Home/Security
Topic

Security

1,018 articles on Security.

11,834 articles
Security — Cloudflare DDoS threat report 2022 Q3

Cloudflare DDoS threat report 2022 Q3

In Q3, DDoS attacks increased by 111% YoY, Cloudflare auto-mitigated a 2.5 Tbps attack targeting a Minecraft server as multi-terabit scale DDoS attacks become increasingly frequent. Read more in our 2022 Q3 DDoS Report

OOmerOmer·October 12, 2022Security
Security — Securing the Internet of Things

Securing the Internet of Things

We’ve been defending customers from Internet of Things botnets for years now, and it’s time to turn the tides: we’re bringing the same security behind our Zero Trust platform to IoT

SSilverlockSilverlock·September 26, 2022Security
Security — The first Zero Trust SIM

The first Zero Trust SIM

We’re announcing the first Zero Trust SIM: the next major part of Cloudflare One, combining both software and hardware layers to rethink mobile device security for organizations

SJSilverlock, James AllworthSilverlock, James Allworth·September 26, 2022Security
Security — Security alert: new phishing campaign targets GitHub users

Security alert: new phishing campaign targets GitHub users

On September 16, GitHub Security learned that threat actors were targeting GitHub users with a phishing campaign by impersonating CircleCI to harvest user credentials and two-factor codes. While GitHub itself was not affected, the campaign has impacted many victim organizations.

AWAlexis WalesAlexis Wales·September 21, 2022Security
Security — Cloudflare Area 1 - how the best email security keeps getting better

Cloudflare Area 1 - how the best email security keeps getting better

Cloudflare started using Area 1 in 2020 and proceeded with acquiring the company in 2022. We were most impressed how phishing, responsible for 90+% of cyberattacks, basically became a non-issue overnight when we deployed Area 1. But our vision is much bigger than preventing phishing attacks

JJoaoJoao·September 20, 2022Security
Security — 5 tips for prioritizing Dependabot alerts

5 tips for prioritizing Dependabot alerts

Dependabot alerts can give you the ability to secure your project by keeping dependency-based vulnerabilities out of your code. Here are some tips to more efficiently prioritize and take action on your alerts, so you can get back to building.

EHErin HavensErin Havens·September 19, 2022Security
Security — Join us for OctogatosConf 2022

Join us for OctogatosConf 2022

Live on September 15, 2022, with talks by industry experts in Spanish, Portuguese, and English, on topics including software development, security, technical project management, community, open source, professional development and best practices.

AGAndrea GriffithsAndrea Griffiths·September 6, 2022Security
Security — Introducing thresholds in Security Event Alerting: a z-score love story

Introducing thresholds in Security Event Alerting: a z-score love story

Today we are excited to announce thresholds for our Security Event Alerts: a new and improved way of detecting anomalous spikes of security events on your Internet properties. By introducing a threshold, we are able to make alerts more accurate and only notify you when it truly matters

KGKristina GalicovaKristina Galicova·August 30, 2022Security
Security — Open sourcing our fork of PgBouncer

Open sourcing our fork of PgBouncer

We are releasing our internal fork of PgBouncer, filled with authentication bug fixes and new features around per user and connection pool isolation

JKJustin KwanJustin Kwan·August 26, 2022Security
Security — Implementing Okta Authentication In React — Smashing Magazine

Implementing Okta Authentication In React — Smashing Magazine

Okta is an identity manager, with features such as single sign-on and multi-factor authentication. Okta can be used to secure the identities of customers and workforces. In this tutorial, we are going to learn how to use Okta for authentication in a React application. We’ll understand the core concepts of Okta, use cases, and why you should use it in your next React application.

TToppleTopple·August 10, 2022Security
Security — Introducing new Cloudflare for SaaS documentation

Introducing new Cloudflare for SaaS documentation

Cloudflare for SaaS offers a suite of Cloudflare products and add-ons to improve the security, performance, and reliability of SaaS providers. Now, the Cloudflare for SaaS documentation outlines how to optimize it in order to meet your goals

CCloudflare·August 9, 2022Security
Security — Dependabot now alerts for vulnerable GitHub Actions

Dependabot now alerts for vulnerable GitHub Actions

GitHub Actions gives teams access to powerful, native CI/CD capabilities right next to their code hosted in GitHub. Starting today, GitHub will send a Dependabot alert for vulnerable GitHub Actions, making it even easier to stay up to date and fix security vulnerabilities in your actions workflows.

