F5 Enhances WAF with AI for Rapid Virtual Patching Against Evolving Threats
F5 has updated its Web Application Firewall (WAF) with AI-driven anomaly detection and agentic threat intelligence to combat AI-powered threats and enable faster virtual patching.

F5 has introduced significant enhancements to its Web Application Firewall (WAF) designed to counter the rapidly evolving landscape of AI-driven cyber threats. The company's latest innovations focus on integrating AI-powered anomaly detection and agentic threat intelligence directly into the data path, enabling near real-time protection and accelerating the deployment of virtual patches. This strategic update aims to provide security leaders with crucial time to make informed, risk-based decisions rather than resorting to immediate, potentially disruptive operational changes.
The core of F5's advancement lies in its AI-powered WAF, which leverages its strategic position within customer infrastructures to deliver real-time defenses. New features like anomaly detection and agentic threat intelligence allow the WAF to analyze traffic patterns, identify deviations from normal behavior, and correlate observed threats with external intelligence. This allows for the precise blocking of active exploits at the request level, a critical capability given the shrinking window between vulnerability discovery and exploitation.
Kunal Anand, CPO at F5, highlighted the urgency of these changes, stating, "Frontier AI has collapsed the time between vulnerability discovery and active exploitation. The old model of waiting for code to be rewritten, tested, and redeployed cannot keep pace." F5's approach places protection directly in the data path, enabling the identification and blocking of exploits within minutes. This capability, known as virtual patching, grants organizations much-needed time to assess risks, protect business operations, and plan for permanent fixes without constant crisis management.
Internal testing by F5 demonstrated the efficacy of these new capabilities, achieving 98% threat detection with a mere 1% false positive rate. This performance boost extends the F5 Application Delivery and Security Platform (ADSP), giving security teams the confidence to convert identified vulnerabilities into enforced protections rapidly. The WAF solution evaluates incoming requests using real-time machine learning classification and a neural network risk engine, assigning a dynamic risk score that helps defend against zero-day attacks, injection attempts, and polymorphic exploit chains.
Key to the enhanced WAF are two primary innovations. Anomaly detection acts as an intelligent, self-learning capability that continuously monitors each application's traffic, establishing baselines and flagging meaningful deviations indicative of an attack. Agentic threat intelligence, built on technology from Fletch acquisition, combines external threat data with F5's observed traffic to provide a unified view of relevant threats and recommended mitigations, which can be applied instantly as virtual patches.
F5 also offers automated virtual patching through its Distributed Cloud Web App Scanning (WAS) solution. This tool identifies exposed vulnerabilities, unprotected APIs, and business logic flaws, triggering targeted virtual patches at runtime. For hybrid environments, these capabilities extend to F5 WAF for BIG-IP, allowing customers to apply existing signatures or custom rules across their infrastructure. The reduction in false positives to 1% is crucial for enabling SecOps teams to confidently block risky traffic without impacting application availability.
These new AI-powered WAF capabilities are now available on F5 Distributed Cloud as part of the F5 ADSP. Virtual patching features and the integration between F5 Distributed Cloud WAS and F5 WAF for BIG-IP are also available. Agentic threat intelligence and anomaly detection are currently rolling out to F5 WAF for Distributed Cloud customers, with broader availability expected in the coming months. F5 Insight for ADSP further supports remediation by accelerating patching of underlying infrastructure across the F5 estate.