LATEST / 24.09.26
● MIGGO NAMED A 2026 SINET16 HONOREE● AWS WAF RULESETS NOW AVAILABLE● PULSE CONNECTS THREAT INTELLIGENCE TO DEFENSE

Company / Application Security

Miggo Security wants to buy you time before the patch

A vulnerability can become an attack before its fix reaches production. Miggo watches running applications and builds targeted defenses for the awkward interval in between.

On March 21, 2024, Miggo’s researchers encountered a customer service that relied on an Amazon Web Services Application Load Balancer for authentication. The arrangement looked reassuring: a gatekeeper checked visitors before sending them into the application. But the researchers suspected that the application could be persuaded to accept a visitor who had used a different gatekeeper. The signature could be genuine. The trust could still be misplaced.

The story in four lines
  • Miggo watches applications while they run, mapping services and attack paths.
  • It asks which vulnerabilities are exploitable in that particular environment.
  • Its defenses include runtime blocking and custom firewall rules.
  • The aim is protection while developers prepare a permanent fix.

The finding became ALBeast, a configuration-based authentication problem disclosed that August. It also makes a useful introduction to Miggo Security. Security failures often live between two things that each appear to work. A load balancer authenticates. An application accepts a token. The dangerous question is what the second thing assumes about the first.

A doorman with the wrong address

Miggo estimated more than 15,000 potentially vulnerable instances from its scanning, not 15,000 confirmed breaches. The distinction matters. AWS disputed describing the technique as a bypass of its service, pointing instead to misconfigured customer applications. Miggo acknowledged that distinction. This was a failure in how protection had been assembled.

AWS’s guidance requires applications to verify the token signature and confirm that its signer matches the expected load balancer. It also recommends restricting application traffic to that balancer. A valid signature, by itself, is insufficient. The practical lesson travels well beyond AWS: when one service vouches for another, check precisely whose assurance you are accepting.

ALBeast / the missing question
01Signed tokenIs the signature valid?
02Expected signerDid our load balancer sign it?
03ApplicationAccept only the intended trust.
A signature has a return address. The application needs to read it. Simplified trust-check diagram.

The queue cannot defend itself

CEO Daniel Shechter and CTO Itai Goldman founded Miggo in 2023. They had met while serving in Israel’s Unit 8200. Shechter later worked at McKinsey; Goldman had led a cyber research unit. Their launch essay describes a problem created by distributed applications: services communicate through chains of trust, and attackers can manipulate those relationships.

A scanner can identify a vulnerable component. Developers must then determine whether it matters, prepare a fix, test it and deploy it. Meanwhile, the application remains available. So does its weakness. A backlog is an excellent record of unfinished work and a rather poor security guard.

Miggo’s Application Detection and Response platform, or ADR, brings production behavior into that decision. Its DeepTracing technology maps service interactions and examines exploitable paths at the function level. The company’s pitch is that security teams should be able to act inside the application while remediation proceeds.

“We’re here to block the attack while you fix the issue.”

Daniel Shechter / April 2025
Miggo Security team gathered outside a glass-fronted building
Matching shirts, competing clocks. Miggo’s team in the photograph released with its April 2025 funding announcement.

Three verbs, one production problem

The current product family turns this argument into three verbs. Miggo Know supplies visibility into live applications, their connections and sensitive data flows. Miggo Prove uses runtime evidence to prioritize exploitable risks. Miggo Shield turns the resulting knowledge into targeted protection, including rules generated by WAF Copilot.

That sequence gives buyers a concrete way to evaluate the product. Ask it to show a running service, explain an exposed path and demonstrate the proposed defense. A severity score describes a vulnerability in general. Production evidence helps explain what that vulnerability means here. The test should include the handoff to engineering: can the developer see the same evidence, understand the proposed mitigation and know which permanent repair to prioritize?

From evidence to action
  1. 01 / KnowMap the running application
  2. 02 / ProveFind the exploitable path
  3. 03 / ShieldDeploy targeted protection
Three decisions a security team must connect. A conceptual workflow, not a performance benchmark.

WAF Copilot, launched in August 2025, works with web application firewalls customers already operate. Miggo describes a process that analyzes vulnerability information and exploit payloads, creates a tailored rule and validates it before blocking. Its workflow starts with logging to check effects on legitimate traffic, then recommends when to enable enforcement.

The unglamorous detail is the useful one. A defense that interrupts ordinary customers creates a second incident. Watching what a rule would block before activating it is a habit other teams can copy. Miggo also describes retiring temporary rules once the vulnerability is fixed.

Miggo interface showing a vulnerability list and exploit-response panel with available security controls
The alert gets a to-do list. Miggo’s published interface places response controls beside vulnerability evidence.

A business built around the interval

Miggo names SoFi, Patreon and LifeLabs as customers. Its website also displays Riskified and Eitan Medical. Those references put the company among enterprise security suppliers serving businesses where applications carry payments, customer accounts or sensitive information. The likely buyer is an application security or security operations team, working with engineering.

The business is B2B security software, with demo-led enterprise sales and an additional distribution route through AWS Marketplace. The High Emerging Application Threats managed ruleset listed $1 per million evaluated requests and a $0 monthly regional charge when checked in October 2026. AWS WAF charges are separate. That price buys the ruleset, not the entire ADR platform.

Investors have supplied $24.5 million across the disclosed rounds: a $7.5 million seed announced in April 2024 and a $17 million Series A announced in April 2025, led by SYN Ventures with YL Ventures participating. YL credits practitioner feedback with shaping deployment and usability. Miggo’s stated values similarly emphasize customer outcomes, execution, improvement and teamwork.

Disclosed financing$24.5m
Seed / $7.5mSeries A / $17m

The shield still needs a fix behind it

In April 2026, Miggo launched Pulse, connecting vulnerability intelligence with runtime validation and protection. Its Grafana integration draws on tracing and profiling telemetry to inform risk decisions. AWS WAF partner-managed rules followed in a July announcement. September brought a company announcement of SINET16 recognition. The product direction keeps pulling intelligence toward an action somebody can take.

Miggo competes for attention alongside runtime vendors such as Contrast Security and Oligo, as well as existing firewall rules and manual mitigation. Its distinction is the connection between application context and response. Buyers should test that connection against their own architecture, traffic and operational constraints.

There are clear boundaries. The AWS emerging-threat ruleset covers server-side web exploits; client-side-only vulnerabilities and non-HTTP protocols fall outside its scope. Runtime analysis needs relevant visibility, and firewall rules need traffic to pass through the enforcement point. Temporary mitigation also leaves the underlying flaw intact. Miggo’s proposition is most useful when a team needs to protect a reachable application now and can follow through with a lasting repair. Buying time is sensible. Spending it well remains the customer’s job.

Follow the application trail