< ciso
brief />
Tag Banner

All news with #cloudflare tag

447 articles · page 8 of 23

Threatsday bulletin: proxyware, exploits, and trends

🛡️ This week’s bulletin highlights a string of practical and persistent threats: privacy-preserving bot defense work from Cloudflare and browsers, six serious curl vulnerabilities fixed in 8.21.0, and a critical unauthenticated takeover in Hoppscotch. Spur Intelligence found widespread proxyware in LG and Samsung smart TV apps, while Teams-based social engineering delivered the Edgecution extension. Other items include legacy credential breaches, state-crime convergence, admin reset alerts, and macOS ClickFix campaigns.
read more →

Cloudflare Opens Self‑Managed OAuth to All Customers

🔐 Cloudflare announced self-managed OAuth, allowing any customer to create and manage OAuth clients for delegated access to the Cloudflare API. The company upgraded its underlying OAuth engine (Hydra) through staged 1.X and 2.X migrations, implemented blue‑green cutovers, and used queues to preserve revocations during the transition. Post‑upgrade improvements reduced latency and resource usage and enabled broader, safer integration patterns for developers.
read more →

U.S. Executive Order Accelerates PQC Adoption

🔒 On June 22, 2026, President Trump signed Executive Order 14409, setting federal deadlines to adopt post-quantum cryptography: key establishment by December 31, 2030, and authentication by December 31, 2031, with contractors required to comply by 2030. Cloudflare supports the EO, noting federal procurement has historically driven industry adoption and highlighting that post-quantum encryption deployment is already widespread across its services while authentication work continues. The EO focuses on NIST-standardized PQC, excludes National Security Systems, and directs OMB and agencies to plan and report migration progress.
read more →

Race condition in hyper caused truncated image responses

🛠️ Cloudflare’s Images service, built in Rust on Workers, encountered intermittent truncation of larger transformed images after a 2025 rearchitecture that connected Workers to Images via a local binding. The failure returned HTTP 200 with a shortened body and no logged errors, appearing only under production concurrency and reproducible as a timing-dependent race in the hyper HTTP library. Instrumentation, strace, and controlled reproductions identified premature shutdown calls from the Images service that left most response bytes in hyper’s internal buffer; a four-line change ultimately fixed the issue.
read more →

Cloudflare introduces temporary agent accounts

⚙️ Today Cloudflare announced Temporary Cloudflare Accounts for AI agents, enabling agents to run wrangler deploy --temporary to deploy Workers instantly without human sign-up. Temporary deployments remain live for 60 minutes and can be claimed by a user to become permanent; unclaimed accounts expire automatically. The feature integrates with Wrangler, which now informs agents about the --temporary flag, letting agent-driven development iterate quickly through deploy, verify, and redeploy cycles.
read more →

Building a Model-Agnostic Vulnerability Harness

🔧 This post describes how Cloudflare evolved a single-repo security skill into a fleet-scale, model-agnostic Vulnerability Discovery Harness (VDH) and a separate Vulnerability Validation System (VVS). It explains why single-agent prompts fail at scale and why treating models as interchangeable components improves coverage. The article outlines stages like Recon, Hunt, Validate, Trace, Dedup, Gapfill, and Feedback and emphasizes persistence, strict context controls, and cross-repo reasoning.
read more →

Cloudflare Celebrates 12 Years of Project Galileo

🎉 Project Galileo provides free cybersecurity services to over 3,400 websites belonging to journalists, human rights defenders, and nonprofits across 120 countries. Cloudflare published its first comprehensive report on cyberattacks targeting civil society, released 16 participant case studies, and announced new partners. The findings show civil society faces more frequent and intense attacks, including prolonged DDoS, higher exploitation attempts, and elevated phishing rates. Cloudflare calls for broader, affordable protections and will produce this report annually.
read more →

Cloudflare Agents SDK and Flue for production agents

🛠️ Cloudflare describes how the Agents SDK provides durable execution, dynamic code execution, a durable filesystem, and dynamic workflows as platform primitives to run agent harnesses in production. The new Flue framework (1.0 Beta) builds on the Pi harness and targets Cloudflare Durable Objects to offer declarative agent development, integrations with Slack/GitHub/Discord, headless UI hooks, and Durable Streams for reliable checkpointing. Flue uses runFiber(), stash(), onFiberRecovered(), @cloudflare/codemode, and @cloudflare/shell to securely execute LLM-generated code, provide a virtual filesystem, and enable durable, resumable agent turns at low cost.
read more →

Cloudflare releases Cloudflare One stack for Zero Trust

🛡️ Cloudflare announced the Cloudflare One stack, a pair of agent skills designed to automate planning, deploying, migrating, and managing Zero Trust environments. The toolkit packages Cloudflare’s institutional migration expertise into two skill files — cloudflare-one and cloudflare-one-migration — to assist with VPN replacement, Gateway policies, connectivity, vendor-to-vendor translation, and troubleshooting. When paired with the Cloudflare code mode MCP server, agents gain typed, controlled access to the Cloudflare API for live inventory, configuration inspection, and curated change workflows.
read more →

Cloudflare DMARC Management Generally Available

📣 Cloudflare has made DMARC Management generally available and free for customers, offering a redesigned dashboard to simplify the path to full DMARC enforcement. The tool unifies visibility into SPF, DKIM, DMARC, and BIMI, surfaces sending source IPs, and integrates Cloudflare threat intelligence for investigation. It provides automated record analysis with pass/warning/fail statuses and plain-language recommendations, plus an SPF lookup audit to reveal and resolve the 10-lookup limit. DMARC Management requires Cloudflare DNS and is enabled from Email > DMARC Management in the dashboard.
read more →

