<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Home on Waratek</title><link>https://waratek.com/</link><description>Recent content in Home on Waratek</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 21 Jul 2026 09:00:00 +0000</lastBuildDate><atom:link href="https://waratek.com/index.xml" rel="self" type="application/rss+xml"/><item><title>Oracle Releases the July 2026 Critical Patch Update</title><link>https://waratek.com/news/oracle-releases-the-july-2026-critical-patch-update/</link><pubDate>Tue, 21 Jul 2026 09:00:00 +0000</pubDate><guid>https://waratek.com/news/oracle-releases-the-july-2026-critical-patch-update/</guid><description>&lt;blockquote class="wt-highlights"&gt;&lt;p&gt;&lt;strong&gt;Highlights&lt;/strong&gt;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Oracle&amp;rsquo;s July 2026 CPU ships 1,455 new security patches, the largest Critical Patch Update Oracle has issued to date.&lt;/li&gt;
&lt;li&gt;The highest score this quarter is a perfect CVSS 10.0, affecting Oracle Access Manager, WebLogic Server and Oracle Coherence within Fusion Middleware.&lt;/li&gt;
&lt;li&gt;PeopleSoft is the emergency priority. CVE-2026-35278 and CVE-2026-35273 (both CVSS 9.8) are under active exploitation by the ShinyHunters extortion group, which claims to have compromised more than 300 PeopleSoft servers across 100+ organizations since late May 2026.&lt;/li&gt;
&lt;li&gt;Fusion Middleware receives 359 patches (224 remotely exploitable without authentication), the largest single-family total in this CPU. WebLogic, Identity Manager and WebCenter Capture each carry CVSS 9.9 unauthenticated RCE flaws.&lt;/li&gt;
&lt;li&gt;E-Business Suite receives 416 patches (63 remotely exploitable), reflecting sustained attacker interest after the 2025 Cl0p campaign and a separately exploited flaw patched last month.&lt;/li&gt;
&lt;li&gt;Java SE ships 20 patches (18 remotely exploitable) with a comparatively modest maximum CVSS of 7.8, mostly affecting availability rather than confidentiality or integrity.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Action:&lt;/strong&gt; patch internet-facing PeopleSoft, Fusion Middleware (WebLogic, Identity Manager, Access Manager) and E-Business Suite this week. Treat the Database Server 9.9 flaw as high priority even though it is not yet reported under active exploitation.&lt;/li&gt;
&lt;/ul&gt;
&lt;/blockquote&gt;
&lt;h2 id="commentary"&gt;Commentary&lt;/h2&gt;
&lt;p&gt;The Oracle Critical Patch Update (CPU) for July 2026 contains 1,455 new security patches spanning more than two dozen product families, making it the largest quarterly release Oracle has published. The update is cumulative, meaning it folds in the May 28 and June 16, 2026 monthly Critical Security Patch Updates (CSPU) as well as the out-of-band Security Alert issued June 10, 2026 for the PeopleSoft PeopleTools vulnerability now tracked as CVE-2026-35273.&lt;/p&gt;</description></item><item><title>Can We Bridge the 42% Perception Gap? Aligning the C-Suite and the SOC</title><link>https://waratek.com/blogs/bridging-the-soc-perception-gap/</link><pubDate>Thu, 25 Jun 2026 00:00:00 +0000</pubDate><guid>https://waratek.com/blogs/bridging-the-soc-perception-gap/</guid><description>&lt;p&gt;&lt;strong&gt;Who Should Read:&lt;/strong&gt; Executive Leadership (CISO, CTO, CIO), GRC (Governance, Risk, and Compliance) Officers, and AppSec Directors.&lt;/p&gt;
&lt;h2 id="summary"&gt;Summary&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;The 42% Perception Gap:&lt;/strong&gt; A major disconnect exists between executive leadership and security practitioners regarding SLA compliance, with 57% of C-suite executives believing SLAs are being met while only 15% of practitioners agree.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The Visibility Crisis:&lt;/strong&gt; Executives are often misled by &amp;ldquo;green&amp;rdquo; dashboards showing completed scans, while practitioners are actually overwhelmed by an unmanageable mountain of unresolvable and AI-generated vulnerabilities.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Unifying the View:&lt;/strong&gt; Waratek eliminates this disconnect by combining &lt;a href="https://waratek.com/iast/"&gt;Interactive Application Security Testing (IAST)&lt;/a&gt; and &lt;a href="https://waratek.com/rasp/"&gt;Runtime Application Self-Protection (RASP)&lt;/a&gt; to establish &amp;ldquo;one version of the truth&amp;rdquo; for both leadership and the SOC.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Automated, Real-Time Remediation:&lt;/strong&gt; By automating defense at the runtime level, security issues are mitigated at the speed of the attack rather than waiting on slow development sprint cycles.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Verifiable Protection for GRC:&lt;/strong&gt; The platform shifts organizations from &amp;ldquo;hopeful security&amp;rdquo; to verifiable compliance, relieving the burden on the SOC through virtual patching and ensuring high-level reporting matches actual security posture.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="introduction-is-there-a-visibility-crisis-in-the-boardroom"&gt;Introduction: Is There A Visibility Crisis in the Boardroom?&lt;/h2&gt;
&lt;p&gt;There is a massive disconnect currently unfolding in the modern enterprise. While C-suite executives sit in boardrooms reviewing dashboards that signal &amp;ldquo;all clear,&amp;rdquo; the practitioners in the trenches are battling a different reality. New data reveals a staggering 42% perception gap: 57% of executives believe their security Service Level Agreements (SLAs) are being met, while only 15% of the security practitioners doing the work agree.&lt;/p&gt;</description></item><item><title>Oracle Releases Significant June Security Update</title><link>https://waratek.com/news/oracle-releases-significant-june-security-update/</link><pubDate>Wed, 17 Jun 2026 11:30:29 +0000</pubDate><guid>https://waratek.com/news/oracle-releases-significant-june-security-update/</guid><description>&lt;h2 id="key-findings---oracle-cspu-june-2026"&gt;Key findings - Oracle CSPU June 2026&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Advisory scope:&lt;/strong&gt; 257 CVE-product matrix entries across 66 products in 11 product families (251 unique CVEs; same CVE can appear in multiple matrices).&lt;/p&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th&gt;Severity&lt;/th&gt;
					&lt;th&gt;Count&lt;/th&gt;
					&lt;th&gt;No Auth Required&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td&gt;&lt;strong&gt;Critical&lt;/strong&gt; (CVSS ≥ 9.0)&lt;/td&gt;
					&lt;td&gt;&lt;strong&gt;134&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;&lt;strong&gt;104&lt;/strong&gt;&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;&lt;strong&gt;High&lt;/strong&gt; (7.0–8.9)&lt;/td&gt;
					&lt;td&gt;&lt;strong&gt;104&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;-&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;&lt;strong&gt;Medium&lt;/strong&gt; (4.0–6.9)&lt;/td&gt;
					&lt;td&gt;&lt;strong&gt;15&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;-&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Low (&amp;lt; 4.0)&lt;/td&gt;
					&lt;td&gt;4&lt;/td&gt;
					&lt;td&gt;-&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="top-risk-products-critical-cves"&gt;Top risk products (Critical CVEs)&lt;/h2&gt;
&lt;table&gt;
	&lt;thead&gt;
			&lt;tr&gt;
					&lt;th&gt;Product&lt;/th&gt;
					&lt;th&gt;Family&lt;/th&gt;
					&lt;th&gt;Critical&lt;/th&gt;
					&lt;th&gt;High&lt;/th&gt;
					&lt;th&gt;Med&lt;/th&gt;
					&lt;th&gt;No Auth Req&lt;/th&gt;
			&lt;/tr&gt;
	&lt;/thead&gt;
	&lt;tbody&gt;
			&lt;tr&gt;
					&lt;td&gt;Oracle WebCenter Content&lt;/td&gt;
					&lt;td&gt;Fusion Middleware&lt;/td&gt;
					&lt;td&gt;&lt;strong&gt;16&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;13&lt;/td&gt;
					&lt;td&gt;1&lt;/td&gt;
					&lt;td&gt;14&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Oracle Enterprise Manager Base Platform&lt;/td&gt;
					&lt;td&gt;Enterprise Manager&lt;/td&gt;
					&lt;td&gt;&lt;strong&gt;13&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;6&lt;/td&gt;
					&lt;td&gt;-&lt;/td&gt;
					&lt;td&gt;9&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;JD Edwards EnterpriseOne Tools&lt;/td&gt;
					&lt;td&gt;JD Edwards&lt;/td&gt;
					&lt;td&gt;&lt;strong&gt;13&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;1&lt;/td&gt;
					&lt;td&gt;-&lt;/td&gt;
					&lt;td&gt;11&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Oracle WebCenter Enterprise Capture&lt;/td&gt;
					&lt;td&gt;Fusion Middleware&lt;/td&gt;
					&lt;td&gt;&lt;strong&gt;10&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;-&lt;/td&gt;
					&lt;td&gt;-&lt;/td&gt;
					&lt;td&gt;2&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Oracle WebCenter Portal&lt;/td&gt;
					&lt;td&gt;Fusion Middleware&lt;/td&gt;
					&lt;td&gt;&lt;strong&gt;10&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;-&lt;/td&gt;
					&lt;td&gt;-&lt;/td&gt;
					&lt;td&gt;3&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Oracle WebCenter Sites&lt;/td&gt;
					&lt;td&gt;Fusion Middleware&lt;/td&gt;
					&lt;td&gt;&lt;strong&gt;8&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;3&lt;/td&gt;
					&lt;td&gt;-&lt;/td&gt;
					&lt;td&gt;8&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Oracle Enterprise Command Center Framework&lt;/td&gt;
					&lt;td&gt;E-Business Suite&lt;/td&gt;
					&lt;td&gt;&lt;strong&gt;7&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;1&lt;/td&gt;
					&lt;td&gt;-&lt;/td&gt;
					&lt;td&gt;2&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Oracle Coherence&lt;/td&gt;
					&lt;td&gt;Fusion Middleware&lt;/td&gt;
					&lt;td&gt;&lt;strong&gt;7&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;-&lt;/td&gt;
					&lt;td&gt;-&lt;/td&gt;
					&lt;td&gt;&lt;strong&gt;7&lt;/strong&gt;&lt;/td&gt;
			&lt;/tr&gt;
			&lt;tr&gt;
					&lt;td&gt;Oracle iSupport&lt;/td&gt;
					&lt;td&gt;E-Business Suite&lt;/td&gt;
					&lt;td&gt;&lt;strong&gt;3&lt;/strong&gt;&lt;/td&gt;
					&lt;td&gt;-&lt;/td&gt;
					&lt;td&gt;-&lt;/td&gt;
					&lt;td&gt;-&lt;/td&gt;
			&lt;/tr&gt;
	&lt;/tbody&gt;
&lt;/table&gt;
&lt;h2 id="family-level-highlights"&gt;Family-level highlights&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Oracle Fusion Middleware&lt;/strong&gt; is the dominant risk surface consisting of 69 Critical CVEs across 14 products, 49 of them remotely exploitable without authentication. The WebCenter stack alone (Content, Portal, Sites, Enterprise Capture, Imaging) accounts for 47 Critical vulnerabilities. Oracle Coherence stands out with 7 Critical CVEs all scoring 9.3–10.0 and all RNoAuth.&lt;/p&gt;</description></item><item><title>Waratek Appoints Apostolos Giannakidis as Chief Technology Officer</title><link>https://waratek.com/news/waratek-appoints-apostolos-giannakidis-as-chief-technology-officer/</link><pubDate>Mon, 15 Jun 2026 08:52:23 +0000</pubDate><guid>https://waratek.com/news/waratek-appoints-apostolos-giannakidis-as-chief-technology-officer/</guid><description>&lt;p&gt;&lt;strong&gt;Veteran runtime security architect to lead Waratek’s technology strategy as enterprises confront a new wave of AI-generated code vulnerabilities and exploits&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;DUBLIN - 15 June, 2026&lt;/strong&gt; - Waratek, the leader in runtime application security, today announced the appointment of Apostolos Giannakidis as Chief Technology Officer. In his new role, Giannakidis will lead Waratek’s technology vision, product strategy, and security research as the company expands its runtime protection platform to address the surge in software vulnerabilities and exploits introduced by AI-generated code.&lt;/p&gt;</description></item><item><title>Remediation Crisis: Why 62% of AI Flaws Go Unfixed</title><link>https://waratek.com/blogs/remediation-crisis-why-62-of-ai-flaws-go-unfixed/</link><pubDate>Tue, 02 Jun 2026 18:38:42 +0000</pubDate><guid>https://waratek.com/blogs/remediation-crisis-why-62-of-ai-flaws-go-unfixed/</guid><description>&lt;p&gt;The rapid adoption of Large Language Models (LLMs) has outpaced our ability to secure them. Currently, 62% of high-risk AI vulnerabilities go unfixed because traditional patching methods-like updating a library-don’t apply to the non-deterministic nature of neural networks. This blog explores why the “remediation gap” exists and how Runtime Application Self-Protection (RASP) secures AI assets without waiting for costly model re-training.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;🎯 Who Should Read:&lt;/strong&gt; AppSec Managers, DevOps Leads, and Senior Software Architects.&lt;/p&gt;</description></item><item><title>Oracle Launches Monthly Security Patching</title><link>https://waratek.com/news/oracle-launches-monthly-security-patching/</link><pubDate>Fri, 29 May 2026 09:57:46 +0000</pubDate><guid>https://waratek.com/news/oracle-launches-monthly-security-patching/</guid><description>&lt;p&gt;&lt;em&gt;Summary and analysis of the first Oracles first monthly Critical Security Patch Update (CSPU)&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;–URGENT ACTION RECOMMENDED–&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;em&gt;For Waratek customers and prospects&lt;/em&gt;&lt;/p&gt;
&lt;h2 id="highlights"&gt;Highlights&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Oracle has moved from quarterly to monthly &amp;amp; quarterly security patching. The first Critical Security Patch Update (CSPU) shipped on Thursday, May 28, 2026; subsequent CSPUs land on the third Tuesday of each month outside the quarterly CPU window.&lt;/li&gt;
&lt;li&gt;This first CSPU is targeted and compact: 35 new security patches across five product families – a deliberately smaller footprint than the 483-patch April CPU.&lt;/li&gt;
&lt;li&gt;Headline severity is a CVSS 10.0 in Oracle REST Data Services (ORDS) – the maximum possible score, unauthenticated, network-exploitable.&lt;/li&gt;
&lt;li&gt;Oracle E-Business Suite ships 12 patches with a max CVSS 9.9 – attacker focus on EBS remains high after October 2025’s Cl0p extortion campaign (CVE-2025-61882).&lt;/li&gt;
&lt;li&gt;Action: Waratek customers should contact &lt;a href="mailto:customersuccess@waratek.com"&gt;customersuccess@waratek.com&lt;/a&gt; for RASP rule coverage; prospects can request a same-week protection assessment from &lt;a href="mailto:sales@waratek.com"&gt;sales@waratek.com&lt;/a&gt;.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="what-changed-oracles-new-monthly-cadence"&gt;What Changed: Oracle’s New Monthly Cadence&lt;/h2&gt;
&lt;p&gt;For more than two decades Oracle has shipped security fixes on a quarterly Critical Patch Update (CPU) rhythm. As of May 28, 2026, Oracle has introduced an additional, monthly Critical Security Patch Update (CSPU) stream that fills the gap between quarterly releases. The change is a direct response to a year in which Oracle products were targeted by ransomware operators (Cl0p / CVE-2025-61882) and Identity Manager flaws (CVE-2025-61757, CVE-2026-21992) reached CISA’s KEV catalog within days of disclosure.&lt;/p&gt;</description></item><item><title>Waratek IAST + RASP is Insurance Against AI Risk</title><link>https://waratek.com/blogs/waratek-iast-rasp-is-insurance-against-ai-risk/</link><pubDate>Tue, 26 May 2026 23:03:15 +0000</pubDate><guid>https://waratek.com/blogs/waratek-iast-rasp-is-insurance-against-ai-risk/</guid><description>&lt;p&gt;As AI-generated code floods the software lifecycle, AppSec leaders face a choice: slow down innovation or risk catastrophic security debt. Waratek’s IAST and RASP solutions provide a dual-layer insurance policy, automating the detection of real threats in development and shielding applications in production. This allows leadership to stop “firefighting” and align their most talented staff to high-value strategic initiatives.&lt;/p&gt;
&lt;h2 id="executive-highlights"&gt;Executive Highlights&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;The “18-Month Wall”:&lt;/strong&gt; AI speeds up delivery but doubles technical debt; Waratek breaks this cycle by validating code logic at the bytecode level.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Zero-Noise Triage:&lt;/strong&gt; Waratek IAST eliminates the “false positive” fatigue of traditional tools by only alerting on exploitable, reachable code paths.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Virtual Patching:&lt;/strong&gt; Waratek RASP provides instant immunity against AI “hallucinations” and zero-days, protecting applications without requiring immediate code changes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Strategic Alignment:&lt;/strong&gt; By automating routine security checks, leaders can adjust staffing and assignments from manual remediation to active threat modeling.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The “Age of AI” has transformed the developer’s workspace. With the click of a button, LLMs can churn out thousands of lines of code, promising a future of unprecedented velocity. But for DevOps and AppSec leaders, this velocity comes with a hidden tax: &lt;em&gt;the “18-month wall.”&lt;/em&gt; Recent industry data from 2026 shows that while AI-generated code speeds up initial delivery, it compounds &lt;a href="https://www.bankinfosecurity.com/mythos-level-ai-creating-tech-debt-crisis-a-31750"&gt;technical debt&lt;/a&gt; at twice the rate of human-written code.&lt;/p&gt;</description></item><item><title>Mythos Doesn’t Need CVEs: Defending against AI Zero-Days</title><link>https://waratek.com/blogs/mythos-doesnt-need-cves-defending-against-ai-zero-days/</link><pubDate>Wed, 20 May 2026 00:14:22 +0000</pubDate><guid>https://waratek.com/blogs/mythos-doesnt-need-cves-defending-against-ai-zero-days/</guid><description>&lt;p&gt;The arrival of Anthropic’s Claude Mythos marks the end of the “Human Era” of cybersecurity. This post explores how Mythos utilizes agentic iteration to collapse the exploit development timeline from weeks to minutes, rendering traditional patching cycles obsolete and necessitating a shift toward runtime virtual patching.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Who Should Read:&lt;/strong&gt; CISOs, DevSecOps Engineers, and Vulnerability Management Leads grappling with the acceleration of AI-driven threats.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Read Time:&lt;/strong&gt; 4 minutes&lt;/p&gt;
&lt;h2 id="highlights"&gt;Highlights:&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Agentic Iteration:&lt;/strong&gt; How Mythos autonomously spins up sandboxes to refine exploits.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The Collapsed Timeline:&lt;/strong&gt; Explaining the formula &lt;em&gt;Time to Exploit ≈ Time to Inference + Time to Execution Test&lt;/em&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Virtual Patching:&lt;/strong&gt; How Waratek RASP secures the JVM level without requiring code changes.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The “Permit List” Strategy:&lt;/strong&gt; Neutralizing zero-days in obscure libraries via runtime boundaries.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="the-engineering-reality-of-machine-speed-exploitation"&gt;The Engineering Reality of “Machine-Speed” Exploitation&lt;/h2&gt;
&lt;p&gt;The pending release of Anthropic’s Claude Mythos represents a paradigm shift in automated vulnerability research (AVR). Unlike previous LLMs that hallucinated syntax or struggled with complex logic, Mythos utilizes &lt;em&gt;Agentic Iteration&lt;/em&gt;. It doesn’t just scan code; it spins up sandboxed environments, attempts exploitation, observes the crash, and refines its payload until successful.&lt;/p&gt;</description></item><item><title>Runtime Reality vs AI Hallucinations in AppSec</title><link>https://waratek.com/blogs/runtime-reality-vs-ai-hallucinations-in-appsec/</link><pubDate>Tue, 12 May 2026 23:30:35 +0000</pubDate><guid>https://waratek.com/blogs/runtime-reality-vs-ai-hallucinations-in-appsec/</guid><description>&lt;p&gt;As organizations race to integrate AI into their security workflows, hallucination tendencies of AI-driven static analysis is leading to developer fatigue and bloated backlogs. There is a solution that replaces guesswork with 100% accurate, execution-based intelligence.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;Who Should Read:&lt;/strong&gt; CISOs, AppSec Managers, Lead Developers, and DevOps Engineers tired of “vulnerability fatigue.”&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="key-highlights"&gt;Key Highlights&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;The Probabilistic Pitfall:&lt;/strong&gt; Why AI models trained on patterns rather than logic create “hallucinations” and false positives.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Runtime vs. Static:&lt;/strong&gt; The fundamental difference between guessing what code &lt;em&gt;might&lt;/em&gt; do and observing what it &lt;em&gt;actually&lt;/em&gt; does.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The Power of 100%:&lt;/strong&gt; How Waratek achieves a perfect score on the OWASP Benchmark by eliminating false positives.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Full Context Visibility:&lt;/strong&gt; Why stack traces and data flow maps are superior to simple line-number alerts.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Blind Spot Protection:&lt;/strong&gt; How to secure compiled binaries that AI scanners simply cannot read.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;In the current gold rush of Artificial Intelligence, the mantra for many security vendors has become “AI-everything.” From automated code generation to AI-enabled security scanners, the promise is clear: faster development and smarter detection. But in the world of Application Security (AppSec), speed without accuracy is just a faster way to create a backlog. As security teams integrate AI-driven Static Analysis (SAST) into their pipelines, they are running into a familiar, albeit amplified, problem: &lt;em&gt;The Hallucination Effect.&lt;/em&gt;&lt;/p&gt;</description></item><item><title>Is Your Security Blind to the Party Inside Your App?</title><link>https://waratek.com/blogs/is-your-security-blind-to-the-party-inside-your-app/</link><pubDate>Wed, 06 May 2026 08:49:04 +0000</pubDate><guid>https://waratek.com/blogs/is-your-security-blind-to-the-party-inside-your-app/</guid><description>&lt;p&gt;Imagine you’re standing in the grand foyer of a luxury hotel, staring at a pair of closed mahogany doors. Behind those doors is a gala-a complex, moving, breathing event. As an AppSec leader or developer, your job is to make sure that gala stays safe. But here’s the problem: most of your security tools are standing in the hallway with you. They’re guessing what’s happening inside based on the guest list or the noise coming through the door.&lt;/p&gt;</description></item><item><title>Why Your Security Team Needs to Move at AI Speed</title><link>https://waratek.com/blogs/why-your-security-team-needs-to-move-at-ai-speed/</link><pubDate>Wed, 29 Apr 2026 08:58:38 +0000</pubDate><guid>https://waratek.com/blogs/why-your-security-team-needs-to-move-at-ai-speed/</guid><description>&lt;p&gt;In the era of AI, new vulnerabilities and Zero-Days emerge faster than human teams can manually patch them. This is where the friction between “Dev” and “Sec” usually peaks. Security teams, tasked with risk mitigation, often demand immediate patches and service restarts. Development teams, measured by 100% uptime and feature velocity, see those restarts as a threat to their “flow” and business KPIs. Traditionally, one side has to lose.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;&lt;em&gt;The second in a two-part series.&lt;/em&gt;&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>Oracle Releases April 2026 Critical Patch Update</title><link>https://waratek.com/blogs/oracle-releases-april-2026-critical-patch-update/</link><pubDate>Wed, 22 Apr 2026 09:33:17 +0000</pubDate><guid>https://waratek.com/blogs/oracle-releases-april-2026-critical-patch-update/</guid><description>&lt;p&gt;&lt;em&gt;Oracle Communications, Fusion Middleware, MySQL, E-Business Suite and&lt;/em&gt; &lt;em&gt;Financial Services lead 483 new security patches.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;–URGENT ACTION REQUIRED–&lt;/strong&gt;&lt;/p&gt;
