{"id":197,"date":"2018-09-17T10:17:33","date_gmt":"2018-09-17T10:17:33","guid":{"rendered":"https:\/\/www.imperva.com\/learn\/?post_type=application_security&#038;p=197"},"modified":"2023-12-20T15:57:45","modified_gmt":"2023-12-20T15:57:45","slug":"zero-day-exploit","status":"publish","type":"application_security","link":"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/","title":{"rendered":"Zero-day (0day) exploit"},"content":{"rendered":"<h2>What is zero-day (0day) exploit<\/h2>\n<p>A zero-day (0day) exploit is a cyber attack targeting a software vulnerability which is unknown to the software vendor or to antivirus vendors. The attacker spots the software vulnerability before any parties interested in mitigating it, quickly creates an exploit, and uses it for an attack. Such attacks are highly likely to succeed because defenses are not in place. This makes zero-day attacks a severe security threat.<\/p>\n<p>Typical attack vectors include Web browsers, which are common targets due to their ubiquity, and email attachments that exploit vulnerabilities in the application opening the attachment, or in specific file types such as Word, Excel, PDF or Flash.<\/p>\n<p>A related concept is zero-day\u00a0<a href=\"https:\/\/www.imperva.com\/learn\/application-security\/malware-detection-and-removal\/\">malware<\/a>\u00a0\u2014 a computer virus for which specific antivirus software signatures are not yet available, so signature-based antivirus software cannot stop it.<\/p>\n<p>Typical targets for a zero-day exploit include:<\/p>\n<ol>\n<li>Government departments.<\/li>\n<li>Large enterprises.<\/li>\n<li>Individuals with access to valuable business data, such as intellectual property.<\/li>\n<li>Large numbers of home users who use a vulnerable system, such as a browser or operating system. Hackers can use vulnerabilities to compromise computers and build massive\u00a0<a href=\"https:\/\/www.imperva.com\/learn\/application-security\/botnet-ddos\/\">botnets.<\/a><\/li>\n<li>Hardware devices, firmware and\u00a0<a href=\"https:\/\/www.imperva.com\/learn\/application-security\/iot-internet-of-things-security\/\">Internet of Things (IoT)<\/a>.<\/li>\n<li>In some cases governments use zero-day exploits to attack individuals, organizations or countries who threaten their natural security.<\/li>\n<\/ol>\n<p>Because zero-day vulnerabilities are valuable for different parties, a market exists in which organizations pay researchers who discover vulnerabilities. In addition to this \u2018white market\u2019, there are gray and black markets in which zero-day vulnerabilities are traded, without public disclosure, for up to hundreds of thousands of dollars.<\/p>\n<h2>Examples of zero-day attacks<\/h2>\n<p>Some high-profile examples of zero-day attacks include:<\/p>\n<ol>\n<li style=\"list-style-type: none;\">\n<ol>\n<li><span class=\"bold-text\"><strong>Stuxnet:<\/strong><\/span>\u00a0This malicious computer worm targeted computers used for manufacturing purposes in several countries, including Iran, India, and Indonesia. The primary target was Iran\u2019s uranium enrichment plants, with the intention of disrupting the country\u2019s nuclear program.The zero-day vulnerabilities existed in software running on industrial computers known as\u00a0<a href=\"https:\/\/en.wikipedia.org\/wiki\/Programmable_logic_controller\">programmable logic controllers (PLCs)<\/a>, which ran on Microsoft Windows. The worm infected the PLCs through vulnerabilities in\u00a0<a href=\"https:\/\/simple.wikipedia.org\/wiki\/SIMATIC\">Siemens Step7 software<\/a>, causing the PLCs to carry out unexpected commands on assembly line machinery, sabotaging the centrifuges used to separate nuclear material.<\/li>\n<li><span class=\"bold-text\"><strong>Sony zero-day attack:<\/strong><\/span>\u00a0Sony Pictures was the victim of a zero-day exploit in late 2014. The attack crippled Sony\u2019s network and led to the release of sensitive corporate data on file-sharing sites. The compromised data included details of forthcoming movies, business plans, and the personal email addresses of senior Sony executives. The details of the exact vulnerability exploited in the Sony attack remains unknown.<\/li>\n<li><span class=\"bold-text\"><strong>RSA:<\/strong><\/span>\u00a0In 2011, hackers used a then-unpatched vulnerability in Adobe Flash Player to gain access to the network of security company RSA. The attackers sent emails with Excel spreadsheet attachments to small groups of RSA employees. The spreadsheets contained an embedded Flash file that exploited the zero-day Flash vulnerability. When one of the employees opened the spreadsheet, the attacked installed the Poison Ivy remote administration tool to take control of the computer.Once they gained access to the network, attackers searched for sensitive information, copied it and transmitted it to external servers they controlled. RSA admitted that among the data stolen was sensitive information related to the company\u2019s SecurID two-factor authentication products, used around the world for access to sensitive data and devices.