On March 21, 2024, Miggo’s researchers encountered a customer service that relied on an Amazon Web Services Application Load Balancer for authentication. The arrangement looked reassuring: a gatekeeper checked visitors before sending them into the application. But the researchers suspected that the application could be persuaded to accept a visitor who had used a different gatekeeper. The signature could be genuine. The trust could still be misplaced.
- Miggo watches applications while they run, mapping services and attack paths.
- It asks which vulnerabilities are exploitable in that particular environment.
- Its defenses include runtime blocking and custom firewall rules.
- The aim is protection while developers prepare a permanent fix.
The finding became ALBeast, a configuration-based authentication problem disclosed that August. It also makes a useful introduction to Miggo Security. Security failures often live between two things that each appear to work. A load balancer authenticates. An application accepts a token. The dangerous question is what the second thing assumes about the first.
A doorman with the wrong address
Miggo estimated more than 15,000 potentially vulnerable instances from its scanning, not 15,000 confirmed breaches. The distinction matters. AWS disputed describing the technique as a bypass of its service, pointing instead to misconfigured customer applications. Miggo acknowledged that distinction. This was a failure in how protection had been assembled.
AWS’s guidance requires applications to verify the token signature and confirm that its signer matches the expected load balancer. It also recommends restricting application traffic to that balancer. A valid signature, by itself, is insufficient. The practical lesson travels well beyond AWS: when one service vouches for another, check precisely whose assurance you are accepting.
The queue cannot defend itself
CEO Daniel Shechter and CTO Itai Goldman founded Miggo in 2023. They had met while serving in Israel’s Unit 8200. Shechter later worked at McKinsey; Goldman had led a cyber research unit. Their launch essay describes a problem created by distributed applications: services communicate through chains of trust, and attackers can manipulate those relationships.
A scanner can identify a vulnerable component. Developers must then determine whether it matters, prepare a fix, test it and deploy it. Meanwhile, the application remains available. So does its weakness. A backlog is an excellent record of unfinished work and a rather poor security guard.
Miggo’s Application Detection and Response platform, or ADR, brings production behavior into that decision. Its DeepTracing technology maps service interactions and examines exploitable paths at the function level. The company’s pitch is that security teams should be able to act inside the application while remediation proceeds.
“We’re here to block the attack while you fix the issue.”
Daniel Shechter / April 2025

Three verbs, one production problem
The current product family turns this argument into three verbs. Miggo Know supplies visibility into live applications, their connections and sensitive data flows. Miggo Prove uses runtime evidence to prioritize exploitable risks. Miggo Shield turns the resulting knowledge into targeted protection, including rules generated by WAF Copilot.
That sequence gives buyers a concrete way to evaluate the product. Ask it to show a running service, explain an exposed path and demonstrate the proposed defense. A severity score describes a vulnerability in general. Production evidence helps explain what that vulnerability means here. The test should include the handoff to engineering: can the developer see the same evidence, understand the proposed mitigation and know which permanent repair to prioritize?
- 01 / KnowMap the running application
- 02 / ProveFind the exploitable path
- 03 / ShieldDeploy targeted protection
WAF Copilot, launched in August 2025, works with web application firewalls customers already operate. Miggo describes a process that analyzes vulnerability information and exploit payloads, creates a tailored rule and validates it before blocking. Its workflow starts with logging to check effects on legitimate traffic, then recommends when to enable enforcement.
The unglamorous detail is the useful one. A defense that interrupts ordinary customers creates a second incident. Watching what a rule would block before activating it is a habit other teams can copy. Miggo also describes retiring temporary rules once the vulnerability is fixed.

A business built around the interval
Miggo names SoFi, Patreon and LifeLabs as customers. Its website also displays Riskified and Eitan Medical. Those references put the company among enterprise security suppliers serving businesses where applications carry payments, customer accounts or sensitive information. The likely buyer is an application security or security operations team, working with engineering.
The business is B2B security software, with demo-led enterprise sales and an additional distribution route through AWS Marketplace. The High Emerging Application Threats managed ruleset listed $1 per million evaluated requests and a $0 monthly regional charge when checked in October 2026. AWS WAF charges are separate. That price buys the ruleset, not the entire ADR platform.
Investors have supplied $24.5 million across the disclosed rounds: a $7.5 million seed announced in April 2024 and a $17 million Series A announced in April 2025, led by SYN Ventures with YL Ventures participating. YL credits practitioner feedback with shaping deployment and usability. Miggo’s stated values similarly emphasize customer outcomes, execution, improvement and teamwork.
The shield still needs a fix behind it
In April 2026, Miggo launched Pulse, connecting vulnerability intelligence with runtime validation and protection. Its Grafana integration draws on tracing and profiling telemetry to inform risk decisions. AWS WAF partner-managed rules followed in a July announcement. September brought a company announcement of SINET16 recognition. The product direction keeps pulling intelligence toward an action somebody can take.
Miggo competes for attention alongside runtime vendors such as Contrast Security and Oligo, as well as existing firewall rules and manual mitigation. Its distinction is the connection between application context and response. Buyers should test that connection against their own architecture, traffic and operational constraints.
There are clear boundaries. The AWS emerging-threat ruleset covers server-side web exploits; client-side-only vulnerabilities and non-HTTP protocols fall outside its scope. Runtime analysis needs relevant visibility, and firewall rules need traffic to pass through the enforcement point. Temporary mitigation also leaves the underlying flaw intact. Miggo’s proposition is most useful when a team needs to protect a reachable application now and can follow through with a lasting repair. Buying time is sensible. Spending it well remains the customer’s job.