&lt;h2 id="highlights"&gt;Highlights&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;Oracle’s April 2026 CPU ships 483 new security patches – one of the largest CPUs on record.&lt;/li&gt;
&lt;li&gt;No CVSS 10.0 this quarter, but multiple CVSS 9.8 vulnerabilities are remotely exploitable without authentication.&lt;/li&gt;
&lt;li&gt;Fusion Middleware fixes CVE-2026-21992 (CVSS 9.8) – Oracle Identity Manager / Web Services Manager unauthenticated RCE, first shipped in the March out-of-band alert.&lt;/li&gt;
&lt;li&gt;MySQL (34), E-Business Suite (18), Financial Services and PeopleSoft (21) all receive new patches – attacker focus on EBS and Identity Manager remains elevated after Cl0p / KEV activity in late 2025.&lt;/li&gt;
&lt;li&gt;Java SE: 12 patches, 8 remotely exploitable, max CVSS 7.5 – availability impact primarily; Waratek RASP mitigates JVM-level attack classes without waiting for a full upgrade.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Action:&lt;/strong&gt; Apply the April CPU immediately on internet-facing Fusion Middleware and EBS; contact &lt;a href="mailto:customersuccess@waratek.com"&gt;customersuccess@waratek.com&lt;/a&gt; to confirm which RASP rules already cover your stack.&lt;/li&gt;
&lt;/ul&gt;
&lt;h3 id="commentary"&gt;Commentary&lt;/h3&gt;
&lt;p&gt;The Oracle Critical Patch Update (CPU) for April 2026 contains 483 new security patches addressing vulnerabilities in Oracle code and third-party components across more than two dozen product families. This is one of the largest Oracle CPUs on record and includes fixes already staged by Oracle’s out-of-band March 2026 security alert for CVE-2026-21992. Oracle strongly recommends immediate application of these patches due to continued reports of in-the-wild exploitation attempts against recent Oracle vulnerabilities.&lt;/p&gt;</description></item><item><title>Moving at the Speed of Thought &amp; No Security Debt</title><link>https://waratek.com/blogs/moving-at-the-speed-of-thought-no-security-debt/</link><pubDate>Wed, 15 Apr 2026 09:01:37 +0000</pubDate><guid>https://waratek.com/blogs/moving-at-the-speed-of-thought-no-security-debt/</guid><description>&lt;p&gt;We have entered the era of the “vibe.” AI-assisted development has fundamentally shifted the developer experience. The bottleneck is no longer “How do I write this logic?” but rather “How do I know this code won’t blow up in production?”&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;First of a two-part series.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Who Should Read:&lt;/strong&gt; CTOs, VPs of Engineering, CISOs, and AppSec Leads managing AI-integrated development lifecycles.&lt;/p&gt;
&lt;h2 id="highlights"&gt;Highlights&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;The AI Paradox:&lt;/strong&gt; AI-assisted development accelerates velocity but introduces security flaws in nearly &lt;strong&gt;45% of generated code&lt;/strong&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Vibe Coding vs. Security Gates:&lt;/strong&gt; Traditional “scan-and-wait” security can’t keep up with the fluid, “speed of thought” nature of modern development.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;The Waratek IAST Solution:&lt;/strong&gt; How Interactive Application Security Testing (IAST) provides line-of-code precision and zero false positives.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;Eliminating Debt:&lt;/strong&gt; Using a patented Data Tainting Engine to validate AI output before it enters your staging environment.&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="the-new-bottleneck-can-i-trust-this"&gt;The New Bottleneck: “Can I Trust This?”&lt;/h2&gt;
&lt;p&gt;While LLMs are exceptional at boilerplate and logic suggestions, they are notoriously “security-blind.” Recent research indicates that 45% of AI-generated code contains security flaws, ranging from insecure deserialization to classic injection vulnerabilities. When your team is moving at the speed of thought, traditional security gates don’t just feel slow-they feel obsolete.&lt;/p&gt;</description></item><item><title>Goldilocks Security: The “Just Right” AppSec Tool </title><link>https://waratek.com/blogs/goldilocks-security-the-just-right-appsec-tool/</link><pubDate>Fri, 20 Mar 2026 17:34:46 +0000</pubDate><guid>https://waratek.com/blogs/goldilocks-security-the-just-right-appsec-tool/</guid><description>&lt;p&gt;&lt;em&gt;Why SAST is too noisy, DAST is too shallow, and IAST is finally hitting the sweet spot for modern DevSecOps.&lt;/em&gt;&lt;/p&gt;
&lt;h2 id="highlights"&gt;Highlights:&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;In an environment with AI-generated code, security testing is not optional&lt;/li&gt;
&lt;li&gt;Traditional xAST tools fall short&lt;/li&gt;
&lt;li&gt;SAST reports too many false positives&lt;/li&gt;
&lt;li&gt;DAST can’t tell you why or where your code is buggy&lt;/li&gt;
&lt;li&gt;IAST in the runtime highlights accuracy and gives devs the context needed to avoid sending vulnerable &amp;amp; exploitable code into production&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;If you ask a developer why they hate security testing, you’ll usually get two answers.&lt;/p&gt;</description></item><item><title>Waratek Redefines Secure Development with Launch of Waratek IAST at JavaOne 2026</title><link>https://waratek.com/news/waratek-redefines-secure-development-with-launch-of-waratek-iast-at-javaone-2026/</link><pubDate>Fri, 20 Mar 2026 10:36:50 +0000</pubDate><guid>https://waratek.com/news/waratek-redefines-secure-development-with-launch-of-waratek-iast-at-javaone-2026/</guid><description>&lt;p&gt;&lt;strong&gt;FOR IMMEDIATE RELEASE&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;REDWOOD SHORES, Calif. - March 18, 2026&lt;/strong&gt; - Waratek, a leader in next-generation application security, today announced the official launch of Waratek IAST (Interactive Application Security Testing). The announcement was made during the JavaOne 2026 conference, where Waratek CEO Doug Ennis delivered a featured session on securing the software development lifecycle (SDLC) in the age of AI-generated code.&lt;/p&gt;
&lt;p&gt;The launch addresses a critical and growing risk for enterprises relying on Large Language Models (LLMs) to accelerate Java development. While AI boosts productivity, new data from industry leaders reveals that this increased code volume comes with a significant security trade-off, specifically for the Java language.&lt;/p&gt;</description></item><item><title>Trust, but Verify: AI Code Supply Chain Security</title><link>https://waratek.com/blogs/trust-but-verify-at-runtime-ai-code-supply-chain-security/</link><pubDate>Tue, 17 Mar 2026 16:08:01 +0000</pubDate><guid>https://waratek.com/blogs/trust-but-verify-at-runtime-ai-code-supply-chain-security/</guid><description>&lt;p&gt;In the race to modernize mission-critical Java applications, two forces are dominating the conversation: the explosive adoption of AI-generated code and the sprawling complexity of software supply chains.&lt;/p&gt;
&lt;p&gt;For decision-makers and AppSec professionals, these advancements bring speed, but they also bring a dangerous illusion of security. AI code often passes the “eye test” while harboring deep logic flaws. Simultaneously, traditional Software Composition Analysis (SCA) tools are burying teams under mountains of alerts for libraries that aren’t even being used.&lt;/p&gt;</description></item><item><title>Waratek Selected for Ireland INC US 250 Index 2024</title><link>https://waratek.com/news/waratek-selected-for-ireland-inc-us-250-index-2024/</link><pubDate>Wed, 13 Nov 2024 17:46:54 +0000</pubDate><guid>https://waratek.com/news/waratek-selected-for-ireland-inc-us-250-index-2024/</guid><description>&lt;p&gt;&lt;em&gt;November 13th, 2024&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;We’re thrilled to share that Waratek has been included in the &lt;a href="https://irelandinc.com/download-ireland-inc-index-250-2023/"&gt;&lt;strong&gt;Ireland INC US 250 Index 2024&lt;/strong&gt;&lt;/a&gt;, a special report curated by &lt;strong&gt;Business &amp;amp; Finance Magazine&lt;/strong&gt; which showcases 250 leading Irish companies that are actively investing in the United States. This annual index highlights the contributions of Irish companies that are driving economic growth, creating jobs, and fostering innovation across the Atlantic.&lt;/p&gt;
&lt;p&gt;The Ireland INC US 250 Index celebrates a remarkable year of growth in Irish foreign direct investment (FDI) in the US. As of 2023, Irish companies have invested a record &lt;strong&gt;$240 billion&lt;/strong&gt; in the US economy. The impact of this investment is far-reaching, with nearly &lt;strong&gt;100,000 US workers&lt;/strong&gt; employed by the US affiliates of Irish-owned companies and a presence in over &lt;strong&gt;2,200 locations&lt;/strong&gt; across the country. Approximately &lt;strong&gt;900 Irish companies&lt;/strong&gt; export to the US, supporting vital industries across technology, healthcare, financial services, and more.&lt;/p&gt;</description></item><item><title/><link>https://waratek.com/cve/cve-2017-5638/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2017-5638/</guid><description>The Jakarta-based Multipart parser in Struts 2 mishandles errors during file uploads: a crafted Content-Type, Content-Disposition, or Content-Length header triggers an exception whose message is evaluated as an OGNL expression, letting an unauthenticated remote attacker execute arbitrary commands. This is the vulnerability behind the 2017 Equifax data breach.</description></item><item><title/><link>https://waratek.com/cve/cve-2017-7525/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2017-7525/</guid><description>When jackson-databind&amp;rsquo;s default typing is enabled, ObjectMapper.readValue can be pointed at attacker-supplied JSON that instantiates arbitrary gadget classes during deserialization. An unauthenticated attacker who controls input reaching readValue can chain these gadgets into remote code execution.</description></item><item><title/><link>https://waratek.com/cve/cve-2017-9805/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2017-9805/</guid><description>The Struts REST Plugin deserializes XML payloads using an XStreamHandler backed by XStream, without any type filtering. An attacker can submit a crafted XML payload to the REST endpoint to achieve remote code execution.</description></item><item><title/><link>https://waratek.com/cve/cve-2018-11776/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2018-11776/</guid><description>When alwaysSelectFullNamespace is enabled (directly, or via a plugin such as the Convention Plugin) and results, url tags, or actions omit a namespace while an ancestor package uses no or a wildcard namespace, Struts evaluates attacker-controlled input as an OGNL expression, leading to remote code execution.</description></item><item><title/><link>https://waratek.com/cve/cve-2018-1260/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2018-1260/</guid><description>Spring Security OAuth evaluates part of the authorization request as a Spring Expression Language (SpEL) expression when the resource owner is redirected to the approval endpoint. An attacker who crafts a malicious authorization request can smuggle a SpEL payload through that flow and have it evaluated by the server, achieving unauthenticated remote code execution against any application built on the vulnerable OAuth2 authorization server.</description></item><item><title/><link>https://waratek.com/cve/cve-2018-2628/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2018-2628/</guid><description>An unauthenticated attacker with network access to the T3 protocol can send a crafted serialized object to Oracle WebLogic Server, triggering unsafe deserialization that leads to full remote code execution and takeover of the server.</description></item><item><title/><link>https://waratek.com/cve/cve-2020-14882/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2020-14882/</guid><description>A crafted URL path lets an unauthenticated attacker bypass the access controls protecting WebLogic&amp;rsquo;s Administration Console, reaching internal console handlers that were never meant to be exposed. Combined with a follow-on request, this grants full unauthenticated remote code execution and has been mass-exploited in the wild.</description></item><item><title/><link>https://waratek.com/cve/cve-2020-9484/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2020-9484/</guid><description>When Tomcat is configured to use the PersistenceManager with a FileStore and a lax sessionAttributeValueClassNameFilter, an attacker who can place a crafted file at a known relative path can trigger remote code execution through deserialization of session data.</description></item><item><title/><link>https://waratek.com/cve/cve-2021-27568/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2021-27568/</guid><description>json-smart&amp;rsquo;s parser throws a NumberFormatException on certain malformed numeric input but callers never catch it. Because json-smart sits underneath Nimbus JOSE+JWT in many JWT validation stacks, an attacker can send a crafted token or payload that crashes the parsing application or leaks internal state through the uncaught exception.</description></item><item><title/><link>https://waratek.com/cve/cve-2021-4104/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2021-4104/</guid><description>When Log4j 1.2 is specifically configured to use JMSAppender, an attacker with write access to the logging configuration can set TopicBindingName and TopicConnectionFactoryBindingName to point at an attacker-controlled JNDI resource, resulting in remote code execution similar to Log4Shell.</description></item><item><title/><link>https://waratek.com/cve/cve-2021-44228/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2021-44228/</guid><description>Apache Log4j 2 evaluates attacker-controlled ${jndi:&amp;hellip;} lookups inside logged strings. Any input that reaches a log statement can force the JVM to fetch and execute code from a remote LDAP or RMI server, giving an unauthenticated attacker full remote code execution.</description></item><item><title/><link>https://waratek.com/cve/cve-2021-44832/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2021-44832/</guid><description>Log4j configurations that use a JDBC Appender with a JNDI LDAP data source URI let an attacker who controls the target LDAP server return a malicious reference. When the appender resolves that data source, Log4j loads and executes attacker-supplied code, giving remote code execution even after the earlier Log4Shell fixes.</description></item><item><title/><link>https://waratek.com/cve/cve-2021-45046/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2021-45046/</guid><description>The 2.15.0 patch for Log4Shell (CVE-2021-44228) disabled the default JNDI lookup pattern but left non-default configurations exposed: when Pattern Layout uses a Context Lookup or a Thread Context Map pattern, attacker-controlled MDC input can still smuggle a JNDI lookup through and trigger remote code execution or information leakage.</description></item><item><title/><link>https://waratek.com/cve/cve-2021-45105/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2021-45105/</guid><description>Log4j2 did not guard against uncontrolled recursion from self-referential lookups. An attacker who controls Thread Context Map data can craft a string that triggers infinite recursion, crashing the application - a follow-on issue from the original Log4Shell disclosure.</description></item><item><title/><link>https://waratek.com/cve/cve-2022-21371/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2022-21371/</guid><description>A crafted HTTP request lets an unauthenticated attacker traverse outside the intended web root and read arbitrary files accessible to the WebLogic Server process. There is no authentication requirement and the flaw is easily exploitable over the network, giving attackers a low-effort path to config files, credentials, and other sensitive data on the server.</description></item><item><title/><link>https://waratek.com/cve/cve-2022-22963/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2022-22963/</guid><description>Spring Cloud Function&amp;rsquo;s routing functionality evaluates a user-supplied routing-expression as a Spring Expression Language (SpEL) string. An attacker can craft a malicious SpEL expression in a request header to achieve remote code execution and access local resources.</description></item><item><title/><link>https://waratek.com/cve/cve-2022-22965/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2022-22965/</guid><description>Spring MVC and WebFlux applications on JDK 9+ can be tricked, through HTTP request-parameter data binding, into reaching the class loader of a bean. An attacker can rewrite Tomcat logging properties to drop and execute a web shell, achieving remote code execution against a WAR-deployed app.</description></item><item><title/><link>https://waratek.com/cve/cve-2022-42889/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2022-42889/</guid><description>Apache Commons Text enables variable interpolation of the form ${prefix:name}. In affected versions the default lookups include &amp;ldquo;script&amp;rdquo;, &amp;ldquo;dns&amp;rdquo; and &amp;ldquo;url&amp;rdquo;, so untrusted input passed to the interpolator can execute arbitrary code through the JVM script engine or reach attacker-controlled servers.</description></item><item><title/><link>https://waratek.com/cve/cve-2022-42920/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2022-42920/</guid><description>Several Commons BCEL APIs that are meant to only tweak specific, narrow class characteristics have an out-of-bounds write defect that lets them be abused to produce arbitrary Java bytecode instead. An application that passes attacker-controllable data into these APIs gives the attacker far more control over the generated class than intended, letting a crafted class be loaded and executed for remote code execution.</description></item><item><title/><link>https://waratek.com/cve/cve-2024-21287/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2024-21287/</guid><description>Oracle Agile PLM&amp;rsquo;s Process Extension SDK component fails to properly enforce authorization on requests that reference file attachments, letting an unauthenticated attacker with network access retrieve arbitrary files and sensitive data from the server over HTTP. CISA added this vulnerability to its Known Exploited Vulnerabilities catalog after confirming active attacks in the wild.</description></item><item><title/><link>https://waratek.com/cve/cve-2025-21587/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2025-21587/</guid><description>A flaw in the JSSE component of Oracle Java SE and GraalVM lets an unauthenticated attacker with network access, over multiple protocols, compromise the JVM through APIs exposed in that component. Oracle rates it difficult to exploit, but a successful attack grants full read and write access to all data the JVM can reach, making it a critical patch-cadence item for any internet-facing Java service.</description></item><item><title/><link>https://waratek.com/cve/cve-2025-30761/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/cve/cve-2025-30761/</guid><description>A flaw in the Scripting component of Oracle Java SE and GraalVM Enterprise Edition lets an unauthenticated attacker with network access compromise the JVM, most commonly through a sandboxed Java Web Start application or applet that loads untrusted code from the internet. A successful attack lets the attacker create, delete, or modify data the JVM has access to, without needing any credentials.</description></item><item><title>About</title><link>https://waratek.com/about/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/about/</guid><description>&lt;section class="page-hero"&gt;
 &lt;h1 class="statement"&gt;We're the industry's only unified runtime platform designed to &lt;em class="accent"&gt;Shift Left with IAST&lt;/em&gt; and &lt;em class="accent"&gt;Shield Right with RASP&lt;/em&gt;. We eliminate the "Protection Gap" by embedding security directly into your application's execution environment in development and production.&lt;/h1&gt;
&lt;/section&gt;

