
To combat the prevalence of malware in the open source ecosystem, GitHub now publishes malware occurrences in the GitHub Advisory Database. These advisories power Dependabot alerts and remain forever free and usable by the community.
BO
Brittany O'Shea, Kate Catlin·June 15, 2022Security 
Zack Deveau, Senior Application Security Engineer at Shopify, shares the details behind a recent contribution to the Rails library, inspired by a bug bounty report we received. He'll go over the report and its root cause, how we fixed it in our system, and how we took it a step further to make Rails more secure by upda
SEShopify Engineering·June 15, 2022Security 
Last week, Cloudflare automatically detected and mitigated a 26 million request per second DDoS attack — the largest HTTPS DDoS attack on record

The Rust community can now discover, report, and prevent security vulnerabilities.
CC
Courtney Claessens·June 6, 2022Security 
UTC Atlassian released a Security Advisory relating to a remote code execution (RCE) vulnerability affecting Confluence Server and Confluence Data Center products.
VH
Vaibhav, Himanshu·June 5, 2022Security 
On June 02, 2022 Atlassian released a security advisory for their Confluence Server and Data Center applications, highlighting a critical severity unauthenticated remote code execution vulnerability.
RD
Reid, Daniel Stinson Diess·June 3, 2022Security 
Learn how you can securely manage users with the latest ships for GitHub Enterprise.

GitHub Enterprise Server 3.5 is available now, including access to the Container registry, the addition of Dependabot, enhanced administrator capabilities, and features for GitHub Advanced Security.

npm’s impact analysis of the attack campaign using stolen OAuth tokens and additional findings.

A two-part story about how GitHub’s Product Security Engineering team rolled out Dependabot internally to track vulnerable dependencies, and how GitHub tracks and prioritizes technical debt.

It was another record year for our Security Bug Bounty program. We’re excited to highlight some achievements we’ve made together with the bounty community from 2021!
JM
Jill Moné-Corallo·May 23, 2022Security 
Upgrade to GHES 3.2 or newer by June 3rd to continue using GitHub Connect.

With innersource, it’s important to measure both the amount of innersource activity and the quality of the code being created. Here’s how.

We’re excited to announce the availability of Network Analytics Logs for maximum visibility into L3/4 traffic and DDoS attacks

JK
John Karabinos, Tony Xu, and Andrew Hannon·May 16, 2022Security 
GitHub’s Information Security Management System (ISMS) has been certified against ISO 27001:2013, an internationally recognized standard for security program best practices.

Fixing third-party security issues and bloat takes collaborative work. We are open sourcing Managed Components, so everyone can use fast and secure third-parties, everywhere

The Cloudflare Bug Bounty has resulted in numerous security improvements to Cloudflare Pages

We’re taking a look at some of the most common security vulnerabilities and detailing how developers can best protect themselves.
JK
Joseph Katsioloudes·May 6, 2022Security 
GitHub will require all users who contribute code on GitHub.com to enable one or more forms of two-factor authentication (2FA) by the end of 2023.

These days software is subject to an ever-changing threat landscape. Check out the many ways you can keep your projects secure on GitHub today.
JH
Justin Hutchings·April 28, 2022Security 
Earlier this month, Cloudflare’s systems automatically detected and mitigated a 15.3 million request-per-second (rps) DDoS attack — one of the largest HTTPS DDoS attacks on record
OJ
Omer, Julien Desgats·April 27, 2022Security 
Do you worry that a CVE will hurt the reputation of your project? In reality, CVEs are a tracking number, and nothing more. Here’s how we think of them at GitHub.
MF
Madison Ficorilli·April 22, 2022Security 
Introducing CodeQL packs to help you codify and share your knowledge of vulnerabilities.
AE
Andrew Eisenberg·April 19, 2022Security 
On April 12, GitHub Security began an investigation that uncovered evidence that an attacker abused stolen OAuth user tokens issued to two third-party OAuth integrators, Heroku and Travis-CI, to download data from dozens of organizations, including npm. Read on to learn more about the impact to GitHub, npm, and our users.

We are excited to announce that as of today, network security teams can procure and use Magic Transit, Cloudflare’s industry-leading DDoS mitigation solution, and Kentik’s network observability as an integrated solution
ML
Matt Lewis 2, Ameet·April 13, 2022Security 
Welcome to our first DDoS report of 2022, and the ninth in total so far. This report includes new data points and insights both in the application-layer and network-layer sections — as observed across the global Cloudflare network between January and March 2022

Upgrade your local installation of Git, especially if you are using Git for Windows, or you use Git on a multi-user machine.

Data is among the most important things that make up a web application or a conventional native app. We need data to be able to see and perhaps understand the purpose of an application. In this article, we’ll look at another approach to obtaining data in an application that requires authentication or authorization using Next.js.

