Home / Companies / Fastly / Blog / August 2026

August 2026 Summaries

13 posts from Fastly

Filter
Month: Year:
Post Summaries Back to Blog
Fastly’s report finds that bots account for 57% of traffic to SaaS/PaaS and high-tech websites, with AI requests growing 30% from January to May 2026 and expanding 6.5 times faster than human traffic. High-tech organizations receive 136% more AI-related wanted bot traffic and 22% more unwanted bot traffic than the global baseline, reflecting demand for valuable technical documentation, APIs, proprietary data, and other machine-readable assets. Automated traffic can increase cloud, bandwidth, and origin-server costs, impair application performance, distort analytics, and enable threats such as credential stuffing, API abuse, scraping, and vulnerability scanning. Because SaaS/PaaS platforms depend on APIs and serve as gateways to wider customer ecosystems, they present especially attractive targets and must distinguish beneficial automation from harmful activity. The report recommends that organizations improve visibility into bot behavior, apply more nuanced controls than simple blocking, consider potential monetization of AI access, and use defensive measures against malicious automation while aligning access policies with business objectives.
Aug 31, 2026 1,614 words in the original blog post.
AI requests across Fastly’s edge network grew 6.5 times faster than human traffic from January through May 2026, while SaaS and PaaS platforms experienced bot activity 21% above the global average and unwanted bot traffic 22% above baseline in January. The report argues that aggressive blocking through static WAF rules and IP restrictions can harm legitimate AI crawlers, retrieval agents, and search indexers that may support discovery and recommendations, while failing to stop adaptive attackers targeting logins, account takeovers, and authenticated resources. Since more than 51% of AI requests require origin infrastructure access, organizations face increased costs in compute, database capacity, and bandwidth when they cannot distinguish useful automation from malicious or low-value scraping. Fastly recommends granular edge telemetry, adaptive mitigation, deception techniques, and real-time rate limiting to protect multi-tenant platform reliability while preserving beneficial traffic, drawing its findings from billions of inspected requests through its WAF and bot-management products.
Aug 31, 2026 520 words in the original blog post.
WebMCP is an emerging web standard intended to help browser-based AI agents interact reliably with forms by supplying semantic descriptions of each form and field, reducing errors with controls such as date pickers and multi-selects. A Fastly Compute proof of concept addresses limited site adoption by intercepting HTML at the edge, heuristically identifying common form types from existing markup signals such as field names, labels, placeholders, input types, action URLs, and field combinations, then injecting WebMCP attributes without requiring changes from site developers. The streaming implementation uses HTMLRewritingStream to modify forms and inputs inline with minimal latency and no full-response buffering, adding tool names, descriptions, parameter guidance, and safe auto-submit behavior where appropriate. Fastly argues that edge infrastructure is well suited to also manage WebMCP’s required headers, permissions policies, origin-trial token, and origin-isolation requirements, while future work could correct or enrich standard HTML validation attributes to improve browser-generated input schemas. WebMCP remains an early specification, but the proposal positions agent-ready web experiences as an infrastructure challenge as AI agents become a more common way to browse sites.
Aug 31, 2026 1,273 words in the original blog post.
Fastly’s fourth internship cohort for Summer 2026 contributed production-focused projects across engineering, network operations, security, developer tools, and UX, reflecting the company’s emphasis on hands-on work for early-career talent. Interns modernized internal cloud-cost and feature-flag systems, created network transit scoring and DNS-utilization tools, improved peering automation, developed Go microservices for infrastructure and service configuration, expanded local caching tests in Viceroy, and applied machine learning to bot detection and web application firewall false-positive mitigation. Their work aimed to improve operational efficiency, reliability, security, developer workflows, customer experience, and cost management. Participants described a supportive culture marked by mentorship, collaboration, access to experienced engineers, social events, and opportunities to deploy meaningful code, while advising future interns to ask questions, study documentation and source code, seek feedback, build connections, track project milestones, and focus on measurable impact.