&lt;section class="cards-section"&gt;
 &lt;div class="panel"&gt;
 &lt;h2&gt;Meet the Team&lt;/h2&gt;
 &lt;div class="team-grid"&gt;
 &lt;div class="team-card"&gt;
 &lt;img
 src="https://waratek.com/wp-content/uploads/2026/03/Doug_2026-Headshot.jpeg"
 alt="Doug Ennis"
 width="160"
 height="160"
 sizes="160px"
 srcset="auto"
 &gt;
 &lt;h3&gt;Doug Ennis&lt;br&gt;Executive Chair &amp;amp; CEO&lt;/h3&gt;
 &lt;p&gt;As the Chief Executive Officer of Waratek, Doug leads a global team of experts to deliver innovative and effective solutions for securing mission-critical applications.&lt;/p&gt;
 &lt;/div&gt;

 &lt;div class="team-card"&gt;
 &lt;img
 src="https://waratek.com/wp-content/uploads/2022/10/padraic.jpg"
 alt="Padraic Gaffney"
 width="160"
 height="160"
 sizes="160px"
 srcset="auto"
 &gt;
 &lt;h3&gt;Padraic Gaffney&lt;br&gt;Chief Financial Officer&lt;/h3&gt;
 &lt;p&gt;Padraic brings 20+ years' experience in finance, accounting, and strategic planning at start-ups and SMB's. Padraic is also responsible for legal and corporate secretarial.&lt;/p&gt;</description></item><item><title>Blog-Page</title><link>https://waratek.com/blog-page/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/blog-page/</guid><description>&lt;!--WT_DYNAMIC:blog-page-posts.html--&gt;</description></item><item><title>FAQs</title><link>https://waratek.com/faqs/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/faqs/</guid><description>&lt;section class="page-hero"&gt;
 &lt;h1&gt;FAQs&lt;/h1&gt;

