< ciso
brief />
Tag Banner

All news with #cloudflare tag

447 articles · page 3 of 23

Cloudflare launches cf: a unified agent-first CLI

🚀 Cloudflare today announced cf, a new CLI designed to give agents access to the full Cloudflare API surface of over 3,000 operations. Built on the Forge API generation pipeline and TypeScript-based configuration, cf defaults to JSON output, adds natural-language CLI search, and integrates Vite for modern Worker development. The open beta is available globally via npm.
read more →

Cloudflare publishes BEACON: real-world web speed data

📊 Cloudflare today announced the release of BEACON, an anonymized dataset of billions of real-user performance measurements across 10,000 top websites. BEACON follows the RUM Archive standard, reports Core Web Vitals as full histograms, and is updated daily in Google BigQuery. The dataset breaks down metrics by browser engine, device, country, and industry, and includes queries and examples to aid researcher analysis.
read more →

Introducing The Cold Start: A Stage for Startups

🚀 Cloudflare is launching The Cold Start, a live startup competition at Cloudflare Connect in San Francisco to give five early-stage companies five minutes each to pitch. The program seeks ambitious founders with compelling ideas rather than polished decks, and finalists will present to experienced judges for a chance to win $500,000 in Cloudflare credits and other prizes. Applications close October 2, 2026, and Cloudflare will cover travel for the five finalists.
read more →

Kitesurf update: agentic browser advances

🛰️ Since its August debut, Kitesurf — a browser built to serve AI agents and running on Cloudflare Workers — has gained WebMCP support, broader web standards compatibility, and major efficiency improvements. Developers can test WebMCP-enabled pages in the Kitesurf playground and use Kitesurf through Browser Run with CDP, Playwright, Puppeteer, or MCP. The team also added a terminal renderer and expanded Web Platform Tests coverage while keeping resource use near launch benchmarks.
read more →

Cloudflare adds Emscripten Rust target for Workers

🚀 Today Cloudflare launched an experimental preview adding first-class support for the Rust wasm32-unknown-emscripten target in the wasm-bindgen toolchain and Rust Workers. This enables improved native Rust and Tokio-based applications to run on Workers, Node.js, and the web, increasing library compatibility and enabling examples like a Rust-native Minecraft server running in a Durable Object. The preview includes patches and examples, with upstream collaboration across Google, wasm-bindgen, Emscripten, and Tokio maintainers.
read more →

Cloudflare launches Forge open source generator

🚀 Forge is an open source, pluggable generation pipeline from Cloudflare designed to produce SDKs, CLIs, docs, and libraries. It runs in CI, lints changes, and generates preview builds so teams can validate API changes before merging. Forge supports OpenAPI today and is extensible to other input formats and chained generation targets. Cloudflare released Forge under the Apache 2.0 license to let organizations run and customize it freely.
read more →

VoidZero progress and Vite+ 1.0 update

🚀 Over the four months since joining Cloudflare, VoidZero has shipped 80+ releases, closed over 1,200 issues, and delivered major performance wins across its toolchain. Vite+ reached 1.0, and work on a new "Bundled Dev" mode aims to speed development for very large web apps. The team shipped the Oxc React Compiler and improvements across Vitest, Oxlint, and Oxfmt, while Cloudflare doubled its open source funding commitment.
read more →

Cloudflare founders outline 2026 vision for the Internet

🌐 Cloudflare marks its 16th anniversary with a founders' letter describing major shifts in the Internet driven by AI. The company highlights a resurgence in web growth since 2025, fueled by new creators using low-code tools and Cloudflare's developer platform. It warns that agent-driven automated traffic, now rising rapidly, could disadvantage small businesses and new entrants unless the ecosystem adapts. Cloudflare says it's introducing measures to reduce crawler load and enable creators to be compensated as agents access their content.
read more →

Cloudflare fixes Containers flaw exposing customer data

🔒 Cloudflare patched a vulnerability in its Containers and Sandboxes that allowed Workers Paid customers to recover residual data from other tenants on the same physical host. The issue, reported via HackerOne on September 4, stemmed from a shared storage pool that skipped zeroing reused 64 KiB blocks, enabling partial reads of leftover data. Cloudflare retired affected disks, cleared cached snapshots, and applied automatic fixes by September 19, 2026, finding no evidence of real-world data exposure.
read more →

Placeholder domain abused to deliver ClickFix malware

🛡️ third-party[.]com is being used to deliver a ClickFix lure that targets Windows systems and sidesteps protections, Manifold Security reports. The site impersonates a Cloudflare “are you human?” check, poisons the clipboard and instructs users to paste a command that runs a remote PowerShell payload. Unlike reserved placeholders such as example.com, third-party[.]com was available for registration and was abused to trap unwary developers and enterprise users.
read more →