<\/li>\n<li><span class=\"bold-text\"><strong>Operation Aurora:<\/strong><\/span>\u00a0This 2009 zero-day exploit targeted the intellectual property of several major enterprises, including Google, Adobe Systems, Yahoo, and Dow Chemical. The vulnerabilities existed in both Internet Explorer and Perforce; the latter was used by Google to manage its source code.<\/li>\n<\/ol>\n<\/li>\n<\/ol>\n<h2>Zero-day vulnerability detection<\/h2>\n<p>By definition, no patches or antivirus signatures exist yet for zero-day exploits, making them difficult to detect. However, there are several ways to detect previously unknown software vulnerabilities.<\/p>\n<h3><span class=\"bold-text\">Vulnerability scanning<\/span><\/h3>\n<p><a href=\"https:\/\/www.imperva.com\/learn\/application-security\/vulnerability-management\/\">Vulnerability scanning<\/a>\u00a0can detect some zero-day exploits. Security vendors who offer vulnerability scanning solutions can simulate attacks on software code, conduct code reviews, and attempt to find new vulnerabilities that may have been introduced after a software update.<\/p>\n<p>This approach cannot detect all zero-day exploits. But even for those it detects, scanning is not enough\u2014organizations must act on the results of a scan, perform code review and sanitize their code to prevent the exploit. In reality most organizations are slow to respond to newly discovered vulnerabilities, while attackers can be very quick to exploit a zero-day exploit.<\/p>\n<h3><span class=\"bold-text\">Patch management<\/span><\/h3>\n<p>Another strategy is to deploy software patches as soon as possible for newly discovered software vulnerabilities. While this cannot prevent zero-day attacks, quickly applying patches and software upgrades can significantly reduce the risk of an attack.<\/p>\n<p>However, there are three factors that can delay the deployment of security patches. Software vendors take time to discover vulnerabilities, develop a patch and distribute it to users. It can also take time for the patch to be applied on organizational systems. The longer this process takes, the higher the risk of a zero-day attack.<\/p>\n<h3><span class=\"bold-text\">Input validation and sanitization<\/span><\/h3>\n<p>Input validation solves many of the issues inherent in vulnerability scanning and patch management. It doesn\u2019t leave organizations unprotected while they are patching systems or sanitizing code\u2014processes that can take time. It is operated by security experts and is much more flexible, able to adapt and respond to new threats in real time.<\/p>\n<p>One of the most effective ways to prevent zero-day attacks is deploying a web application firewall (WAF) on the network edge. A WAF reviews all incoming traffic and filters out malicious inputs that might target security vulnerabilities.<\/p>\n<p>Additionally, the most recent advancement in the fight against zero-day attacks is runtime application self-protection (RASP). RASP agents sit inside applications, examining request payloads with the context of the application code at runtime, to determine whether a request is normal or malicious- enabling applications to defend themselves.<\/p>\n<h3><span class=\"bold-text\">Zero-day initiative<\/span><\/h3>\n<p>A program established to reward security researchers for responsibly disclosing vulnerabilities, instead of selling the information on the black market. Its objective is to create a broad community of vulnerability researchers who can discover security vulnerabilities before hackers do, and alert software vendors.<\/p>\n<div class=\"ddos-banner\"><div class=\"wrap\"><p>See how Imperva Web Application Firewall can help you with zero-day exploits.<\/p>\n<div class=\"cta-container\">\n                                                    <a class=\"impv-yellow-btn\"  event-action=\"Click\"  event-category=\"LC Banner\"  event-label=\"Request demo\"  gtm-track  target=\"_self\" href=\"javascript:openModal('modalid3533', '\/learn\/banner\/virtual\/request-demo\/', 'Personal Demo Request | Imperva');\">Request demo<\/a>\n                                                    <a class=\"gst-yellow-dark-text-btn\"  event-action=\"Click\"  event-category=\"LC Banner\"  event-label=\"Learn more\"  gtm-track  target=\"_self\" href=\"https:\/\/www.imperva.com\/products\/web-application-firewall-waf\/\">Learn more<\/a>\n                                                <\/div><\/div><\/div><h2>Imperva zero-day threat mitigation<\/h2>\n<p>Vulnerability scanning and patch management are partial solutions to zero-day attacks. And they create a large window of vulnerability, due to the time it takes to develop and apply patches and code fixes.