 &lt;div class="faq-group"&gt;
 &lt;h2 class="faq-label"&gt;Waratek IAST&lt;/h2&gt;
 &lt;div class="accordion"&gt;
 &lt;details&gt;
 &lt;summary&gt;What makes Waratek IAST different from traditional DAST or SAST?&lt;/summary&gt;
 &lt;p&gt;Unlike SAST (which looks at idle code) or DAST (which probes from the outside), Waratek IAST works from within the application. It uses runtime instrumentation to observe data flow and execution paths in real-time, providing the precision of code-level analysis with the functional context of a live attack.&lt;/p&gt;
 &lt;/details&gt;
 &lt;details&gt;
 &lt;summary&gt;How does Waratek IAST handle false positives?&lt;/summary&gt;
 &lt;p&gt;Because Waratek operates inside the JVM, it only flags vulnerabilities that are actually reachable and executable in a running environment. This results in near-zero false positives, allowing your team to focus on legitimate risks rather than chasing "ghost" vulnerabilities.&lt;/p&gt;</description></item><item><title>IAST</title><link>https://waratek.com/iast/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/iast/</guid><description>&lt;section class="page-hero"&gt;
 &lt;h1&gt;Secure &lt;em class="accent"&gt;AI-Generated Code&lt;/em&gt; at the Speed of Development&lt;/h1&gt;
 &lt;p class="page-hero-lead"&gt;Using AI to accelerate software delivery solves one problem - coding time - but it creates a new challenge: securing code that humans didn't write.&lt;/p&gt;