Aug 26, 2026 2,645 words in the original blog post.
As API use expands through microservices, AI agents, and developer coding assistants, organizations face growing risks from unknown endpoints, malformed requests, data exposure, and uncontrolled costs, with Fastly reporting AI traffic growth far outpacing human traffic in early 2026. Fastly API Security addresses these challenges through API Discovery, which automatically identifies and inventories production API traffic with business context, and API Enforcement, which validates requests at the network edge against uploaded JSON or YAML schemas and can log or block nonconforming traffic before it reaches origin systems. The platform supports granular inspection and policy controls by service, schema, operation, domain, path, method, and query parameter, while providing metrics and logging to identify unsecured APIs and understand client behavior. It is integrated with Fastly’s WAAP platform alongside next-generation WAF and bot management, while remaining usable with other security infrastructures.
Aug 25, 2026 1,074 words in the original blog post.
Fastly has released an example project for running Model Context Protocol (MCP) servers as stateless WebAssembly applications on its global Compute edge network, aiming to reduce the repeated long-distance latency that can slow AI agents making many tool calls. The approach relies on the MCP specification’s stateless design, in which identity, capabilities, and necessary state travel with individual requests rather than being stored in sessions tied to a single server or region. It supports multi-step and long-running work through encrypted continuation tokens and task handles, allowing requests to resume or be polled without persistent connections. Frequently requested tool, prompt, and resource catalogs can be edge-cached, while personalized responses are excluded from caching. The prototype also applies security controls at the edge, including fail-closed authentication, JWT verification, scope-based authorization, request-size limits, SSRF protections, and error redaction, while using Fastly platform features such as rapid startup, WebAssembly isolation, DDoS mitigation, and request collapsing.
Aug 19, 2026 1,058 words in the original blog post.
Fastly describes how World Cup matches created major, rapidly shifting internet traffic patterns, with streaming demand rising before and throughout games, gaming traffic falling by 18–20% during the final, and social activity increasing about 25% through spikes tied to key moments; traffic returned to normal within 45 minutes after the match. Across 39 days and 104 matches, the company says it managed growing tournament-scale demand through advance capacity planning informed by machine-learning analysis of historical and real-time telemetry, including localized infrastructure adjustments after unexpected viewership increases. Its edge systems reportedly made millions of automated routing decisions per second to avoid network bottlenecks while inline security tools addressed piracy, credential attacks, and DDoS activity without disrupting legitimate streams. Fastly also emphasizes the role of engineers working directly with customer teams through shared live monitoring, prepared runbooks, and failure simulations, presenting these combined automated and human processes as a model for handling everyday peak-traffic events.
Aug 13, 2026 808 words in the original blog post.
Fastly-terraformer is presented as a tool for bringing existing Fastly infrastructure under Terraform management without manually recreating configurations or disrupting production services. It scans a Fastly account through its API, discovers resources such as services, backends, domains, TLS certificates, NGWAF configurations, storage, logging endpoints, access controls, and user management, then generates Terraform import blocks. Users run Terraform’s configuration-generation and apply commands to produce Terraform definitions and import the resources into state while leaving deployed infrastructure unchanged. Supporting more than 40 resource types, with the exception of legacy WAF due to API limitations, the tool can import either an entire account or only NGWAF resources. Its stated benefits include faster infrastructure-as-code adoption, version control, peer-reviewed changes, auditability, rollback and disaster-recovery capabilities, and easier environment replication.
Aug 12, 2026 868 words in the original blog post.
