< ciso
brief />
Tag Banner

All news with #cloudflare tag

447 articles · page 7 of 23

BGP ORIGIN Attribute Manipulation and Impact

📘 Cloudflare examines the BGP ORIGIN attribute, a mandatory path attribute intended to signal how a route was injected into BGP. Their experiments show widespread modification of ORIGIN values—predominantly to IGP—by many networks, including Tier-1s, altering route selection and diverting traffic for commercial advantage. The report describes methodology, measurements across IPv4/IPv6, and the resulting routing and economic impacts.
read more →

Cloudflare introduces post‑origin Cache Response Rules

🛠️ Cloudflare announced Cache Response Rules, a new rule type that runs after an origin response arrives but before Cloudflare caches it. These rules let you rewrite Cache-Control, manage cache-tags, and strip headers like Set-Cookie, ETag, and Last-Modified without changing the origin. The feature complements existing Cache Rules by giving the response phase final control over whether and how Cloudflare caches content.
read more →

Global Internet Traffic Shifts During the 2026 World Cup

📈 Cloudflare Radar analyzed HTTP, DNS, and security signals across its global network during the June–July 2026 World Cup to measure how matches changed Internet activity. Using a four-week median baseline and log2 ratios, the study compared per-country deviations by kickoff time, revealing large spikes for overnight matches and smaller evening bumps. The report ranks matches and teams by worldwide impact and examines regional behaviors, streaming effects, and distinct halftime and hydration-break patterns.
read more →

Cloudflare Launches Internal DNS for Enterprises

🔒 Cloudflare Internal DNS is now generally available, providing authoritative and recursive DNS for private networks on the same control plane used for public DNS, Zero Trust, and networking. It consolidates public and private DNS management, simplifies split-horizon setups, and extends Zero Trust enforcement to DNS. Enterprise customers get this capability included with Cloudflare Gateway, with Terraform support and integration across Cloudflare connectivity methods.
read more →

Cloudflare deploys WAF rules for WordPress RCE and SQLi

🛡️ Cloudflare has deployed new Web Application Firewall protections to block two critical WordPress vulnerabilities: an unauthenticated RCE in the REST API and a related SQL injection. The rules, activated on July 17, 2026 at 17:03 UTC, protect all proxied customers including Free plans. Customers should still apply WordPress patches (7.0.2 and backports) and ensure Managed Rules remain set to Block while monitoring Security Events.
read more →

Cloudflare explains DNSSEC NTA and EDE 33

🛡️ On July 3, 2026, Albania's .AL TLD experienced a failed DNSSEC key rollover that caused widespread validation failures for validating resolvers, including Cloudflare's 1.1.1.1. Cloudflare applied a Negative Trust Anchor (NTA) to restore resolution and for the first time returned a new Extended DNS Error (EDE 33) to signal that DNSSEC validation had been bypassed. The change provides visibility into responses served under an NTA and complements EDE codes like EDE 9 to show the underlying DNSSEC failure.
read more →

Cloudflare launches Precursor for session detection

🔍 Precursor is a client-side, session-scoped verification system from Cloudflare that continuously collects behavioral signals via a lightweight injected script to distinguish humans from bots across an entire user journey. It complements Turnstile as part of Enterprise Bot Management, feeding session-level signals into edge evaluators and existing bot-scoring and challenge systems. Designed with privacy in mind, Precursor captures minimal interaction metadata (timing, rhythms, movement patterns) rather than content and provides session-based analytics in Security Analytics. It is rolling out now and will be free until GA.
read more →

New MODBEACON Rust RAT Uses gRPC Streaming

🛡️ QiAnXin attributes a new Rust-based remote access trojan named MODBEACON to the China-linked Silver Fox cluster. The memory-resident implant uses a modular, plugin-based architecture and leverages gRPC tunnel streaming with transport borrowed from open-source proxy tools (Xray/V2Ray) for its C2 channel. Distributors push the malware via counterfeit installers promoted through SEO poisoning and host C2 infrastructure on Amazon and Cloudflare CDNs.
read more →

Smart Tiered Cache for public cloud regions

🔧 Smart Tiered Cache now supports public cloud regions by accepting a user-provided region hint. Cloudflare maps ambiguous anycast or regional unicast origins to the correct cloud region so it can select optimal primary and fallback upper tiers, improving cache efficiency and reducing hairpin latency. The feature is available via dashboard, API, and Terraform and initially supports AWS, GCP, Azure, and Oracle Cloud.
read more →

Cloudflare on ML‑DSA and the PQ signature landscape

🔒 Cloudflare explains why ML‑DSA, the NIST‑standardized post‑quantum signature, must be used for the initial migration even though better schemes may arrive later. The post‑quantum transition is underway: most traffic already uses ML‑KEM encryption, and Cloudflare targets full post‑quantum protection by 2029. The post outlines tradeoffs among candidate signature families — size, speed, and implementation risks — and highlights why specialization and generalist schemes will both be needed.
read more →