 &lt;div class="card"&gt;
 &lt;div&gt;
 &lt;h2&gt;Waratek IAST provides the critical safety net for AI-driven development:&lt;/h2&gt;
 &lt;p&gt;AI-generated code often introduces subtle vulnerabilities, insecure defaults, and complex logic flaws that traditional security tools struggle to detect and humans struggle to review.&lt;/p&gt;
 &lt;ul class="benefits"&gt;
 &lt;li&gt;&lt;strong&gt;Eliminate AI Hallucinations:&lt;/strong&gt; Validate that AI-suggested libraries and coding patterns are secure within your specific runtime environment.&lt;/li&gt;
 &lt;li&gt;&lt;strong&gt;Zero-Gap Coverage:&lt;/strong&gt; Waratek IAST monitors the actual behavior of the code, catching real vulnerabilities as they manifest during execution that other testing tools miss due to lack of runtime visibility.&lt;/li&gt;
 &lt;li&gt;&lt;strong&gt;Developer-First Feedback:&lt;/strong&gt; Provide your team with instant, high-fidelity alerts with context-rich metadata. If the AI writes a vulnerability that is exploitable, Waratek finds it during the first test run, complete with the stack trace needed to remediate it.&lt;/li&gt;
 &lt;/ul&gt;
 &lt;/div&gt;
 &lt;div class="card-images"&gt;
 &lt;div class="card-photo-stack"&gt;
 &lt;img src="https://waratek.com/images/pages/ai-generated-code-security.png" srcset="auto" sizes="(max-width: 640px) 100vw, 400px" alt="Humanoid AI robot writing code on holographic screens in a data center" width="2560" height="1396"&gt;
 &lt;img src="https://waratek.com/images/pages/ai-hallucination-developer.jpg" srcset="auto" sizes="(max-width: 640px) 100vw, 400px" alt="Robot developer gazing at a fantasy oasis rendered on its monitor - an AI coding hallucination" width="2560" height="1396"&gt;
 &lt;/div&gt;
 &lt;/div&gt;
 &lt;/div&gt;