GGitHub·August 9, 2022Security
Security — All GitHub Enterprise users now have access to the security overview

All GitHub Enterprise users now have access to the security overview

Today, we’re expanding access to the GitHub security overview! All GitHub Enterprise customers now have access to the security overview, not just those with GitHub Advanced Security. Additionally, all users within an enterprise can now access the security overview, not just admins and security managers.

BOBrittany O'Shea, Kelly ArwineBrittany O'Shea, Kelly Arwine·August 8, 2022Security
Security — Rethinking Authentication UX — Smashing Magazine

Rethinking Authentication UX — Smashing Magazine

Nobody wakes up in the morning hoping to finally identify crosswalks and fire hydrants that day. Yet every day, we prompt users through hoops and loops to sign up and log in. Let’s fix that. Authentication is everywhere, and sometimes it’s extremely frustrating, and sometimes it’s seamless. Let’s explore a few patterns to create experience that are a bit more seamless than frustrating.

VFVitaly FriedmanVitaly Friedman·August 4, 2022Security
Security — How We Maintain Security Testing within the Software Development Life Cycle

How We Maintain Security Testing within the Software Development Life Cycle

TL;DR The (SDLC) has always been followed by functional testing to ensure software solutions have all the necessary features and functions. Because of the growing number of cyberattacks, software development stakeholders have been forced to implement security testing as the main track in SDLC to prevent vulnerabilities and flaws in applications or software (assets). A software security assessment

SESpotify Engineering·August 1, 2022Security
Security — Five security principles for billions of messages across Meta’s apps

Five security principles for billions of messages across Meta’s apps

At Meta, our messaging apps help billions of people around the world stay connected to those who matter most to them. This scale brings potential threats from criminals and hackers, so we have a responsibility to keep people and their data safe. We’re sharing a set of principles to ensure that security is central to […]

CWChris Wiltz·July 28, 2022Security
Security — Corrupting memory without memory corruption

Corrupting memory without memory corruption

In this post I’ll exploit CVE-2022-20186, a vulnerability in the Arm Mali GPU kernel driver and use it to gain arbitrary kernel memory access from an untrusted app on a Pixel 6. This then allows me to gain root and disable SELinux. This vulnerability highlights the strong primitives that an attacker may gain by exploiting errors in the memory management code of GPU drivers.

MYMan Yue MoMan Yue Mo·July 27, 2022Security
Security — Introducing even more security enhancements to npm

Introducing even more security enhancements to npm

New npm security enhancements include an improved login and publish experience with the npm CLI, connected GitHub and Twitter accounts, and a new CLI command to verify the integrity of packages in npm.

MBMyles Borins, Monish MohanMyles Borins, Monish Mohan·July 26, 2022Security
Security — Using Hermes’s Quicksort to run Doom: A tale of JavaScript exploitation

Using Hermes’s Quicksort to run Doom: A tale of JavaScript exploitation

At Meta, our Bug Bounty program is an important element of our “defense-in-depth” approach to security. Our internal product security teams investigate every bug submission to assess its maximum potential impact so that we can always reward external researchers based on both the bug they found and our further internal research assessment of where else […]

CWChris Wiltz·July 20, 2022Security
Security — DDoS attack trends for 2022 Q2

DDoS attack trends for 2022 Q2

Welcome to our 2022 Q2 DDoS report. This report includes insights and trends about the DDoS threat landscape — as observed across the global Cloudflare network

OOmerOmer·July 6, 2022Security
Security — The Chromium super (inline cache) type confusion

The Chromium super (inline cache) type confusion

In this post I’ll exploit CVE-2022-1134, a type confusion in Chrome that I reported in March 2022, which allows remote code execution (RCE) in the renderer sandbox of Chrome by a single visit to a malicious site. I’ll also look at some past vulnerabilities of this type and some implementation details of inline cache in V8, the JavaScript engine of Chrome.

MYMan Yue MoMan Yue Mo·June 29, 2022Security
Security — How Cloudflare One solves your observability problems

How Cloudflare One solves your observability problems

Today, we’re excited to announce Cloudflare One Observability. Cloudflare One Observability will help customers work across Cloudflare One applications to troubleshoot network connectivity, security policies, and performance issues to ensure a consistent experience for employees everywhere

CDChris DraperChris Draper·June 21, 2022Security
Security — The Android kernel mitigations obstacle race

The Android kernel mitigations obstacle race

In this post I’ll exploit CVE-2022-22057, a use-after-free in the Qualcomm gpu kernel driver, to gain root and disable SELinux from the untrusted app sandbox on a Samsung Z flip 3. I’ll look at various mitigations that are implemented on modern Android devices and how they affect the exploit.

MYMan Yue MoMan Yue Mo·June 16, 2022Security