Chainguard launches Athena coalition to protect OSS

🔒 Chainguard has launched Athena, an industry coalition announced on June 16 to protect open-source software from attacks facilitated by frontier AI models. Founding members include BNY, Cisco, Cloudflare, Docker, JPMorganChase, PwC and others. Athena pools vulnerability findings into a shared platform, applies private patches and provides mitigations to members before public disclosure. The initiative aims to coordinate upstream fixes and partner with the Linux Foundation for broader incident response support.
read more →

Cloudflare expands AI infrastructure team with Ensemble hire

🚀 Today Cloudflare announced that key members of Ensemble AI are joining the company to accelerate AI infrastructure work and help developers run powerful models efficiently at scale. Ensemble AI developed methods like NdLinear and NdLinear-LoRA to preserve model structure while reducing parameters and compute, complementing quantization and vector quantization. The hire strengthens Cloudflare Workers AI and advances efforts to lower inference costs, improve GPU utilization, and enable global, serverless model deployment.
read more →

Scaling Security Scans to Serve Millions

🔍 Cloudflare’s Security Insights runs automated scans to surface risks across accounts, zones, and DNS records. They faced two problems: scans were too infrequent (up to two weeks) and many free accounts were opt-in only. To resolve this they increased scanning throughput ~10x, redesigned Kafka consumers, optimized Postgres bulk inserts, centralized API latency to follow the primary DB, and improved scheduling with per-zone timing, randomization, and adaptive rate limiting.
read more →

Cloudflare adds private origin routing for apps

🛡️ Today Cloudflare launched Application Services for Private Origins in closed beta for eligible Enterprise customers, enabling secure routing to private IP origins without exposing them to the public Internet. This lets Cloudflare’s WAF, bot management, rate limiting, Workers, and other services sit in front of private applications using existing private connectivity such as Cloudflare Tunnel, Cloudflare Mesh, or Cloudflare WAN. The feature uses a toggle on proxied DNS records or an API attribute to instruct Cloudflare’s private networking layer to route traffic to private networks, and extends Layer 4 support via Spectrum for TCP/UDP services.
read more →

Defending Applications Against Frontier Model Threats

🔒 Cloudflare describes an architectural approach to defend applications and internal systems from high-speed attacks enabled by frontier AI models. The post explains how layered controls — including WAF, ML-based scoring, API Shield, Bot Management, Zero Trust, IdP federation, MCP server controls, and AI Gateway — work together to reduce discovery, limit exploit adaptation, and contain impact. It emphasizes deploying inspection ahead of public apps, defining valid API traffic, restricting automated probing, and enforcing per-request identity for internal tools.
read more →

Cloudflare adds realtime threat intel to WAF

🛡️ Cloudflare now exposes live Threat Events signals directly to its WAF engine, enabling security teams to create proactive rules using attacker names, target industries, countries, attack types, and dataset sources. The integration enriches HTTP request metadata in real time without adding noticeable latency, supporting both UI and Infrastructure-as-Code workflows via API and Terraform. Matches are logged in Security Analytics for auditing, and Saved Views can be exported directly into WAF rules for streamlined operations.
read more →

Cloudflare AI Gateway Adds Dollar-Based Spend Limits

🛡️ Cloudflare announces spend controls in AI Gateway, plus a closed beta for identity-driven budgets and routing using Cloudflare Access and existing identity providers. The update introduces dollar-denominated budgets, real-time cost tracking, and options to block or route requests when limits are reached. Identity integration enables per-user and per-team attribution and policies to manage who can access which models and how much they may spend.
read more →

HTTP/2 header flaw enables new DoS attacks

🔍 Security researchers disclosed a flaw in default HTTP/2 configurations that enables a denial-of-service technique dubbed the "HTTP/2 Bomb." The issue abuses HPACK header compression and flow-control behavior to force excessive memory allocations and hold them, impacting servers such as nginx, Apache HTTP Server, Microsoft IIS, Envoy, and Cloudflare’s Pingora. Patches have been released for several implementations, and mitigations include disabling HTTP/2 or enforcing header count caps.
read more →

Enforce First AS to Prevent BGP Path Forgery

🔍 Recent route hijacks exploited unused ASNs and forged AS_PATHs to misdirect traffic and conceal attackers. Cloudflare analyzed incidents reported by Spamhaus and found implausible AS relationships indicating path fabrication, including forged paths that inserted Cloudflare’s ASN. The post explains how enforcing the First AS in an AS_PATH, per RFC 4271 and RFC 7606 guidance, would block such manipulations. Cloudflare also conducted safe tests against Tier 1 peers to measure First AS enforcement and observed variation in vendor and operator behavior.
read more →

Reducing Core Server Boot Time After Firmware Update

🚀 After a firmware update, Cloudflare's Gen12 core servers experienced boots stretching from minutes to hours due to repeated network boot timeouts. The team traced the issue to UEFI probing every available network boot interface sequentially and fixed it by declaring the correct boot interface early in the PXE pre-boot stage. They implemented validation, vendor collaboration, and tooling enhancements (including regex matching and a uefi-same-hex flag) to enforce persistent settings. The result cut firmware upgrade automation from nearly four hours to about three minutes and subsequent boots from ~20 minutes to under a minute.
read more →