 &lt;div class="card"&gt;
 &lt;div&gt;
 &lt;h2&gt;Waratek IAST Outperforms the Rest&lt;/h2&gt;
 &lt;ul class="benefits"&gt;
 &lt;li&gt;&lt;strong&gt;SAST (Static Analysis):&lt;/strong&gt; Scans dead code, resulting in high false-positive rates and "vulnerability fatigue" for developers. It cannot see how code behaves in production.&lt;/li&gt;
 &lt;li&gt;&lt;strong&gt;DAST (Dynamic Analysis):&lt;/strong&gt; Acts as a "black box" that crawls the outside of an app. It misses deep logic flaws and provides no code-level visibility for fixes.&lt;/li&gt;
 &lt;/ul&gt;
 &lt;/div&gt;
 &lt;img src="https://waratek.com/images/pages/choosing-appsec-testing-tools.png" srcset="auto" sizes="(max-width: 640px) 100vw, 400px" alt="Shopper facing supermarket shelves of near-identical cereal boxes labeled SAST Flakes - choosing between lookalike AppSec testing tools" width="2560" height="1396"&gt;
 &lt;/div&gt;
&lt;/section&gt;

&lt;section class="cards-section"&gt;
 &lt;div class="card card-reverse"&gt;
 &lt;img src="https://waratek.com/wp-content/uploads/2026/03/shutterstock_2304768471.jpg" srcset="auto" sizes="(max-width: 640px) 100vw, 400px" alt="Dart striking the bullseye of a target mounted on a laptop screen - representing precise, accurate testing results" width="1000" height="600"&gt;
 &lt;div&gt;
 &lt;h2&gt;Why is Waratek IAST a more accurate testing tool?&lt;/h2&gt;
 &lt;p&gt;Waratek IAST outperforms traditional SAST and DAST by monitoring the application during actual execution. This "Interactive" approach eliminates the noise of false positives, allowing developers to focus on real risks.&lt;/p&gt;</description></item><item><title>IAST+RASP</title><link>https://waratek.com/iast-rasp/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/iast-rasp/</guid><description>&lt;section class="page-hero"&gt;
 &lt;h1&gt;The Perfect Security Combo:&lt;br&gt;&lt;em class="accent"&gt;IAST + RASP&lt;/em&gt;&lt;/h1&gt;
 &lt;p class="page-hero-lead"&gt;By combining Shift Left and Shield Right strategies, Waratek creates a self-reinforcing security ecosystem.&lt;/p&gt;

 &lt;div class="card"&gt;
 &lt;div&gt;
 &lt;h2&gt;What are the benefits of combining IAST and RASP?&lt;/h2&gt;
 &lt;p&gt;&lt;strong&gt;Intelligence Sharing:&lt;/strong&gt; Vulnerabilities found by IAST help inform RASP's protection rules.&lt;/p&gt;
 &lt;p&gt;&lt;strong&gt;Reduced Security Debt:&lt;/strong&gt; Shield vulnerabilities in production while developers fix them in the next sprint.&lt;/p&gt;
 &lt;p&gt;&lt;strong&gt;Continuous Compliance:&lt;/strong&gt; Real-time documentation for PCI DSS, HIPAA, and GDPR.&lt;/p&gt;
 &lt;/div&gt;
 &lt;img src="https://waratek.com/wp-content/uploads/2026/03/shutterstock_2200985385.jpg" srcset="auto" sizes="(max-width: 640px) 100vw, 400px" alt="Glowing infinity loop of connected security icons - representing the continuous feedback cycle between IAST and RASP" width="1000" height="604"&gt;
 &lt;/div&gt;
&lt;/section&gt;

&lt;section class="cards-section"&gt;
 &lt;div class="card card-reverse"&gt;
 &lt;img src="https://waratek.com/wp-content/uploads/2026/03/shutterstock_2045107499.jpg" srcset="auto" sizes="(max-width: 640px) 100vw, 400px" alt="One rocket breaking ahead of a uniform grid of hexagon blocks - representing a strategic competitive advantage" width="1000" height="632"&gt;
 &lt;div&gt;
 &lt;h2&gt;Strategic Advantage for CISOs&lt;/h2&gt;
 &lt;p&gt;Waratek IAST outperforms traditional SAST and DAST by monitoring the application during actual execution. This "Interactive" approach eliminates the noise of false positives, allowing developers to focus on real risks.&lt;/p&gt;</description></item><item><title>Legal</title><link>https://waratek.com/legal/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/legal/</guid><description>&lt;section class="page-hero"&gt;
 &lt;h1&gt;Legal&lt;/h1&gt;

 &lt;div class="faq-group"&gt;
 &lt;h2 class="faq-label"&gt;Terms of Use&lt;/h2&gt;
 &lt;div class="accordion"&gt;
 &lt;details&gt;
 &lt;summary&gt;&lt;strong&gt;Trademarks&lt;/strong&gt;&lt;/summary&gt;
 &lt;p&gt;The following are trademarks of Waratek Limited and may not be used without written permission:&lt;/p&gt;
 &lt;p&gt;Waratek®, Replicode®, CloudVM™, Waratek AppSecurity for Java™, Waratek Locker™, ElastiCat™, Waratek Patch™, Waratek Secure™, Waratek Upgrade™,Waratek Enterprise™, Waratek ARMR™,Name Space Layout Randomization (NSLR)™, Waratek Security Rules Editor™, Java Virtual Container™, Secure Java Container™, BYOS™, jSleep™, JMotion™, Jirsh™, JMirror™ and JHybernate™&lt;/p&gt;
 &lt;/details&gt;
 &lt;details&gt;
 &lt;summary&gt;&lt;strong&gt;Governance&lt;/strong&gt;&lt;/summary&gt;
 &lt;p&gt;Waratek Ltd is an Irish private limited company based in Dublin, Ireland.&lt;/p&gt;</description></item><item><title>RASP</title><link>https://waratek.com/rasp/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/rasp/</guid><description>&lt;section class="page-hero"&gt;
 &lt;h1&gt;Waratek RASP: Adaptive &lt;em class="accent"&gt;Shield Right&lt;/em&gt; Defense&lt;/h1&gt;
 &lt;p class="page-hero-lead"&gt;Protect Your Production with Autonomous RASP.&lt;br&gt;&lt;br&gt;Waratek RASP (Runtime Application Self-Protection) provides a "Shield Right" defense that observes how application code executes and blocks any attempt to alter its intended behavior.&lt;/p&gt;

