< ciso
brief />
Tag Banner

All news with #cloudflare tag

447 articles · page 5 of 23

Cloudflare reduces noise in CT monitoring alerts

🛡️ Certificate Transparency Monitoring, launched in public beta in 2019, now filters out certificates Cloudflare issues on customers' behalf before sending alerts. This change addresses noisy notifications caused by routine Universal SSL renewals and other Cloudflare-managed certificates. The service is generally available and will only notify customers about certificates issued outside Cloudflare's automated systems. Settings remain available in the Cloudflare dashboard.
read more →

Signal adds automatic key verification feature

🔐 Signal introduced Automatic Key Verification, a new feature within a key transparency system that uses Cloudflare and Trail of Bits as independent auditors to confirm the integrity of encrypted chats. The feature enables users to verify contacts’ public keys automatically via Settings > Privacy > Advanced or by selecting "Verify Automatically" on the safety number screen, showing a green checkmark when successful. Users may disable it and continue with manual safety number checks if they prefer. Signal says this complements existing safety numbers and helps prevent undetected key swaps and man-in-the-middle attacks.
read more →

Cloudflare: Massive rise in >1 Tbps DDoS attacks

🛡️ Cloudflare reported it mitigated over 800 network-layer DDoS attacks exceeding 1 Tbps in Q2, a more than fivefold increase from Q1's 130 such events. The company, which protects roughly 20% of the web, also defended against a record 31.4 Tbps attack by the Aisuru/Kimwolf botnet. In H1 it mitigated 23.2 million network-layer attacks and handled 29.64 trillion malicious HTTP requests, while noting most attacks remained small and short-lived.
read more →

Cloudflare DDoS Threat Report H1 2026 Summary

📊 Cloudflare's H1 2026 DDoS Threat Report from Cloudforce One summarizes DDoS activity across January–June 2026. The report details mitigation of 23.2 million network-layer attacks and 29.64 trillion HTTP requests, highlights April as a peak month, and describes growth in hyper-volumetric and reflection-based vectors like CLDAP. It emphasizes the necessity of automated, always-on protection.
read more →

Cloudflare’s Agents Week: Building an Agentic Internet

🤖 Over Agents Week, Cloudflare outlined how agents are shaping a new class of software and detailed the platform work required to support AI-native applications. The company presented daily briefings covering runtime and infrastructure, the Agent Development Lifecycle (ADLC), Zero Trust for agents, the concept of an Agentic Internet, and measurement tools for agent behavior on the web. Cloudflare emphasized secure execution layers, developer primitives, and community collaboration as core to this evolution.
read more →

Cloudflare Achieves FedRAMP High Certification

🔒 Cloudflare for Government has achieved FedRAMP Class D (High) certification, marking a major milestone in meeting rigorous U.S. federal security standards. Built on Cloudflare’s single global network and its Data Localization Suite, the FedRAMP High offering ensures processing and storage of inspected traffic within U.S. data centers. This foundation also supports Cloudflare’s pursuit of DoD IL4 authorization to serve defense-sector needs.
read more →

Assessing Good and Bad Agentic Behaviors Online

🔍 Cloudflare outlines how the line between human and automated traffic is blurring and why site owners must evaluate continuous behaviors rather than one-time checks. The post explains the team’s Risk vs. Trust framework, introduces tools like Precursor for continuous client-side behavioral analysis and the BotBase directory for tracking bot reputations, and previews Adaptive Intelligence and advanced mitigations for managing agentic traffic responsibly.
read more →

Cloudflare refreshes community and open-source support

🛠️ Cloudflare announced a refreshed community program with two main tracks: Cloudflare Ambassadors and Community Engineers. Ambassadors will receive resources, visibility, and support to run events, teach, and grow local communities, with applications open through September 6. Community Engineers will receive grant funding to support open-source maintainers, backed by a $1M commitment and an additional $1M for Vite-related work. The update also creates a Discord committee to improve community collaboration and reduce moderation burden with new automation.
read more →

Cloudflare Radar Researcher beta launches

🛰️ Cloudflare launches Radar Researcher in beta, an AI-powered assistant that lets users query Radar’s open Internet datasets in plain language and receive interactive charts. The tool combines screenshots, raw API data, and view parameters to generate precise explanations and visualizations. Built on Cloudflare Workers, Agents SDK, and Workers AI, Researcher runs models with fallbacks, exposes tool traces, and uses Code Mode to query the Radar API dynamically.
read more →

Cloudflare unifies Workers AI and AI Gateway

🛠️ Cloudflare is consolidating AI Gateway and Workers AI into a single unified control plane and entrypoint. The unified path provides a shared binding and a single /ai/ REST API endpoint, enabling automatic creation of a default gateway for immediate observability, logging, token tracking, and cost attribution. Users can route to any provider or Workers AI with unified billing and optional elevated rate limits when using AI Gateway credits.
read more →