Ensuring secure access to your source code is more important than ever. Git Credential Manager helps make that easy.
MJ
Matthew John Cheetham·April 7, 2022Security 
Learn how to build packages with SLSA 3 provenance using GitHub Actions.

The new dependency review action and API prevents the introduction of known supply chain vulnerabilities into your code.
CC
Courtney Claessens·April 6, 2022Security 
We want to take away the pain and effort of keeping your code secure, so check out how Dependabot empowers developers to keep to their projects secure.

Organizations with GitHub Advanced Security can now proactively protect against secret leaks with secret scanning’s new push protection feature.

From Jan. 2021 to Jan. 2022, more than 8.5 million (of 56 million in total) brand phishing emails blocked by Area 1 impersonated the World Health Organization

CVE-2022-1096 is yet another zero day vulnerability affecting web browsers. Cloudflare zero trust mitigates the risk of zero day attacks in the browser and has been patched

Securing your projects is no easy task, but end-to-end supply chain security is more top of mind than ever. We’ve seen bad actors expand their focus to taking over user…
ZS
Zachary Steindler·March 28, 2022Security 
Learn who made the list of the top brands that attackers use in phishing lures. This bracket is based on an analysis of more than 56 million phishing emails blocked by Area 1’s solution in the preceding 12 months since Feb 2022.

Implementing a toy version of TLS 1.3

SaaS providers can now enable mutual TLS authentication on their customer’s domains through our Access product

Today at 03:30 UTC we learnt of a compromise of Okta. We use Okta internally for employee identity as part of our authentication stack. We have investigated this compromise carefully and do not believe we have been compromised as a result
JG
John Graham Cumming, Lucas Ferreira·March 22, 2022Security 
In this post, we share some of the insights we’ve gathered from the 32 million HTTP requests/second that pass through our network
MT
Michael Tremante, Sabina·March 21, 2022Security 
Today, we’re proud to report we are the fastest provider in 71% of the top 1,000 most reported networks around the world

If there’s one habit that can make software more secure, it’s probably input validation. Here’s how to apply OWASP Proactive Control C5 (Validate All Inputs) to your code.
JL
Jaroslav Lobacevski·March 21, 2022Security 
Cloudflare has been hooked on securing customers globally since its inception. Our services protect customer traffic and data as well as our own, and we are continuously improving and expanding those services to respond to the changing threat landscape of the Internet
LM
Ling, Matt Gallagher·March 18, 2022Security 
Starting today, you can build Zero Trust rules that require periodic authentication to control network access

Cloudflare is committed to bolstering our security posture with best-in-class solutions — which is why we often turn to our own products as any other Cloudflare customer would.
ME
Molly, Evan Johnson·March 18, 2022Security 
The security landscape is moving fast. We invited users to help us shape a new WAF experience that enables us to evolve WAF to meet their demands and use cases

The data we glean from attacks trains our machine learning models and improves the efficacy of our network and application security products, but historically hasn’t been available to query directly. This week, we’re changing that

Once the acquisition of Area 1 closes, we plan to give all paid self-serve plans access to their email security technology at no additional charge
PS
Patrick, Shalabh·March 14, 2022Security 
Welcome to our first innovation week of the year: Security Week! In this post we will be going over Cloudflare’s security products’ history giving you an introduction to all the great announcements we have planned
MT
Michael Tremante·March 13, 2022Security 

A zero-day vulnerability in the Mitel MiCollab business phone system has recently been discovered (CVE-2022-26143). This vulnerability, called TP240PhoneHome, which Cloudflare customers are already protected against, can be used to launch UDP amplification attacks
OA
Omer, Alex Forster·March 8, 2022Security 
A new reflection/amplification distributed denial-of-service (DDoS) vector with a record-breaking potential amplification ratio of 4,294,967,296:1 has been abused by attackers in the wild to launch multiple high-impact DDoS attacks

HPKE (RFC 9180) was made to be simple, reusable, and future-proof by building upon knowledge from prior PKE schemes and software implementations. This article provides an overview of this new standard, going back to discuss its motivation, design goals, and development process

As Cloudflare expands globally, Rebecca Rogers, Manager of Security Validations, discusses an exciting update to Cloudflare’s commitment to customer security for our German customers

This blogpost will touch upon how to practically use Jasmin and EasyCrypt to achieve better security guarantees when verifying KEMs
SG
Sofia, Goutam Tamvada·February 24, 2022Security 
Earlier today we announced that Cloudflare has agreed to acquire Area 1 Security
JG
John Graham Cumming·February 23, 2022Security 
On February 1, 2022, a configuration error on one of our routers caused a route leak of up to 2,000 Internet prefixes to one of our Internet transit providers. This leak lasted for 32 seconds and at a later time 7 seconds

GitHub Actions workflows in the Security category will now appear among the workflow recommendations based on a repository’s content.
PA
Pulkit Agarwal·February 22, 2022Security