 &lt;div class="card"&gt;
 &lt;div&gt;
 &lt;h2&gt;How does RASP block AI-driven attacks?&lt;/h2&gt;
 &lt;p&gt;Modern AI-driven and "Agentic" threats use polymorphic techniques to bypass traditional signatures. Waratek RASP is immune to these tactics because it monitors execution intent.&lt;/p&gt;
 &lt;p&gt;&lt;strong&gt;Behavioral Observation:&lt;/strong&gt; RASP tracks how the code should run.&lt;/p&gt;</description></item><item><title>Request a Demo</title><link>https://waratek.com/request-a-demo/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://waratek.com/request-a-demo/</guid><description>&lt;style&gt;
 .wt-demo {
 --coral: #ff887c;
 --magenta: #b6325f;
 --navy: #171d24;
 --navy2: #171431;
 --white: #ffffff;
 --off-white: #f2f2f2;
 --text: #1e2230;
 --muted: #6b7280;
 --border: #e4e4e8;
 --grad: linear-gradient(135deg, var(--coral) 0%, var(--magenta) 100%);
 --radius: 12px;
 --shadow: 0 4px 28px rgba(0, 0, 0, 0.09);
 line-height: 1.6;
 }
 .wt-demo *,
 .wt-demo *::before,
 .wt-demo *::after {
 box-sizing: border-box;
 }

 /* ── HERO ── */
 .wt-demo .hero {
 background-color: var(--navy);
 background-image:
 repeating-linear-gradient(
 45deg,
 rgba(182, 50, 95, 0.07) 0px,
 rgba(182, 50, 95, 0.07) 1px,
 transparent 1px,
 transparent 28px
 ),
 repeating-linear-gradient(
 -45deg,
 rgba(182, 50, 95, 0.07) 0px,
 rgba(182, 50, 95, 0.07) 1px,
 transparent 1px,
 transparent 28px
 ),
 radial-gradient(ellipse at 80% 50%, rgba(182, 50, 95, 0.18) 0%, transparent 60%);
 color: var(--white);
 text-align: center;
 padding: 88px 24px 80px;
 }
 .wt-demo .hero-eyebrow {
 display: inline-block;
 font-size: 0.7rem;
 font-weight: 700;
 letter-spacing: 2px;
 text-transform: uppercase;
 color: var(--coral);
 border: 1px solid rgba(255, 136, 124, 0.4);
 background: rgba(255, 136, 124, 0.08);
 padding: 6px 18px;
 border-radius: 100px;
 margin-bottom: 26px;
 }
 .wt-demo .hero h1 {
 font-size: clamp(2rem, 4.5vw, 3.1rem);
 font-weight: 800;
 line-height: 1.15;
 max-width: 820px;
 margin: 0 auto 20px;
 letter-spacing: -0.3px;
 color: var(--white);
 }
 .wt-demo .hero h1 .grad-text {
 background: var(--grad);
 -webkit-background-clip: text;
 -webkit-text-fill-color: transparent;
 background-clip: text;
 }
 .wt-demo .hero-sub {
 font-size: 1.1rem;
 color: rgba(255, 255, 255, 0.65);
 max-width: 580px;
 margin: 0 auto 16px;
 font-weight: 300;
 }
 .wt-demo .hero-tagline {
 font-size: 0.85rem;
 color: var(--coral);
 font-weight: 600;
 letter-spacing: 0.5px;
 margin-bottom: 36px;
 }
 .wt-demo .hero-btn {
 display: inline-block;
 background: var(--grad);
 color: var(--white) !important;
 font-weight: 700;
 font-size: 1rem;
 padding: 16px 38px;
 border-radius: 8px;
 text-decoration: none;
 box-shadow: 0 6px 24px rgba(182, 50, 95, 0.45);
 transition:
 opacity 0.2s,
 transform 0.15s;
 }
 .wt-demo .hero-btn:hover {
 opacity: 0.9;
 transform: translateY(-2px);
 }

 /* ── PRODUCTS ── */
 .wt-demo .products {
 padding: 72px 24px;
 background: var(--off-white);
 }
 .wt-demo .products-inner {
 max-width: 1100px;
 margin: 0 auto;
 }
 .wt-demo .section-eyebrow {
 font-size: 0.68rem;
 font-weight: 700;
 letter-spacing: 2px;
 text-transform: uppercase;
 color: var(--magenta);
 border-left: 3px solid var(--magenta);
 padding-left: 10px;
 margin-bottom: 10px;
 }
 .wt-demo .section-title {
 font-size: clamp(1.5rem, 3vw, 2.1rem);
 font-weight: 800;
 color: var(--navy);
 margin-bottom: 10px;
 line-height: 1.2;
 }
 .wt-demo .section-sub {
 font-size: 1rem;
 color: var(--muted);
 max-width: 620px;
 margin-bottom: 52px;
 font-weight: 400;
 }
 .wt-demo .products-grid {
 display: grid;
 grid-template-columns: repeat(auto-fit, minmax(300px, 1fr));
 gap: 28px;
 }
 .wt-demo .card {
 background: var(--white);
 border-radius: var(--radius);
 box-shadow: var(--shadow);
 border: 1px solid var(--border);
 overflow: hidden;
 display: flex;
 flex-direction: column;
 align-items: stretch;
 gap: 0;
 max-width: none;
 margin: 0;
 padding: 0;
 text-align: left;
 transition:
 transform 0.2s,
 box-shadow 0.2s;
 }
 .wt-demo .card:hover {
 transform: translateY(-5px);
 box-shadow: 0 14px 40px rgba(0, 0, 0, 0.13);
 }
 .wt-demo .card.featured {
 border: 2px solid transparent;
 background:
 linear-gradient(white, white) padding-box,
 var(--grad) border-box;
 position: relative;
 }
 .wt-demo .featured-badge {
 position: absolute;
 top: 0;
 right: 0;
 background: var(--grad);
 color: white;
 font-size: 0.62rem;
 font-weight: 700;
 letter-spacing: 1.2px;
 text-transform: uppercase;
 padding: 5px 14px;
 border-bottom-left-radius: 8px;
 }
 .wt-demo .card-header {
 background: var(--navy);
 padding: 28px 28px 22px;
 flex: 0 0 auto;
 }
 .wt-demo .card-label {
 font-size: 0.65rem;
 font-weight: 700;
 letter-spacing: 2px;
 text-transform: uppercase;
 color: var(--coral);
 margin-bottom: 8px;
 }
 .wt-demo .card-header h3 {
 font-size: 1.3rem;
 font-weight: 800;
 color: var(--white);
 margin-bottom: 8px;
 }
 .wt-demo .card-tagline {
 font-size: 0.85rem;
 color: rgba(255, 255, 255, 0.55);
 font-style: italic;
 font-weight: 300;
 }
 .wt-demo .card-body {
 padding: 28px;
 flex: 1;
 display: flex;
 flex-direction: column;
 }
 .wt-demo .card-desc {
 font-size: 0.92rem;
 color: var(--text);
 margin-bottom: 24px;
 line-height: 1.75;
 font-weight: 400;
 }
 .wt-demo .benefit-list {
 list-style: none;
 margin-bottom: 28px;
 padding: 0;
 display: flex;
 flex-direction: column;
 gap: 10px;
 }
 .wt-demo .benefit-list li {
 display: flex;
 align-items: flex-start;
 gap: 10px;
 font-size: 0.88rem;
 color: var(--text);
 line-height: 1.5;
 }
 .wt-demo .benefit-list li::before {
 content: "";
 display: inline-block;
 width: 18px;
 height: 18px;
 min-width: 18px;
 margin-top: 1px;
 background: var(--grad);
 border-radius: 50%;
 background-image: url("data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' viewBox='0 0 18 18'%3E%3Cpath d='M4 9l3.5 3.5L14 6' stroke='white' stroke-width='2' fill='none' stroke-linecap='round' stroke-linejoin='round'/%3E%3C/svg%3E");
 background-repeat: no-repeat;
 background-size: 18px 18px;
 }
 .wt-demo .card-cta {
 display: block;
 text-align: center;
 background: var(--navy);
 color: var(--white);
 font-weight: 600;
 font-size: 0.88rem;
 padding: 13px;
 border-radius: 8px;
 text-decoration: none;
 margin-top: auto;
 transition:
 background 0.2s,
 opacity 0.2s;
 }
 .wt-demo .card-cta:hover {
 opacity: 0.85;
 }
 .wt-demo .card.featured .card-cta {
 background: var(--grad);
 color: var(--white);
 }

