
Today at 03:30 UTC we learnt of a compromise of Okta. We use Okta internally for employee identity as part of our authentication stack. We have investigated this compromise carefully and do not believe we have been compromised as a result
JG
John Graham Cumming, Lucas Ferreira·March 22, 2022Security 
We are thrilled to announce Health Checks availability within Cloudflare’s centralized Notification tab, available to all Pro, Business, and Enterprise customers. Now, you can get critical alerts on the health of your origin without checking your inbox!

How do query parameter data types affect performance? Find out how to avoid bad performance by choosing the correct parameter types.

Today, we are rolling out a new beta version of GitHub’s home feed, making it easier to discover projects, developers and more across GitHub.

If you’re a GHES customer with heavy read traffic on your monorepo, check out the repository cache, especially if you have CI workloads distributed around the world.


In 2022, Shopify's Bug Bounty Program is doubling the maximum reward to $100,000 and moving key services into the highest severity level.

Good interface design shows the right things at the right moment. We need to understand when to display a call to action, and how to build a relationship with the user before promting them to act.

In this post, we share some of the insights we’ve gathered from the 32 million HTTP requests/second that pass through our network
MT
Michael Tremante, Sabina·March 21, 2022Security 
Today, we’re proud to report we are the fastest provider in 71% of the top 1,000 most reported networks around the world

Today, we are announcing the addition of 18 new cities in Africa, South America, Asia, and the Middle East, bringing our network to over 270 cities globally

You may not use XHTML (anymore), but when you write HTML, you may be more influenced by XHTML than you think. You are very likely writing HTML, the XHTML way.
JO
Jens Oliver Meiert·March 21, 2022Frontend 
You can now create a branch to work on an issue directly from the issue page so that it’s easier to get started right away.

If there’s one habit that can make software more secure, it’s probably input validation. Here’s how to apply OWASP Proactive Control C5 (Validate All Inputs) to your code.
JL
Jaroslav Lobacevski·March 21, 2022Security 
CSS Custom Properties can be used for far more than just color, and their values update in realtime, both via display mode updates and JavaScript logic. This is powerful stuff. Eric explains how modern CSS is a powerful piece of assistive technology that can thread into it to create flexible, maintainable and adaptive digital experiences.

We continue our technical deep dive into traditional TCP proxying over HTTP


A technical dive into traditional TCP proxying over HTTP


We asked ourselves: can we use our own products to secure IoT devices themselves — even on the same network as production systems? Using Cloudflare One, the answer is yes.

Cloudflare has been hooked on securing customers globally since its inception. Our services protect customer traffic and data as well as our own, and we are continuously improving and expanding those services to respond to the changing threat landscape of the Internet
LM
Ling, Matt Gallagher·March 18, 2022Security 
Today, we’re excited to announce the ability to route traffic from user devices with our lightweight roaming agent (WARP) installed to any network connected with our Magic IP-layer tunnels

Right now we’re working on making the out-of-band CASB product a seamless part of the Zero Trust platform

Starting today, you can build Zero Trust rules that require periodic authentication to control network access