Cybersecurity firm Imperva has suffered a data breach affecting some customers of its Cloud Web Application Firewall (WAF) product, formerly known as Incapsula. CEO Chris Hylen revealed that the company learned about the incident on August 20, 2019, when it was informed about the data exposure impacting Cloud WAF product. Email addresses and hashed and salted passwords were exposed through September 15, 2017. API keys and customer-provided SSL certificates were also exposed. The company urges Cloud users to change their passwords, implement Single Sign-On (SSO), enable two-factor authentication (2FA) and generate and upload new SSL certificate.”]
Source: https://securityaffairs.co/wordpress/90464/data-breach/imperva-data-breach.html