Introducing Meerkat: Cloudflare’s New Consensus Service

🟢 Cloudflare introduces Meerkat, an experimental distributed consensus service designed to provide strong consistency and global fault tolerance across 330+ data centers. Built atop the QuePaxa algorithm, Meerkat lets every replica accept writes and avoids leader-timeout availability failures common in Raft. Initially internal, Meerkat hosts applications like a transactional key-value store and leasing system by converting client operations into a replicated log, ensuring linearizability and majority-based safety.
read more →

Cloudflare joins UK cyber resilience pledge

🔐 Cloudflare announced it has joined the UK government's Cyber Resilience Pledge as a founding signatory, aligning with the pledge’s pillars of democratized security, leadership accountability, and radical transparency. The post highlights rising cyber threats — including massive DDoS volumes and AI-driven attack vectors — and describes how Cloudflare's global network, zero trust controls, and free protections support resilience across the UK economy. Cloudflare emphasizes supply-chain assurance, board-level governance, and international certifications to meet the pledge's aims.
read more →

Why CAPTCHAs are Disappearing from the Web

🔍 CAPTCHAs began as distorted text and audio tests but have evolved into image challenges and now experimental gesture videos as AI improves. Google’s new hand-gesture approach records brief camera footage to verify 21 hand key points, raising privacy concerns despite reassurances about data handling. Alternative defenses include behavioral analysis, Cloudflare Turnstile, and hCaptcha, while passkeys offer a passwordless path that can reduce the need for human checks.
read more →

Cloudflare Workers Cache: Tiered Edge Caching

🧭 Today Cloudflare launched Workers Cache, a tiered cache that sits in front of your Worker and is enabled via a simple Wrangler config and standard Cache-Control headers. Cacheable requests hit Cloudflare first so fresh responses are returned without running the Worker; on a miss the Worker runs and stores the response for subsequent requests. The cache supports stale-while-revalidate, Vary, tag- and prefix-based purges, and per-entrypoint control, and is available to all Workers on any plan.
read more →

Cloudflare Expands AI Bot Controls and Taxonomy

🛡️ Cloudflare updates its bot management to distinguish between three AI use cases—Search, Agent, and Training—so site owners can better control access and compensation for their content. The company will change defaults on September 15, 2026, blocking Training and Agent bots on ad-bearing pages while leaving Search allowed. Cloudflare also launched BotBase, a searchable directory of tracked bots, and added a new content-use signal for robots.txt to express preferences like use=reference.
read more →

Cloudflare Monetization Gateway and x402 Payments

🔒 Cloudflare announced the Monetization Gateway, a control plane to charge for any asset protected by Cloudflare — web pages, APIs, datasets, or MCP tools — and to enforce payments at the edge. At launch payments will settle in stablecoins over the open x402 protocol, enabling micropayments and sub-second settlement. The Gateway moves metering and payment verification off your origin while preserving your pricing and rules.
read more →

Agentic Internet: Bot Traffic and Content Market

🧭 Cloudflare reports a rapid shift toward an agent-driven Internet where AI training and mixed-use crawlers dominate. Publishers face falling referral traffic as over 50% of Internet traffic is now non-human, and AI companies increasingly ingest content without compensation. Cloudflare highlights tools and marketplace developments that restore publisher control, enable attribution, and support licensing between content owners and AI firms.
read more →

Cloudflare Proposes New Economics for AI Search

🔍 Cloudflare outlines initiatives to make AI-driven search more efficient and to compensate creators fairly. The company will launch a research program using network signals to surface fresher, higher-quality content and reduce unnecessary crawling. It is also evolving Pay Per Crawl toward Pay Per Use, experimenting with partners like Ceramic.ai and You.com to enable pay-per-query and other payment models.
read more →

Cloudflare launches Attribution Business Insights dashboard

📊 Cloudflare introduces the Attribution Business Insights dashboard to help publishers and business leaders distinguish valuable human referrals from extractive AI crawler traffic. The dashboard provides site-wide and per-operator crawl-to-referral ratios, top bot breakdowns, and updated crawler classifications like Training, Search, and Agent. Available to Cloudflare Bot Management customers, it centralizes visibility so decision-makers can evaluate impact before acting via existing security rules.
read more →

Cloudflare Workflows adds durable saga rollbacks

🛠️ Cloudflare Workflows now supports saga rollbacks, letting developers declare per-step compensation logic directly in step.do() calls. This feature simplifies undoing partial work when later steps fail by running rollback handlers in reverse step-start order and preserving idempotency via idempotency keys. Rollback handlers are durable, configurable with retries and timeouts, emit lifecycle events, and execute only when the Workflow fails terminally.
read more →