惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
SegmentFault 最新的问题
博客园 - 三生石上(FineUI控件)
WordPress大学
WordPress大学
博客园 - 【当耐特】
月光博客
月光博客
Vercel News
Vercel News
D
Docker
I
InfoQ
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 叶小钗
MongoDB | Blog
MongoDB | Blog
GbyAI
GbyAI
有赞技术团队
有赞技术团队
雷峰网
雷峰网
博客园 - 聂微东
小众软件
小众软件
Y
Y Combinator Blog
腾讯CDC
L
LangChain Blog
The GitHub Blog
The GitHub Blog
宝玉的分享
宝玉的分享
Stack Overflow Blog
Stack Overflow Blog
大猫的无限游戏
大猫的无限游戏
T
The Blog of Author Tim Ferriss

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
Cequence introduces behavioral bot detection and biometri...
Industry News · 2026-06-24 · via Help Net Security

Cequence Security has announced the launch of Intent Graph and Biometric Check, two new capabilities that extend the behavioral architecture Cequence has built since its inception. They provide enterprises with bot defense that works across web, mobile, API, and agentic AI traffic, without relying on the client-side signals that sophisticated bots have learned to defeat.

The architectural divide in bot defense is now unavoidable. While traditional bot defense relies on browser signals such as CAPTCHAs, JavaScript puzzles, device and machine fingerprints, and TLS characteristics, attackers have industrialized workarounds. Modern proxy providers now run real browsers that solve CAPTCHAs, pass puzzle runtimes, and present clean fingerprints at scale, making adversarial automation indistinguishable from legitimate customer sessions.

The agentic shift has made this client-side approach structurally unworkable for several reasons. For example:

  • AI agents operating on behalf of real customers often run in headless environments where puzzle runtimes don’t execute at all;
  • MCP-based agents don’t use browsers, so client-side signals are simply absent;
  • Fast-moving AI-forward companies ship products daily or weekly and can’t afford the time and resource penalty imposed by SDK instrumentation.

Automated traffic now accounts for more than half of all web requests globally, according to Cloudflare, and native agentic commerce is already live across ChatGPT, Amazon, Google’s Agent E-commerce Protocol, Visa’s agentic commerce standard, and Stripe’s payment primitives. A bot defence posture that assumes a web browser is both present and trustworthy cannot protect the channels where commerce is actually moving.

“Client-side bot protection wasn’t architected for AI-driven traffic, and enterprises are already feeling the consequences of this as automated traffic exceeds that from humans,” said Ameya Talwalkar, CEO of Cequence.

Intent Graph: Behavioural detection across every channel

Talwalkar noted that MCP is becoming a first-class commerce channel alongside web, mobile, and API — one where there is no browser to fingerprint and no puzzle to serve. “The Intent Graph tells you what a user, bot, or AI agent is actually doing on your application, regardless of how it got there. Intent Graph doesn’t just detect bad actors; it maps their intent, so when attackers evolve their tactics in real time, adaptive behavioural intelligence has already moved to stop them. This is the posture enterprises need before the agentic inflection, not after.”

Intent Graph builds a behavioural model specific to each application, not a generic fingerprint, but a living map of how real users navigate that particular flow. Because the model is application-specific and behaviour travels with the client, one detection layer covers the full surface:

  • Web: credential stuffing, scraping, and account takeover
  • Mobile: automated abuse that slips past app-level protections
  • API: business logic abuse, carding, and data harvesting
  • Agentic AI, including MCP: distinguishing legitimate AI agents from adversarial ones without relying on non-existent client-side instrumentation

What makes Intent Graph different from behavioural fingerprinting is what happens when the model needs to change. Security teams can adjust which behavioural vectors feed into detection and ultimately into mitigation without a code change or a ticket to engineering. When an attack emerges or the traffic profile shifts, the algorithm updates in minutes. No SDK, no JavaScript instrumentation, no application changes required.

In one recent enterprise deployment, adversaries retooled their attack more than ten times over two days using virtual browsers and rotating proxy networks. Cequence’s Intent Graph blocked every iteration, without any CAPTCHA, puzzle, or client challenge being shown to legitimate customers.

Biometric Check: Secure verification that users are already familiar with

Biometric Check replaces CAPTCHAs, puzzles, SMS codes, and email verification with hardware-bound cryptographic attestation via a device’s Secure Enclave. When bot detection flags a session outside a configurable, application-specific confidence threshold, the user completes a familiar biometric interaction, Touch ID, Face ID, Windows Hello, and the device returns signed proof that a real person on a registered device completed the action. The biometric itself never leaves the device and completes verification in less than a second.

This is categorically different from client-side challenges, which become less expensive to attack at scale. There is no Secure Enclave to virtualise and no fingerprint sensor to spoof from a cloud VM. Biometric Check is also the first bot verification mechanism that makes the enterprise’s actual false positive rate measurable rather than estimated. Every challenge passed is direct evidence that detection policy flagged a real customer, a signal to tighten detection, not just a number to report.

The same checkpoint logic extends to AI agents. For low-risk actions, agents operate freely. For high-stakes, irreversible actions such as wire transfers, record retrievals, or contract modifications, Biometric Check inserts a human-in-the-loop gate at the time of the action rather than at the front door. This is the model enterprises will need for agent workflows in financial services, healthcare, B2B commerce, and regulated API surfaces generally.

“Building effective bot defence for MCP and agentic commerce requires institutional knowledge that most companies simply don’t have,” said Shreyans Mehta, CTO of Cequence.

Mehta noted that vendors relying on client-side architecture never accumulated the interaction data needed to challenge automated clients at scale, whereas Cequence has been building an unequaled behavioural understanding across more than 10 billion daily API interactions for Forbes Global 2000 customers.

“Agentic traffic doesn’t respect categorical boundaries. Protecting them requires unified visibility across application protection, API security, and agentic interaction — something enterprises cannot assemble from separate point solutions retrofitted after the fact.”