Home/Security
Topic

Security

1,018 articles on Security.

11,834 articles
Security — How we use Dependabot to secure GitHub

How we use Dependabot to secure GitHub

A two-part story about how GitHub’s Product Security Engineering team rolled out Dependabot internally to track vulnerable dependencies, and how GitHub tracks and prioritizes technical debt.

PTPhil TurnbullPhil Turnbull·May 25, 2022Security
Security — Cloudflare blocks 15M rps HTTPS DDoS attack

Cloudflare blocks 15M rps HTTPS DDoS attack

Earlier this month, Cloudflare’s systems automatically detected and mitigated a 15.3 million request-per-second (rps) DDoS attack — one of the largest HTTPS DDoS attacks on record

OJOmer, Julien DesgatsOmer, Julien Desgats·April 27, 2022Security
Security — DDoS Attack Trends for 2022 Q1

DDoS Attack Trends for 2022 Q1

Welcome to our first DDoS report of 2022, and the ninth in total so far. This report includes new data points and insights both in the application-layer and network-layer sections — as observed across the global Cloudflare network between January and March 2022

OOmerOmer·April 12, 2022Security
Security — Dynamic Data-Fetching In An Authenticated Next.js App — Smashing Magazine

Dynamic Data-Fetching In An Authenticated Next.js App — Smashing Magazine

Data is among the most important things that make up a web application or a conventional native app. We need data to be able to see and perhaps understand the purpose of an application. In this article, we’ll look at another approach to obtaining data in an application that requires authentication or authorization using Next.js.

COCaleb OlojoCaleb Olojo·April 8, 2022Security
Security — Cloudflare’s investigation of the January 2022 Okta compromise

Cloudflare’s investigation of the January 2022 Okta compromise

Today at 03:30 UTC we learnt of a compromise of Okta. We use Okta internally for employee identity as part of our authentication stack. We have investigated this compromise carefully and do not believe we have been compromised as a result

JGJohn Graham Cumming, Lucas FerreiraJohn Graham Cumming, Lucas Ferreira·March 22, 2022Security
Security — Commitment to Customer Security

Commitment to Customer Security

Cloudflare has been hooked on securing customers globally since its inception. Our services protect customer traffic and data as well as our own, and we are continuously improving and expanding those services to respond to the changing threat landscape of the Internet

LMLing, Matt GallagherLing, Matt Gallagher·March 18, 2022Security
Security — Securing Cloudflare Using Cloudflare

Securing Cloudflare Using Cloudflare

Cloudflare is committed to bolstering our security posture with best-in-class solutions — which is why we often turn to our own products as any other Cloudflare customer would.

MEMolly, Evan JohnsonMolly, Evan Johnson·March 18, 2022Security
Security — A new WAF experience

A new WAF experience

The security landscape is moving fast. We invited users to help us shape a new WAF experience that enables us to evolve WAF to meet their demands and use cases

XMXmflsct, MruXmflsct, Mru·March 15, 2022Security
Security — Investigating threats using the Cloudflare Security Center

Investigating threats using the Cloudflare Security Center

The data we glean from attacks trains our machine learning models and improves the efficacy of our network and application security products, but historically hasn’t been available to query directly. This week, we’re changing that

PJPatrick, JessePatrick, Jesse·March 14, 2022Security
Security — Welcome to Security Week 2022!

Welcome to Security Week 2022!

Welcome to our first innovation week of the year: Security Week! In this post we will be going over Cloudflare’s security products’ history giving you an introduction to all the great announcements we have planned

MTMichael TremanteMichael Tremante·March 13, 2022Security
Security — HPKE: Standardizing public-key encryption (finally!)

HPKE: Standardizing public-key encryption (finally!)

HPKE (RFC 9180) was made to be simple, reusable, and future-proof by building upon knowledge from prior PKE schemes and software implementations. This article provides an overview of this new standard, going back to discuss its motivation, design goals, and development process

CCloudflare·February 24, 2022Security
Security — BGP security and confirmation biases

BGP security and confirmation biases

On February 1, 2022, a configuration error on one of our routers caused a route leak of up to 2,000 Internet prefixes to one of our Internet transit providers. This leak lasted for 32 seconds and at a later time 7 seconds

CCloudflare·February 23, 2022Security