FIFA projected that roughly 6 billion people would engage with the World Cup, and the event’s scale also drove substantial unauthorized streaming, bot activity, and other malicious automated traffic alongside legitimate viewing. U.S. Department of Justice actions under Operation Offsides reportedly seized more than 1,000 piracy domains, while the Trustworthy Accountability Group restricted advertising revenue for 1,376 sites associated with stolen tournament content; other international operations targeted major streaming rings and tens of thousands of illegal sports-streaming URLs. The account notes that piracy often benefits from fragmented broadcasting rights and difficult mobile access, while high-demand events also attract credential stuffing, ticket scalping, account takeover attempts, ad fraud, and DDoS attacks designed to resemble real fan traffic. Fastly cites research indicating that unwanted bots comprise a substantial share of web traffic and describes its anti-piracy collaboration with LaLiga, which uses AI and content signals to identify illicit streams more precisely. It concludes that piracy and sophisticated bots are persistent challenges requiring coordinated action by rights holders, law enforcement, advertisers, and infrastructure providers, as platforms must distinguish legitimate audience surges from adversarial traffic.
Aug 07, 2026 1,400 words in the original blog post.
Fastly has joined the Experian Agent Trust ecosystem to help enterprises identify, authorize, and potentially monetize legitimate AI agents conducting commerce on behalf of consumers. As automated traffic increasingly includes autonomous agents that browse products and make purchases, the partnership aims to replace purely defensive bot policies with real-time trust decisions at Fastly’s distributed network edge. Experian Agent Trust provides identity and delegated-authority verification through Human to Agent Binding, while Fastly evaluates these signals in milliseconds and enables organizations to apply customized policies such as identity-based rate limits, pricing, and checkout experiences. The approach is intended to protect origin infrastructure, avoid backend re-architecture, and allow businesses to distinguish trusted, human-authorized agent traffic from malicious automation.
Aug 06, 2026 666 words in the original blog post.
On August 2, 2026, California's SB 942, known as the California AI Transparency Act, and Article 50(2) of the EU AI Act began enforcing laws requiring AI-generated or altered media to include provenance metadata, with meaningful penalties for non-compliance. These regulations have been driven by consumer demand for transparency, as over 90% of consumers expect brands to disclose AI usage in marketing. Fastly's Image Optimizer offers a solution by preserving C2PA (Coalition for Content Provenance and Authenticity) metadata through image transformations, ensuring the provenance data remains intact across various formats. This functionality is significant because generative AI has made it easy to create misleading photorealistic images, challenging the notion of "seeing is believing" and emphasizing the importance of brand trust. Fastly's Image Optimizer now supports the latest C2PA spec across all image formats (except JPEG XL) without additional cost, allowing customers to maintain provenance metadata during image optimizations. The system has been designed to handle transformations such as resizing and reformatting without stripping crucial provenance data, and it will continue to evolve to meet regulatory and C2PA standards.
Aug 04, 2026 793 words in the original blog post.
CVE-2026-66066 is an arbitrary file read vulnerability in the Active Storage component of Rails that can lead to remote code execution (RCE) when exploited alongside libvips versions below 8.13. Rails released patches and advisories on July 29, 2026, to address this issue, affecting Active Storage versions below 7.2.3.2, 8.0 up to 8.0.5.1, and 8.1 up to 8.1.3.1. Fastly's Next-Gen WAF customers can activate a virtual patch for immediate protection while waiting for the underlying components to be patched. To fully mitigate the vulnerability, it is recommended to update Active Storage and libvips to the latest versions. Rails has also provided guidance for forensic analysis to detect potential exploitation, and Ethiack has detailed the vulnerability's cause in their research.
Aug 03, 2026 294 words in the original blog post.
Fintech companies face unique challenges with security and performance, particularly when handling sensitive data and financial transactions, where even minor disruptions can cause significant user stress and potential financial loss. To address these challenges, high-performing fintechs are moving away from fragmented legacy tools in favor of modern security solutions delivered at the edge, such as the Fastly Edge Cloud Platform. This platform integrates Web Application Firewall (WAF), bot management, DDoS protection, API security, and edge delivery into a single system, which reduces operational complexity, enhances real-time visibility, and stabilizes infrastructure during traffic spikes. By streamlining security processes and meeting regulatory expectations, the platform helps fintechs maintain robust cybersecurity resilience without compromising developer velocity, ultimately ensuring faster incident response times and lower total cost of ownership.
Aug 02, 2026 749 words in the original blog post.