<\/p>\n<p><a href=\"https:\/\/www.imperva.com\/products\/application-security\/web-application-firewall-waf\/\">Imperva\u2019s Web Application Firewall (WAF)<\/a>\u00a0is a managed input validation service deployed at the edge of your network which intelligently filters and verifies incoming traffic, blocking attacks at the network edge.<\/p>\n<p><a href=\"https:\/\/www.imperva.com\/products\/runtime-application-self-protection-rasp\/\">Imperva RASP<\/a> is the latest innovation in the fight against zero-day attacks. Using patented grammar-based techniques that leverage LangSec, RASP allows applications to defend themselves without signatures or patches- providing security by default and sparing you the operational costs of off-cycle 0-day patching.   <\/p>\n<div id=\"attachment_198\" style=\"width: 738px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" aria-describedby=\"caption-attachment-198\" class=\"wp-image-198 size-full\" src=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2019\/01\/zero-day.jpg\" alt=\"Imperva Cloud WAF blocks zero-day attack by using crowdsourced security\" width=\"728\" height=\"481\" srcset=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2019\/01\/zero-day.jpg 728w, https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2019\/01\/zero-day-300x198.jpg 300w, https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2019\/01\/zero-day-552x365.jpg 552w, https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2019\/01\/zero-day-510x337.jpg 510w, https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2019\/01\/zero-day-76x50.jpg 76w, https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2019\/01\/zero-day-545x360.jpg 545w, https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2019\/01\/zero-day-420x278.jpg 420w\" sizes=\"auto, (max-width: 728px) 100vw, 728px\" \/><p id=\"caption-attachment-198\" class=\"wp-caption-text\">Imperva cloud-based WAF blocks zero-day attacks by using crowdsourced security to identify new threats<\/p><\/div>\n<p><a href=\"https:\/\/www.imperva.com\/products\/web-application-firewall-waf\/\">Imperva cloud-based WAF<\/a>\u00a0leverages crowdsourced security to protect against zero-day attacks, aggregating attack data to react to threats instantly. As soon as a new threat is identified anywhere on the Incapsula network, a mitigation path is quickly deployed to safeguard the entire user base.<\/p>\n","protected":false},"featured_media":0,"template":"","categories":[3],"class_list":["post-197","application_security","type-application_security","status-publish","hentry","category-attack-types"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v26.5 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>What is a Zero-Day Exploit | Protecting Against 0day Vulnerabilities | Imperva<\/title>\n<meta name=\"description\" content=\"Targeting unknown vulnerabilities, zero-day attacks are among the scariest cyber threats. Learn all about early detection &amp; mitigation strategies against 0day assaults.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What is a Zero-Day Exploit | Protecting Against 0day Vulnerabilities | Imperva\" \/>\n<meta property=\"og:description\" content=\"Targeting unknown vulnerabilities, zero-day attacks are among the scariest cyber threats. Learn all about early detection &amp; mitigation strategies against 0day assaults.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/\" \/>\n<meta property=\"og:site_name\" content=\"Learning Center\" \/>\n<meta property=\"article:modified_time\" content=\"2023-12-20T15:57:45+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2019\/01\/zero-day.jpg\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"6 minutes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data2\" content=\"Itamar Verta\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/\",\"url\":\"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/\",\"name\":\"What is a Zero-Day Exploit | Protecting Against 0day Vulnerabilities | Imperva\",\"isPartOf\":{\"@id\":\"https:\/\/www.imperva.com\/learn\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2019\/01\/zero-day.jpg\",\"datePublished\":\"2018-09-17T10:17:33+00:00\",\"dateModified\":\"2023-12-20T15:57:45+00:00\",\"description\":\"Targeting unknown vulnerabilities, zero-day attacks are among the scariest cyber threats. Learn all about early detection & mitigation strategies against 0day assaults.