< ciso
brief />
Tag Banner

All news with #cloudflare tag

447 articles · page 4 of 23

Cloudflare CASB adds automatic remediation policies

🔒 Cloudflare introduces automatic remediation policies for Cloudflare CASB, enabling security teams to define event-driven responses that revoke risky file shares or dispatch custom webhooks without manual steps. CASB previously provided visibility into SaaS misconfigurations; the new feature extends that visibility with native, automated remediation executed via Cloudflare One. Policies run on the Cloudflare developer platform and Workflows to ensure durable, rate-limit aware execution and deliver completion logs for audit and compliance.
read more →

Cloudflare Enables ML-DSA-44 Validation on 1.1.1.1

🔒 Cloudflare’s 1.1.1.1 resolver now validates DNSSEC signatures created with the post-quantum algorithm ML-DSA-44, a NIST-standardized scheme. This step lets Cloudflare test large signature transport and downgrade-resilience at Internet scale while planning full post-quantum DNSSEC support by 2029. The update is automatic for users when zones publish the requisite DNSSEC records.
read more →

Cloudflare Workers new module registry aligns with Node

🛠️ The Workers runtime's module registry in workerd has been rewritten to improve speed, standards compliance, and alignment with Node.js module semantics. Enabling the new_module_registry flag activates features like import.meta.url, import.meta.main, and import.meta.resolve(), Node-style require(esm) behavior, and correct handling of json import attributes. The registry now uses URL-based specifiers, supports separate module files (including Wasm) and shared compilation caches, and enables bundlers like Rollup/Vite to rely more on the runtime for resolution.
read more →

Cloudflare Enables Automatic Key Exchange for Origins

🔐 Cloudflare introduces Automatic Key Exchange, extending Automatic SSL/TLS to probe origin servers and choose the optimal TLS 1.3 key agreement on the first ClientHello. This measurement-driven approach replaces a static X25519 guess, dramatically reducing HelloRetryRequests and lowering handshake latency while enabling broader post-quantum hybrid key usage. The feature is active by default and includes compliance filters for operators who need to restrict allowable algorithms.
read more →

Cloudflare launches Vulnerability Discovery and Remediation

🔍 Cloudflare is offering early access to Vulnerability Discovery and Remediation, a managed service that scans authorized customer codebases using OpenAI Daybreak models (including GPT-5.6 Cyber) to find and prioritize vulnerabilities. The service correlates source findings with production traffic, WAF signals, and security events to produce prioritized fixes and scoped WAF mitigations. Customers review proposed patches and rules before any change is made.
read more →

Cache Transcoding expands effective CDN cache capacity

🧩 Cloudflare prototyped Cache Transcoding to increase effective cache capacity by encoding eligible cache entries with Zstandard (zstd). The system encodes eligible responses on cache fill, stores them compressed on disk and transfers them compressed between tiers, then decodes before serving. In tests zstd level 3 reduced on-disk size to roughly one-third for eligible text assets while adding only a small CPU cost, improving storage density and inter-datacenter bandwidth efficiency.
read more →

White House launches Project Watershed 250 pilot

🛡️ The White House has launched Project Watershed 250, a pilot program in Texas to provide water and wastewater utilities with federal and private-sector cybersecurity resources at no cost. Announced jointly by Governor Greg Abbott and National Cyber Director Sean Cairncross, the six-month initiative will deploy expertise from vendors including Microsoft, Google, AWS, Cloudflare, Palo Alto Networks, Forescout and Dragos. Supported by Texas Cyber Command, the pilot aims to identify vulnerabilities and strengthen defenses for rural and urban water providers amid growing OT-targeted threats tied to nation-state actors.
read more →

Cloudflare launches Adaptive Intelligence for bots

🛡️ Cloudflare today unveiled Adaptive Intelligence, a new non-deterministic bot detection engine designed to make attacks slow and costly rather than trying to keep every attacker out. It continuously retrains on live traffic, generates short-lived disposable rules, and learns from labeled corrections across the network to reduce attacker feedback. The approach complements behavioral validation and aims to balance protection with low false positives for real users.
read more →

Cloudflare launches BotBase for Operators

🛡️ This post introduces BotBase for Operators, a new Cloudflare dashboard experience that gives bot operators visibility and control over their submissions. Operators can now find the submission form under Protect & Connect → Application Security → BotBase, view submission history and statuses, edit or cancel entries, and filter "My bots." The intake form asks operators to declare what the bot does, how it uses content, and who runs it, aligning with the Content Signals model. Automated checks speed up reviews by validating identifiers, IP lists, reverse DNS, or Web Bot Auth, routing only ambiguous cases to human reviewers. The goal is better transparency and ongoing operator participation in the bot ecosystem.
read more →

Optimizing DNS cache memory for Cloudflare scale

🧠 Cloudflare’s Big Pineapple platform stores over 250 billion DNS cache entries and reduced per-entry memory by over 50% through five successive storage optimizations. These changes freed roughly 100 TB of RAM across the fleet while improving insert throughput by 43% and lowering lookup latency by 19%. The post details techniques like replacing Vec/String with Box, packing section offsets, inferring record owners, boxing large enum variants, and storing record data as a contiguous byte buffer to improve memory locality and reduce allocations.
read more →

