In today’s post-Mythos world, the mean time from vulnerability disclosure to exploitation is now estimated at minus seven days. Faster vulnerability discovery and automated exploitation mean attackers weaponize threats before teams can patch them, so exposure often begins before remediation starts. Patching is still the only permanent fix, but production fixes take time, which is why more organizations use virtual patching to reduce exposure in the meantime.
At scale, that requires runtime defense that detects and blocks exploit attempts in the data path without disrupting operations. In other words, protection cannot be separated from performance and availability. It has to be enforced where traffic and interactions occur. Here is how three organizations used the AI-powered WAF in the F5 Application Delivery and Security Platform (ADSP) to sharpen detection, cut false positives, and enforce policies with confidence in production.
A major financial institution accelerated threat detection and virtual patching
A major financial institution recognized that the threat landscape was evolving faster than traditional security processes could accommodate.
The organization maintained mature vulnerability management practices, but security leaders were increasingly concerned about AI-driven attacks and emerging zero-day threats.
To address these challenges, the institution leveraged F5 WAF for Distributed Cloud, part of F5 ADSP, as a strategic component of its security architecture.
The deployment helped automate threat detection and accelerate virtual patching efforts. According to the customer, F5's AI-powered WAF actively identified and blocked zero-day attacks without requiring new signatures, enabling security teams to move more quickly from monitoring threats to enforcing protections. The customer also reported a 20% increase in efficacy across production traffic.
By helping identify and block exploit attempts earlier, the organization was able to reduce exposure, while maintaining its existing security and operational processes.
A European engineering company achieved 100% blocking-mode adoption
A large European engineering and construction company faced challenges protecting a critical enterprise resource planning (ERP) application running on a highly customized third-party codebase.
The application's unique traffic patterns regularly confused traditional security tools, generating high volumes of false positives and creating concerns that legitimate business activity could be disrupted by enforcement decisions. Because of this risk, the organization was reluctant to fully enable blocking mode.
To improve detection accuracy, the company deployed F5's AI-powered WAF to better understand the application's behavior and distinguish legitimate traffic from malicious activity.
Requests that had previously been blocked by the organization's legacy security controls were correctly identified as legitimate traffic, contributing to a greater than 90% reduction in false positives. Security teams validated the results through ongoing log analysis and steadily gained confidence in the platform's decisions.
Ultimately, the company achieved 100% blocking-mode adoption across the protected application, enabling it to more confidently enforce protections on a business-critical system.
A healthcare technology company reduced WAF false positives by more than 50%
A national healthcare technology company faced a different challenge. Its security team struggled with high volumes of false positives generated by its existing WAF.
Clinical free-text entries routinely triggered SQL injection protections, while everyday inputs such as abbreviated addresses generated command-injection alerts. Over time, security teams were forced to disable entire categories of signatures to reduce operational disruption, creating gaps in visibility and protection.
The company deployed F5 WAF for Distributed Cloud, which correlates multiple signals before taking enforcement action and reserves blocking decisions for high-confidence detections.
The results were significant. The organization reduced false positives by more than 50%, reported no false-positive incidents requiring remediation during a four-month period, and reduced policy tuning requirements sixfold.
These improvements allowed an already lean security team to spend less time managing alerts and policy exceptions while maintaining strong application protection.
Runtime defense is becoming a prerequisite for modern application security
While the organizations highlighted here approached today's expanding threat landscape from different directions, each recognized the importance of accurate, enforceable runtime protection that allowed them to act with confidence when threats emerged. As exploit timelines compress and architectures become more distributed and AI-intensive, delivery and security can no longer be treated as separate priorities. They have to converge where applications, APIs, users, and AI-enabled interactions meet. That is what F5 is built for, delivering and securing every app and API, wherever they run.
To learn more about F5's latest AI-powered WAF innovations and virtual patching capabilities, explore the F5 WAF for Distributed Cloud product page and the virtual patching use case page.
About the Authors


Related Blog Posts

Who can you trust in the age of AI agents?
New features for F5 Distributed Cloud Bot Defense enable organizations to distinguish between trusted and fraudulent AI traffic.

Securing F5 NGINX in the age of AI
How F5 is applying AI-driven security practices across the F5 NGINX portfolio to help deliver safer, more resilient software.

From dashboard fatigue to operational excellence: Why XOps needs F5 Insight for ADSP
Learn how F5 Insight for ADSP lays the visibility foundation for XOps—turning fragmented signals across applications and infrastructure into actionable intelligence.

The hidden cost of unmanaged AI infrastructure
AI platforms don’t lose value because of models. They lose value because of instability. See how intelligent traffic management improves token throughput while protecting expensive GPU infrastructure.

Govern your AI present and anticipate your AI future
Learn from our field CISO, Chuck Herrin, how to prepare for the new challenge of securing AI models and agents.

F5 recognized as one of the Emerging Visionaries in the Emerging Market Quadrant of the 2025 Gartner® Innovation Guide for Generative AI Engineering
We’re excited to share that F5 has been recognized in 2025 Gartner Emerging Market Quadrant(eMQ) for Generative AI Engineering.