Home/Security
Topic

Security

1,018 articles on Security.

11,834 articles
Security — Introducing Adaptive Intelligence: undermining the economics of every bot attack

Introducing Adaptive Intelligence: undermining the economics of every bot attack

Bot operators have historically had the economic advantage, bypassing static, deterministic detection rules with cheap proxies and retooling. Cloudflare's new Adaptive Intelligence engine flips this dynamic by autonomously learning from the meta-signals of live traffic and deploying disposable rules, making automated attacks too expensive to sustain.

CPChris PopeChris Pope·August 31, 2026Security
Security — A revisit of remote Spectre attacks on Cloudflare Workers

A revisit of remote Spectre attacks on Cloudflare Workers

In 2024 and 2025, we reassessed remote Spectre attacks on our Workers infrastructure. We share details about the new attack primitives like Spectre gadgets, remote timers, achieving co-location and how new defenses further harden Cloudflare Workers.

MAMartin, Albert PedersenMartin, Albert Pedersen·August 19, 2026Security
Security — How Cloudflare detects MCP traffic and helps secure it

How Cloudflare detects MCP traffic and helps secure it

Cloudflare Gateway identifies MCP requests using protocol-level heuristics. Security teams can use that signal to find shadow MCP traffic, enforce Portal-only access for approved servers, and block direct connections on managed network paths.

AKAj, KennyAj, Kenny·August 14, 2026Security
Security — How We’re Building Scam Alert on WhatsApp With End-to-End Encryption and Verifiability Guarantees

How We’re Building Scam Alert on WhatsApp With End-to-End Encryption and Verifiability Guarantees

WhatsApp is committed to helping people stay safe while protecting the privacy of their messages. As scam tactics evolve — from impersonation to social engineering to AI-generated lures — we’re always evolving as well, so that our protections stay ahead of scammers while protecting people’s personal messages with end-to-end encryption. Today, we’re sharing an early […]

CWChris Wiltz·August 12, 2026Security
Security — How we took malware advisories beyond npm

How we took malware advisories beyond npm

GitHub malware advisories no longer stop at npm. Here’s how we wired OpenSSF’s malicious-packages data into the Advisory Database, and why we built the pipeline paranoid.

AKAnkit Kumar HoneyAnkit Kumar Honey·August 6, 2026Security
Security — Welcome to Agents Week

Welcome to Agents Week

Agents Week explores how cloud infrastructure must evolve to serve autonomous agents rather than human browsers. Join us as we unpack the storage, execution, and security primitives needed for an agent-native web.

RRitaRita·August 2, 2026Security
Security — Post-quantum authentication to origins is now supported

Post-quantum authentication to origins is now supported

Cloudflare now supports post-quantum (PQ) authentication when connecting to customer origin servers via Authenticated Origin Pulls and Custom Origin Trust Store. This is the first step towards providing PQ authentication for all Cloudflare products.

LKLuke, Kevin GuthrieLuke, Kevin Guthrie·July 29, 2026Security
Security — How GitHub gave every repository a durable owner

How GitHub gave every repository a durable owner

GitHub had over 14,000 repositories. Fewer than half had clear ownership. Here’s how we gave every active repository a validated owner in under 45 days, archived the rest, and made ownership the foundation for everything that followed.

MRMichael RecachinasMichael Recachinas·July 9, 2026Security
Security — Cloudflare proudly joins the UK government's Cyber Resilience Pledge

Cloudflare proudly joins the UK government's Cyber Resilience Pledge

The pledge is a voluntary framework inviting organizations to commit to foundational cyber security governance, board-level accountability, and supply chain rigor. For over a decade, Cloudflare has pioneered the core pillars of this framework: democratizing security, leadership accountability, and radical transparency.

CCloudflare·July 7, 2026Security
Security — Skills Night: 69,000+ ways agents are getting smarter

Skills Night: 69,000+ ways agents are getting smarter

Andrew Qu reflects on Skills Night SF: how a weekend project became 69,000 community-created skills, the security partnerships protecting them, and what eight partner demos revealed about agents, context, and the future of development.

VVercel·July 2, 2026Security
Security — Introducing the new v0

Introducing the new v0

The new v0 brings production-ready AI coding to enterprises with git workflows, security, and real integrations. Ship faster with agents and teams.

VVercel·July 2, 2026Security
Security — Agent skills explained: An FAQ

Agent skills explained: An FAQ

A plainspoken Skills FAQ with a ready-to-use guide: what skill packages are, how agents load them, what skills-ai.dev is, how Skills compare to MCP, plus security and alternatives.

