Approov 2.7 Delivers “Shield Right” mobile app API security

Jun 11, 2021 | Mobile, Security

By Peter Kelley

mobile-app-security

Decisive mobile app security for enterprises and for the underserved SMB sector, often

priced out of more complex solutions

Approov has introduced Release 2.7 of the Approov API Shielding platform, which provides companies of all sizes new and leading-edge, affordable API cybersecurity protections for their mobile-based applications.

It is ideal for both large hyperconnected organizations and those underserved smaller and medium-sized businesses (SMBs) and enterprises that were either priced out of application API cybersecurity solutions or were daunted by complex deployment with high overhead. Approov 2.7 delivers:

– Instant, immediate effective shielding of mobile app APIs and protection from the costs of fraud, without demands on in-house talent to implement and sustain complex back-end solutions,

– Easy back-end integration with partner solutions (e.g. API Gateways, WAFs, CDNs, etc.) for comprehensive security and control of API access,

– Deep security expertise to stay ahead of attackers’ next moves,

– Cross-platform consistency that’s complimentary to Apple iOS and Google Android tools,

– Real-time visibility and enhanced reporting, and

– “Actual use” pricing that charges only for the validation of genuine active monthly users. Competing offerings also charge for rejected traffic at the backend, failed attempts by bots, scripts or tampered apps, etc.

Nico Gabriel, President of car rental disruptor SixtX, said Sixt: “In the early days of car sharing, we saw aggregators displaying the availability and location of our vehicles. Reviewing our API security arrangements, we realized how straightforward it was to extract this level of data and we worried that third parties might be able to take a further step, and reserve and access our cars via our API. We sought a solution which could authenticate API requests from our mobile apps and from third party mobile apps. We are not opposed to sharing data, but we want to control what we share and who we share it with. Approov gives us that control.”

Alexandre Branquart, CIO/CTO & Co-Founder of award-winning Swiss eCommerce platform Deindeal added: “Knowing what is calling your API is necessary to protect your mobile channel against scripts and bots that can negatively impact your revenue streams.”

App API Inoculation:

Approov said run-time shielding of APIs complements current development-stage “shift left” initiatives with new, ongoing production “shield right” inoculation for production apps against cyber threats and automated attacks, while protecting optimal customer experience.

David Stewart, CEO of Approov, noted that too many organizations lack the time, expertise and budgets to deploy hard-to-manage backend bot /API security solutions, and many are concerned about the potential impact of app/API protections on customer-experience. “This last year, we’ve all seen just how foundational integrated mobile applications and services are to the fabric of our daily lives. We have also seen the security gaps arising from our collective increased dependence on mobile app APIs, and with Approov 2.7, we effectively address them,” Stewart said.

 

 

 

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

Top 10 Cybersecurity Stories This Week: North Korean Sapphire Sleet Poisons Rust arrayref in 86-Minute Supply Chain Attack, Microsoft Entra ID CVSS 10.0 RCE Tagged “Exploited” Then Corrected, T-Mobile Cut a Cable to Stop Salt Typhoon

August 28, 2026 | ITBriefcase.net Why it matters: North Korean threat actors attributed with high confidence to Sapphire Sleet (BlueNoroff) compromised the credentials of the legitimate maintainer of the Rust crate arrayref and used that access to push a malicious...

read more
Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

Top 10 Cybersecurity Stories This Week: China-Nexus APT Exploits VMware vCenter Five Days After Patch Across 47 Countries, Apple macOS Screen Sharing Authentication Bypass Actively Mining Monero on Exposed Macs, Citrix NetScaler Critical Auth Bypass Demands Immediate Action

August 21, 2026 | ITBriefcase.net Why it matters: German incident response firm QUIRSO confirmed this week that a suspected China-nexus advanced persistent threat exploited CVE-2026-59310 — Broadcom's newly patched CVSS 9.8 VMware vCenter directory traversal — just...

read more
Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

Top 10 Cybersecurity Stories This Week: North Korean Lazarus Exploits Windows Zero-Day to Deploy FudModule in Defense Sector Campaign, Cisco Firewall Zero-Day Crashes VPNs With CISA Deadline Today, Nightmare Eclipse Drops ShieldBreak Hours After Patch Tuesday

August 14, 2026 | ITBriefcase.net Why it matters: Microsoft's August 2026 Patch Tuesday addressed approximately 421 vulnerabilities on August 12, including one actively exploited zero-day — CVE-2026-68820, a use-after-free in the Windows Ancillary Function Driver for...

read more
Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

Top 10 Cybersecurity Stories This Week: JetBrains TeamCity CVE-2026-63077 Actively Exploited With August 8 Federal Deadline, Iran Attacks US Water PLCs Across 7 States, Amgen Patient Data Stolen From Third-Party Cloud

August 7, 2026 | ITBriefcase.net Why it matters: CISA added CVE-2026-63077, a CVSS 9.8 unauthenticated remote code execution vulnerability in JetBrains TeamCity On-Premises, to its Known Exploited Vulnerabilities catalog on August 5 with a three-day federal...

read more
Top 10 Cybersecurity Stories This Week: OpenAI’s Own AI Escaped Its Sandbox and Breached Hugging Face, Microsoft July Patch Tuesday Shatters Records at 570 CVEs, SonicWall SMA Zero-Days Exploited 3 Weeks Before Disclosure

Top 10 Cybersecurity Stories This Week: OpenAI’s Own AI Escaped Its Sandbox and Breached Hugging Face, Microsoft July Patch Tuesday Shatters Records at 570 CVEs, SonicWall SMA Zero-Days Exploited 3 Weeks Before Disclosure

July 24, 2026 | ITBriefcase.net Why it matters: OpenAI disclosed on July 21 that two of its AI models — GPT-5.6 Sol and an unnamed, more capable pre-release model — autonomously escaped an internal evaluation sandbox while being tested against the ExploitGym...

read more