Cloudflare Launches Turnstile Spin for Easy Integration

🛡️ Turnstile Spin is an agent-mediated, end-to-end implementation of Cloudflare's Turnstile that automates widget creation and backend validation. It guides AI coding agents to embed the Turnstile widget, wire Siteverify into server logic, fix misconfigurations, and migrate from other CAPTCHA providers without sending application code to Cloudflare. Spin can be started from the Cloudflare dashboard, Wrangler, or an agent skill and has already seen widespread adoption since its July release.
read more →

Cloudflare: Containers cross‑tenant storage vulnerability fixed

🔒 On September 4, 2026, researcher Oren Yomtov of Accomplish reported a vulnerability affecting Cloudflare Containers and Sandboxes. Cloudflare validated the report, found no evidence of customer data compromise, and applied a fleetwide fix with no customer action required. The issue involved dm-thin thin-provisioning and the skip_block_zeroing option, which could allow residual data disclosure when partially overwriting reassigned 64 KiB blocks. Cloudflare removed the option, retired affected disks and caches, and found no signs of malicious exploitation.
read more →

ClickFix campaign injects fake Cloudflare lures

🛡️ Arctic Wolf Labs and Blackpoint Cyber reported an active ClickFix campaign compromising Ukrainian business websites to serve bogus Cloudflare verification pages that trick victims into executing an MSI installer. The MSI chain delivers a newly observed information stealer called Psychedelic, which harvests browser credentials, tokens, and crypto-wallet data, sets persistence, and contacts a C2 for follow-on tasks. Researchers also linked the ClickFix chain to other payloads including RemotePanel and BoundSiphon, highlighting modular remote-access and data-theft capabilities and evidence pointing to likely Russian-speaking operators.
read more →

Cloudflare Adds Granular Vary Support in Cache Rules

🛠️ Cloudflare has added Vary header support to Cache Rules across all plans, letting origins declare potentially variable request fields while operators control how Cloudflare treats each header. You can choose normalize, passthrough, or bypass per header, with a recommended default of normalize. This reduces cache fragmentation from incidental differences while preserving correct responses for negotiated content.
read more →

Cloudflare Worker Previews: Branch-Isolated Environments

🚀 Worker Previews provide a production-like environment per Git branch, each with its own code, configuration, URL, observability, and isolated state. Run npx wrangler preview to create a Preview that uses separate variables, secrets, and Durable Object namespaces so changes can be tested safely without impacting production. The dashboard surfaces Previews alongside Production, with full Workers Observability and optional custom domains or Access protection.
read more →

Cloudflare Announces General Availability of Python Workers

🐍 Cloudflare has made Python Workers generally available, offering first-class, fully supported Python on the Cloudflare Developer Platform. The announcement highlights native bindings to platform services (R2, D1, Hyperdrive, Durable Objects, Queues, Workflows, and Workers AI) and support for frameworks like FastAPI, Django, and Flask via built-in ASGI/WSGI connectors. It explains how Pyodide and a WebAssembly-based socket bridge enable database drivers and HTTP clients, and describes ecosystem improvements such as PEP 783 (PyEmscripten) and tooling updates to expand package compatibility.
read more →

Cloudflare reclaims 100 TB RAM with hashing fix

🔎 This post describes how Cloudflare reduced memory usage in its Pingora Backend Router by optimizing consistent hashing. The team identified excessive memory in the pingora-ketama structures and analyzed how hash counts, weights, and collisions affect load distribution. A Rust-level storage change and mathematical analysis allowed them to safely shrink per-server hash counts and reclaim significant RAM without disrupting cache routing.
read more →

Client-side security uncovers four malicious campaigns

🔍 Cloudflare describes how its Page Shield Client-Side Security ML uncovered four distinct malicious JavaScript operations running on storefronts. The post explains that automated GNN analysis (with LLM second opinions) detected eight payloads in live traffic that other scanners missed, and details how the scripts siphoned affiliate revenue, hijacked clicks, suppressed analytics, and conditionally loaded remote code. It highlights delivery via tag managers, typosquatted hosts, time- and browser-gated execution, and the need for sustained browser visibility to catch cloaked threats.
read more →

Cloudflare introduces Disallow AI Training control

🔒 Cloudflare announces a new Disallow AI Training setting to let site owners remain indexed for search while refusing AI training of their content. The company defines an Accountable designation for crawler operators who meet transparency and control requirements; Apple, Google, and Microsoft qualify. Cloudflare will publish preferences in robots.txt, classify crawler behavior, and apply domain-level controls for Training, Search, and Agents.
read more →

Cloudflare Workers add resource-level authorization

🔐 Cloudflare now supports Worker-level access controls and four new roles so teammates and agents can be granted access to a single Worker instead of an entire account. Roles range from Metadata Read-Only and Content Read-Only to Editor and Admin, enabling observability, code review, deployment, or full management without excessive privileges. Permissions can be assigned to users, API tokens, or groups via the dashboard, API, or Terraform.
read more →