Check Point Research at Black Hat USA 2026

🛡️ Check Point Research presented four technical talks at Black Hat USA 2026 exposing trusted layers attackers abuse. Researchers dissected a decade-old Windows kernel driver in Defender, found post-injection exploitation paths across major AI agent frameworks, developed a pipeline to decompile compiled V8 bytecode malware, and identified sandbox escape vulnerabilities in Cloudflare’s Code Mode. Each talk highlighted how trusted or overlooked components can be repurposed offensively.
read more →

Cloudflare Simplifies AI Search Setup and Pricing

🛠️ Cloudflare announced developer experience improvements to AI Search, automating the assembly of Workers AI, AI Gateway, Vectorize, R2, and Browser Run so teams can deploy search instances out of the box. The update includes public /search and /mcp endpoints, optional Cloudflare Access for private instances, and multi-instance querying via Workers or public endpoints. A pricing preview is provided, with embedding and reranking free on default models while in beta.
read more →

Building the Open Agentic Internet for Agents

🔎 Cloudflare outlines the rise of software agents as a new class of web visitors and presents the concept of an "Agentic Internet" built to be readable, discoverable, callable, and payable. The post describes open standards and tools—like Web Bot Auth, PACT, Markdown for Agents, WebMCP, and Monetization Gateway—that enable cooperation between agents and domain owners. Cloudflare positions itself as a neutral platform offering these primitives while advocating for an open, standards-based future.
read more →

Cloudflare launches Kitesurf: a browser for agents

🛰️ Kitesurf is a new browser built by Cloudflare to run entirely on top of Workers and optimized for AI agents. It targets agentic tasks by being far more efficient in CPU and memory than Chromium for common operations like screenshots and HTML extraction. The design emphasizes isolation, stateless components, robust exception handling, and extensive testing using Web Platform Tests plus integration and visual regression suites. Kitesurf’s architecture separates the Engine, PageScript, and PageRenderer, uses Rust-compiled WebAssembly where possible, and enforces network access through a SandboxOutbound worker to minimize risk.
read more →

How to Make Your Site Discoverable to AI Agents

🤖 Cloudflare explains that customers increasingly find businesses via AI assistants rather than human-led search, so site owners must optimize for agent discoverability. The company has integrated Agent Readiness diagnostics and a new Answer Engine Optimization (AEO) tool into the Cloudflare dashboard to show how agents read, fetch, and recommend sites. These tools run checks against robots, sitemaps, headers, and machine-readable content, simulate assistant queries (e.g., Anthropic, OpenAI), and provide actionable remediation steps with links to Cloudflare settings or copyable prompts. The AEO feature benchmarks your category against competitors, measures citations and referral behavior, and surfaces operator crawl and referral patterns so you can iterate and improve recommendations.
read more →

Cloudflare launches WebMCP developer preview

🔧 Cloudflare is launching a developer preview of WebMCP, a browser standard that exposes a document.modelContext surface to enable AI agents to interact with sites without changing origin code. With a single toggle in the Cloudflare Dashboard, an edge injection adds a small bridge script that registers tool packs in the visitor's browser. Two packs—Content Credentials and Site MCP Server—run entirely client-side in this preview, while future packs may call edge workers for heavier tasks.
read more →

Cloudflare Named Visionary in Both 2026 Magic Quadrants

🔒 Cloudflare reports it was named the only vendor recognized as a Visionary in both the 2026 Gartner Magic Quadrant for SASE Platforms and the 2026 Gartner Magic Quadrant for Security Service Edge. The post credits customer feedback and highlights Cloudflare One’s unified SASE architecture, built-in AI agent governance, native post-quantum encryption, and predictable pricing. It argues that modern SASE must be composable, programmable, and ready for agentic operations and quantum threats.
read more →

Cloudflare’s Internal Platform for Safe AI Use

🧭 Sam Rhea, Cloudflare’s CIO, describes how the company built Cloudflare OS to enable safe, productive AI use across teams. Initially cautious in 2025, the company accelerated when powerful AI agents emerged, prompting internal pilots for engineers and non-engineers. Cloudflare OS combines off-the-shelf components with custom services, a contextual Codex for engineering, and a Model Context Protocol to enforce scoped permissions. The platform routes model calls through an AI Gateway for filtering, logging, and cost and model controls.
read more →

Cloudflare Identity-Aware AI Gateway Launch

🛡️ Cloudflare announces Identity-aware AI Gateway with Cloudflare Access in open beta and User Insights generally available to AI Gateway customers. The integration attaches verified user identities to each request as cf.user_id, enabling per-user spend limits, filtering, and auditing. AI Gateway centralizes model access (OpenAI, Anthropic, Google, Workers AI) and routes agent harnesses like Copilot through a single control plane. User Insights builds behavioral baselines from traffic to surface anomalous accounts and cost inefficiencies without blocking traffic.
read more →

Cloudflare introduces WriteGuard for MCP portals

🛡️ Cloudflare describes WriteGuard, a centralized policy, attribution, and auditing layer for MCP servers now available in private beta. It sits between MCP clients and tool handlers to classify calls by risk, attach agent attribution, scrub audit events, and block dangerous actions before execution. The post explains how WriteGuard integrates with existing identity flows, per-tool configuration, and an asynchronous audit Worker to make agentic writes visible and controllable across MCP-connected systems.
read more →