VVercel·July 2, 2026Security
Security — Compliance

Compliance

Security and sustainability are our goals. CYBERTEC is ISO and TISAX certified. CYBERTEC is audited on a regular basis.

CPCYBERTEC PostgreSQL·June 15, 2026Security
Security — Turning Cloudflare’s threat indicators into real-time WAF rules

Turning Cloudflare’s threat indicators into real-time WAF rules

Cloudflare customers can now use Cloudforce One threat intelligence directly within the WAF to block high-risk traffic. By using new cf.intel fields, security teams can automate protection against specific threat actors and targeted industries in real time.

AHAlexandra, Harsh SaxenaAlexandra, Harsh Saxena·June 8, 2026Security
Security — New ways to turn global demand into revenue

New ways to turn global demand into revenue

Stripe’s latest global commerce solutions help all types of businesses localize checkout for every market, increase authorization rates with AI, reduce FX costs with multicurrency support, and automate tax and compliance processes.

ATAbhi TiwariAbhi Tiwari·June 4, 2026Security
Security — When is a function leakproof?

When is a function leakproof?

This article discusses row-level security, security barrier functions and leakproof functions, which are necessary to make them work.

LALaurenz Albe·June 2, 2026Security
Security — Protecting against token theft

Protecting against token theft

Inference theft lets attackers resell your paid AI calls. See how the attack works, why rate limits and auth walls fail, and how Vercel BotID stops it on every request.

VVercel·May 29, 2026Security
Security — Slack AI: The Path to Multi-Cloud

Slack AI: The Path to Multi-Cloud

In early 2023, Slack faced a foundational challenge: serving Large Language Models (LLMs) at enterprise scale with the security, reliability, and performance our customers expect. Over three years, we evolved from basic infrastructure to orchestrating a sophisticated multi-cloud architecture. We didn’t just want shiny new models; we needed a system resilient to regional outages and…

SKShaurya Kethireddy·May 28, 2026Security
Security — The VibeSec Reckoning

The VibeSec Reckoning

“Vibe coding” - the practice of non-technical citizen builders using generative AI tools to rapidly develop applications, this has significantly accelerated software prototyping. However, because AI agents naturally prioritise the path of least resistance, they frequently recommend insecure configurations, creating systemic security exposure across industries. To combat this we need to write a sec

MFMartin Fowler·May 27, 2026Security
Security — Project Glasswing: what Mythos showed us

Project Glasswing: what Mythos showed us

In recent weeks, we pointed Mythos and other security-focused LLMs at live code across critical parts of our infrastructure. We share what we observed, the models’ strengths and weaknesses, and what the work around them needs to look like before any of it can scale.

GGrantGrant·May 18, 2026Security
Security — From SSH to REST: A Security-Driven Modernization of Slack’s EMR Data Pipelines

From SSH to REST: A Security-Driven Modernization of Slack’s EMR Data Pipelines

Excerpt By 2024, Slack’s data platform had accumulated 700+ SSH-based operators orchestrating critical data pipelines. We’re talking daily search indexing that processed terabytes of data, analytics jobs powering business intelligence, the whole shebang. Every single one of these jobs required direct SSH access to production AWS Elastic MapReduce (EMR) clusters. We had a massive security…

MVMahendran Vasagam·May 5, 2026Security
Security — Post-Quantum Cryptography Migration at Meta: Framework, Lessons, and Takeaways

Post-Quantum Cryptography Migration at Meta: Framework, Lessons, and Takeaways

We’re sharing lessons learned from Meta’s post-quantum cryptography (PQC) migration to help other organizations strengthen their resilience as industry transitions to post-quantum cryptography standards. We’re proposing the idea of PQC Migration Levels to help teams within organizations manage the complexity of PQC migration for their various use cases. By outlining Meta’s approach to this work […

CWChris Wiltz·April 16, 2026Security
Security — Dynamic, identity-aware, and secure Sandbox auth

Dynamic, identity-aware, and secure Sandbox auth

Outbound Workers for Sandboxes provide a programmable, zero-trust egress proxy for AI agents. This allows developers to inject credentials and enforce dynamic security policies without exposing sensitive tokens to untrusted code.

MNMike Nomitch, Gabi Villalonga SimonMike Nomitch, Gabi Villalonga Simon·April 13, 2026Security