 /* ── TRUST BAR ── */
 .wt-demo .trust {
 background: var(--navy2);
 padding: 40px 24px;
 text-align: center;
 }
 .wt-demo .trust p {
 font-size: 0.7rem;
 font-weight: 700;
 letter-spacing: 2px;
 text-transform: uppercase;
 color: rgba(255, 255, 255, 0.4);
 margin-bottom: 24px;
 }
 .wt-demo .trust-stats {
 display: flex;
 flex-wrap: wrap;
 justify-content: center;
 gap: 48px;
 }
 .wt-demo .stat .num {
 font-size: 2rem;
 font-weight: 800;
 background: var(--grad);
 -webkit-background-clip: text;
 -webkit-text-fill-color: transparent;
 background-clip: text;
 display: block;
 line-height: 1.1;
 }
 .wt-demo .stat .label {
 font-size: 0.78rem;
 color: rgba(255, 255, 255, 0.5);
 margin-top: 4px;
 font-weight: 400;
 }

 /* ── FORM SECTION ── */
 .wt-demo .form-section {
 padding: 72px 24px;
 background: var(--white);
 }
 .wt-demo .form-wrap {
 max-width: 980px;
 margin: 0 auto;
 display: grid;
 grid-template-columns: 1fr 1fr;
 gap: 60px;
 align-items: start;
 }
 @media (max-width: 720px) {
 .wt-demo .form-wrap {
 grid-template-columns: 1fr;
 }
 }
 .wt-demo .form-left .section-eyebrow {
 margin-bottom: 12px;
 }
 .wt-demo .form-left h2 {
 font-size: clamp(1.5rem, 3vw, 2rem);
 font-weight: 800;
 color: var(--navy);
 margin-bottom: 16px;
 line-height: 1.2;
 }
 .wt-demo .form-left p {
 font-size: 0.95rem;
 color: var(--muted);
 margin-bottom: 28px;
 line-height: 1.7;
 font-weight: 400;
 }
 .wt-demo .expect-title {
 font-size: 0.7rem;
 font-weight: 700;
 text-transform: uppercase;
 letter-spacing: 1.5px;
 color: var(--navy);
 margin-bottom: 14px;
 }
 .wt-demo .expect-list {
 list-style: none;
 padding: 0;
 display: flex;
 flex-direction: column;
 gap: 12px;
 }
 .wt-demo .expect-list li {
 display: flex;
 align-items: flex-start;
 gap: 12px;
 font-size: 0.88rem;
 color: var(--text);
 line-height: 1.5;
 }
 .wt-demo .expect-icon {
 width: 30px;
 height: 30px;
 min-width: 30px;
 background: var(--grad);
 border-radius: 50%;
 display: flex;
 align-items: center;
 justify-content: center;
 font-size: 0.85rem;
 }
 .wt-demo .form-right {
 background: var(--navy);
 border-radius: var(--radius);
 padding: 36px;
 position: relative;
 overflow: hidden;
 }
 .wt-demo .form-right::before {
 content: "";
 position: absolute;
 top: 0;
 right: 0;
 bottom: 0;
 left: 0;
 background-image:
 repeating-linear-gradient(
 45deg,
 rgba(182, 50, 95, 0.06) 0px,
 rgba(182, 50, 95, 0.06) 1px,
 transparent 1px,
 transparent 24px
 ),
 repeating-linear-gradient(
 -45deg,
 rgba(182, 50, 95, 0.06) 0px,
 rgba(182, 50, 95, 0.06) 1px,
 transparent 1px,
 transparent 24px
 );
 pointer-events: none;
 }
 .wt-demo .form-right h3 {
 font-size: 1.15rem;
 font-weight: 700;
 color: var(--white);
 margin-bottom: 6px;
 position: relative;
 }
 .wt-demo .form-right .form-subtitle {
 font-size: 0.8rem;
 color: rgba(255, 255, 255, 0.45);
 margin-bottom: 24px;
 font-weight: 400;
 position: relative;
 }
 .wt-demo .form-group {
 margin-bottom: 16px;
 position: relative;
 }
 .wt-demo .form-row {
 display: grid;
 grid-template-columns: 1fr 1fr;
 gap: 14px;
 }
 @media (max-width: 420px) {
 .wt-demo .form-row {
 grid-template-columns: 1fr;
 }
 }
 /* Honeypot - visually hidden but still present in the DOM for bots. */
 .wt-demo .hp-field {
 position: absolute;
 left: -9999px;
 width: 1px;
 height: 1px;
 overflow: hidden;
 }
 .wt-demo label {
 display: block;
 font-size: 0.78rem;
 font-weight: 600;
 color: rgba(255, 255, 255, 0.75);
 margin-bottom: 6px;
 }
 .wt-demo label .req {
 color: var(--coral);
 }
 .wt-demo label .opt {
 color: rgba(255, 255, 255, 0.35);
 font-weight: 400;
 font-size: 0.72rem;
 }
 .wt-demo input,
 .wt-demo select {
 width: 100%;
 padding: 11px 14px;
 background: rgba(255, 255, 255, 0.07);
 border: 1.5px solid rgba(255, 255, 255, 0.15);
 border-radius: 7px;
 font-family: inherit;
 font-size: 0.88rem;
 color: var(--white);
 transition:
 border-color 0.2s,
 background 0.2s;
 appearance: none;
 position: relative;
 }
 /* !important required to beat a global `::placeholder { ... !important }`
 in the migrated SeedProd style-global.css, which otherwise forces a dark
 placeholder color onto these inputs sitting on a dark background. */
 .wt-demo input::placeholder {
 color: rgba(255, 255, 255, 0.4) !important;
 }
 .wt-demo input:focus,
 .wt-demo select:focus {
 outline: none;
 border-color: var(--coral);
 background: rgba(255, 136, 124, 0.07);
 }
 .wt-demo select {
 background-image: url("data:image/svg+xml,%3Csvg xmlns='http://www.w3.org/2000/svg' width='12' height='8' viewBox='0 0 12 8'%3E%3Cpath d='M1 1l5 5 5-5' stroke='rgba(255,255,255,0.5)' stroke-width='1.5' fill='none' stroke-linecap='round'/%3E%3C/svg%3E");
 background-repeat: no-repeat;
 background-position: right 14px center;
 padding-right: 36px;
 cursor: pointer;
 }
 .wt-demo select option {
 background: var(--navy);
 color: var(--white);
 }
 .wt-demo .form-submit {
 width: 100%;
 background: var(--grad);
 color: var(--white);
 font-family: inherit;
 font-weight: 700;
 font-size: 1rem;
 padding: 14px;
 border: none;
 border-radius: 8px;
 cursor: pointer;
 margin-top: 8px;
 transition:
 opacity 0.2s,
 transform 0.15s;
 box-shadow: 0 4px 20px rgba(182, 50, 95, 0.4);
 position: relative;
 }
 .wt-demo .form-submit:hover {
 opacity: 0.9;
 transform: translateY(-1px);
 }
 .wt-demo .form-submit:disabled {
 opacity: 0.55;
 cursor: not-allowed;
 transform: none;
 }
 .wt-demo .form-status {
 font-size: 0.82rem;
 text-align: center;
 margin-top: 14px;
 line-height: 1.5;
 position: relative;
 padding: 10px 14px;
 border-radius: 7px;
 }
 .wt-demo .form-status.is-error {
 color: #ffd2cc;
 background: rgba(182, 50, 95, 0.18);
 border: 1px solid rgba(255, 136, 124, 0.35);
 }
 .wt-demo .form-status.is-success {
 color: #d6ffe4;
 background: rgba(46, 160, 102, 0.18);
 border: 1px solid rgba(46, 160, 102, 0.4);
 }
 .wt-demo .form-note {
 font-size: 0.72rem;
 color: rgba(255, 255, 255, 0.35);
 text-align: center;
 margin-top: 12px;
 line-height: 1.5;
 position: relative;
 }

 @media (max-width: 600px) {
 .wt-demo .hero {
 padding: 60px 20px 52px;
 }
 .wt-demo .products,
 .wt-demo .form-section {
 padding: 52px 20px;
 }
 .wt-demo .form-right {
 padding: 24px;
 }
 }
&lt;/style&gt;

&lt;div class="wt-demo"&gt;
 &lt;!-- HERO --&gt;
 &lt;section class="hero"&gt;
 &lt;!-- &lt;div class="hero-eyebrow"&gt;Runtime Application Security&lt;/div&gt; --&gt;
 &lt;h1&gt;Stop Vulnerabilities at the Source.&lt;br /&gt;&lt;span class="grad-text"&gt;Block Attacks at Runtime.&lt;/span&gt;&lt;/h1&gt;
 &lt;p class="hero-sub"
 &gt;See how Waratek's compiler-based security platform catches what other tools miss - during development and in
 production.&lt;/p
 &gt;
 &lt;p class="hero-tagline"&gt;Define Once. Secure Constantly.&lt;/p&gt;</description></item></channel></rss>