate users and damage business operations. A structured Risk Score and Priority Score system helps teams prioritize applications based on exposure, business impact, control weaknesses, technical risks, and data sensitivity. Regular tuning, log analysis, and quarterly re-evaluation of the application registry are required because applications evolve constantly. Well-configured WAF solutions must deliver low false-positive rates, rapid exception handling, and resilience under peak loads without creating new operational burdens for security teams.
Avanpost SmartPAM Adds 60 MITRE ATT&CK Signatures for Privileged Session Threat Detection
Avanpost has released an update to its SmartPAM 1.4 solution that incorporates a library of 60 signatures mapped to the MITRE ATT&CK framework. The new capability allows the Privileged Access Management system to monitor and analyze actions performed by administrators inside privileged sessions rather than simply controlling initial access. The signatures cover common attack techniques including credential access, persistence, lateral movement, and defense evasion such as disabling audit logs, antivirus, or firewalls and clearing system events. A built-in signature analysis engine normalizes session data, matches observed behavior against known attack patterns, and triggers automated responses including command blocking, session termination, or SIEM alerts. Customers can combine the vendor-supplied rules with custom policies and will receive regular subscription-based updates at no cost until the end of 2026. Avanpost claims SmartPAM is the first PAM product to offer a MITRE ATT&CK-structured signature library, shifting the tool from a basic access gatekeeper to an active behavioral observer capable of identifying malicious activity even when valid credentials are used.
StormWall Releases StormWall Appliance for On-Premises DDoS Protection
StormWall has introduced StormWall Appliance, a software solution that filters DDoS attacks inside the customer's own infrastructure rather than routing traffic to an external cloud. The product is aimed primarily at banks, hosting providers, internet service providers, and organizations with strict requirements for infrastructure availability and data control. It supports fully isolated networks through offline licensing with a hardware key and can operate independently or in a hybrid mode with StormWall's cloud platform. The appliance handles attacks at OSI layers L3 through L5, including volumetric floods, TCP stack attacks, reflection and amplification schemes, DNS attacks, and gaming protocols. It also processes TLS and QUIC traffic without decryption using DPDK and proprietary algorithms. Deployment takes as little as one day, with a 30-day free trial available after installation.