Cloudflare Blog migration to EmDash CMS

📝 Cloudflare migrated its blog to EmDash, a CMS built for Astro and Cloudflare, moving on August 12. The redesign added dark mode, Kumo-aligned frontend patterns, and improved caching and performance. A staged rollout with a proxy Worker ensured zero downtime while enabling new agent-friendly features like a Model Context Protocol (MCP) server.
read more →

Cloudflare launches Bot Preference Sync for robots.txt

🛡️ Cloudflare introduces Bot Preference Sync to align zone-level AI bot settings with a site's robots.txt, available to all customers from Free to Enterprise. The feature prepends generated directives to any existing robots.txt so owners' Search, Agent, and Training preferences match edge-enforced rules and managed blocks. Bot Preference Sync is on by default for new customers and can be disabled by those who need custom, fine-grained policies.
read more →

Cloudflare introduces OAuth scope customization

🔒 Cloudflare announced task-based OAuth consent to let client owners mark specific scopes as optional, enabling users to grant a narrower subset of requested access during authorization. The change builds on OAuth's existing ability to grant fewer scopes than requested and keeps existing client behavior by default. Developers must check granted scopes after the token exchange and can opt in when configuring a client.
read more →

CDN Tsunami: HTTP/3-to-HTTP/1.1 Amplification Risk

🔍 Researchers disclosed two denial-of-service techniques, collectively dubbed CDN Tsunami, that exploit how major CDNs translate client-facing HTTP/3 into backend HTTP/1.1 requests, amplifying small attacker traffic to large origin load. The study tested Alibaba, Baidu, Cloudflare, CloudFront, Fastly, and Tencent, finding widespread susceptibility to a bandwidth amplification variant and partial susceptibility to a connection-amplification variant. Vendor mitigations are applied at CDN edges, and the work will be presented at a September 2026 symposium.
read more →

Remote Spectre leak against Cloudflare Workers revealed

🔐 Researchers disclosed a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker at up to 12 bits per second, far exceeding the 2021 rate. The experiment used attacker and victim Workers controlled by researchers, with Cloudflare confirming mitigations deployed in production and reporting no signs of active exploitation. Cloudflare improved Dynamic Process Isolation (DyPrIs), integrated the V8 Sandbox, and added MPK-based in-process isolation to address the weakness.
read more →

Revisiting Spectre Attacks on Cloudflare Workers

🔍 In 2024–2025 research, Cloudflare reassessed remote Spectre attacks against Cloudflare Workers and tested defenses introduced in 2021, notably Dynamic Process Isolation (DyPrIs). The team rebuilt a production proof-of-concept showing a reliable remote Spectre leak under production workloads, found a DyPrIs limitation, and implemented further mitigations including the V8 Sandbox and in-process isolation. The report emphasizes the attack was mitigated in production and no active exploitation was observed in the past three years.
read more →

RFC 9234: BGP Role Model and OTC Adoption

🛡️ RFC 9234 introduces a BGP Role capability and an Only to Customer (OTC) path attribute to encode neighbor relationships and prevent route leaks directly in the protocol. Cloudflare measured adoption by monitoring which peers send OTC to its network and discovered that two large Tier‑1 networks strip OTC. The post explains how Roles and OTC function, why OTC stripping undermines deployment, and offers guidance for operators to enable Roles for route leak protection.
read more →

Cloudflare One updates for MCP security

🔒 Cloudflare announces new Cloudflare One capabilities to detect and control Model Context Protocol (MCP) traffic. These features let administrators identify which users and servers are generating MCP requests, distinguish Portal-mediated connections from direct ones, and block unauthorized direct connections on managed network paths. The update combines Gateway protocol signals with MCP Server Portals to help teams find shadow MCP servers and enforce Portal-only access to trusted MCP endpoints.
read more →

Protect Workers with Cloudflare Access by Default

🔐 Cloudflare now lets you apply Access directly to a Worker or to all Workers in an account so applications are protected by your company login by default. When enabled, Access enforces authentication before any request reaches Worker code, regardless of domain, route, or preview URL. Policies can be set per hostname, per Worker, or account-wide, with the most specific policy taking priority. Developers can also access authenticated user details through ctx.access.getIdentity() for personalization and logging.
read more →

Solar eclipse caused measurable internet traffic dips

🌑 Cloudflare Radar analyzed HTTP request volumes during the August 12 total solar eclipse that crossed Iceland, northern Spain and Portugal, comparing five-minute slices to a same-weekday baseline. The data show pronounced traffic declines aligned with maximum obscuration, with regions along the path of totality dropping roughly 15–30% and rebounds occurring within minutes. Variations reflect local factors like time of day, cloud cover, and population distribution, while calculations used precise geometric obscuration of the sun and moon.
read more →