
7/1/2021 · Michael Tremante
What this post added
Introduced new WAF rules (100197 and 100197B) to detect and block reGeorg web shell variants. Expanded the availability of the Exposed Credential Check feature of Account Takeover Protection to all paid plans, which adds an `Exposed-Credential-Check: 1` header to requests when compromised credentials are detected. This header can be used by origin servers to enforce additional security measures like MFA or password resets. The feature can also be used in logging mode for brute-force attack identification via Firewall Analytics.