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/#primaryimage\",\"url\":\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2019\/01\/zero-day.jpg\",\"contentUrl\":\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2019\/01\/zero-day.jpg\",\"width\":728,\"height\":481},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.imperva.com\/learn\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"AppSec\",\"item\":\"https:\/\/www.imperva.com\/learn\/application-security\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"Zero-day (0day) exploit\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.imperva.com\/learn\/#website\",\"url\":\"https:\/\/www.imperva.com\/learn\/\",\"name\":\"Learning Center\",\"description\":\"Imperva\",\"publisher\":{\"@id\":\"https:\/\/www.imperva.com\/learn\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.imperva.com\/learn\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.imperva.com\/learn\/#organization\",\"name\":\"Imperva Inc\",\"url\":\"https:\/\/www.imperva.com\/learn\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.imperva.com\/learn\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2023\/06\/Linkedin-FB-OG-sharing.jpeg\",\"contentUrl\":\"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2023\/06\/Linkedin-FB-OG-sharing.jpeg\",\"width\":1200,\"height\":627,\"caption\":\"Imperva Inc\"},\"image\":{\"@id\":\"https:\/\/www.imperva.com\/learn\/#\/schema\/logo\/image\/\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What is a Zero-Day Exploit | Protecting Against 0day Vulnerabilities | Imperva","description":"Targeting unknown vulnerabilities, zero-day attacks are among the scariest cyber threats. Learn all about early detection & mitigation strategies against 0day assaults.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/","og_locale":"en_US","og_type":"article","og_title":"What is a Zero-Day Exploit | Protecting Against 0day Vulnerabilities | Imperva","og_description":"Targeting unknown vulnerabilities, zero-day attacks are among the scariest cyber threats. Learn all about early detection & mitigation strategies against 0day assaults.","og_url":"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/","og_site_name":"Learning Center","article_modified_time":"2023-12-20T15:57:45+00:00","og_image":[{"url":"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2019\/01\/zero-day.jpg","type":"","width":"","height":""}],"twitter_card":"summary_large_image","twitter_misc":{"Est. reading time":"6 minutes","Written by":"Itamar Verta"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/","url":"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/","name":"What is a Zero-Day Exploit | Protecting Against 0day Vulnerabilities | Imperva","isPartOf":{"@id":"https:\/\/www.imperva.com\/learn\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/#primaryimage"},"image":{"@id":"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/#primaryimage"},"thumbnailUrl":"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2019\/01\/zero-day.jpg","datePublished":"2018-09-17T10:17:33+00:00","dateModified":"2023-12-20T15:57:45+00:00","description":"Targeting unknown vulnerabilities, zero-day attacks are among the scariest cyber threats. Learn all about early detection & mitigation strategies against 0day assaults.","breadcrumb":{"@id":"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/#primaryimage","url":"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2019\/01\/zero-day.jpg","contentUrl":"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2019\/01\/zero-day.jpg","width":728,"height":481},{"@type":"BreadcrumbList","@id":"https:\/\/www.imperva.com\/learn\/application-security\/zero-day-exploit\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.imperva.com\/learn\/"},{"@type":"ListItem","position":2,"name":"AppSec","item":"https:\/\/www.imperva.com\/learn\/application-security\/"},{"@type":"ListItem","position":3,"name":"Zero-day (0day) exploit"}]},{"@type":"WebSite","@id":"https:\/\/www.imperva.com\/learn\/#website","url":"https:\/\/www.imperva.com\/learn\/","name":"Learning Center","description":"Imperva","publisher":{"@id":"https:\/\/www.imperva.com\/learn\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.imperva.com\/learn\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.imperva.com\/learn\/#organization","name":"Imperva Inc","url":"https:\/\/www.imperva.com\/learn\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.imperva.com\/learn\/#\/schema\/logo\/image\/","url":"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2023\/06\/Linkedin-FB-OG-sharing.jpeg","contentUrl":"https:\/\/www.imperva.com\/learn\/wp-content\/uploads\/sites\/13\/2023\/06\/Linkedin-FB-OG-sharing.jpeg","width":1200,"height":627,"caption":"Imperva Inc"},"image":{"@id":"https:\/\/www.imperva.com\/learn\/#\/schema\/logo\/image\/"}}]}},"_links":{"self":[{"href":"https:\/\/www.imperva.com\/learn\/wp-json\/wp\/v2\/application_security\/197","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.imperva.com\/learn\/wp-json\/wp\/v2\/application_security"}],"about":[{"href":"https:\/\/www.imperva.com\/learn\/wp-json\/wp\/v2\/types\/application_security"}],"version-history":[{"count":5,"href":"https:\/\/www.imperva.com\/learn\/wp-json\/wp\/v2\/application_security\/197\/revisions"}],"predecessor-version":[{"id":1318,"href":"https:\/\/www.imperva.com\/learn\/wp-json\/wp\/v2\/application_security\/197\/revisions\/1318"}],"wp:attachment":[{"href":"https:\/\/www.imperva.com\/learn\/wp-json\/wp\/v2\/media?parent=197"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.imperva.com\/learn\/wp-json\/wp\/v2\/categories?post=197"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}