
HPKE (RFC 9180) was made to be simple, reusable, and future-proof by building upon knowledge from prior PKE schemes and software implementations. This article provides an overview of this new standard, going back to discuss its motivation, design goals, and development process

As Cloudflare expands globally, Rebecca Rogers, Manager of Security Validations, discusses an exciting update to Cloudflare’s commitment to customer security for our German customers

This blogpost will touch upon how to practically use Jasmin and EasyCrypt to achieve better security guarantees when verifying KEMs
SG
Sofia, Goutam Tamvada·February 24, 2022Security 
Earlier today we announced that Cloudflare has agreed to acquire Area 1 Security
JG
John Graham Cumming·February 23, 2022Security 
On February 1, 2022, a configuration error on one of our routers caused a route leak of up to 2,000 Internet prefixes to one of our Internet transit providers. This leak lasted for 32 seconds and at a later time 7 seconds

GitHub Actions workflows in the Security category will now appear among the workflow recommendations based on a repository’s content.
PA
Pulkit Agarwal·February 22, 2022Security 
Anyone can now provide additional information to further the community’s understanding and awareness of security advisories.

A behind-the-scenes peek into the machine learning framework powering new code scanning security alerts.
TG
Tiferet Gazit·February 17, 2022Security 
Practical tips on how to apply OWASP Top 10 Proactive Control C4.

GitHub Enterprise Server 3.4 is now generally available for all customers. This release makes software development faster and more secure with new features like reusable workflows, Dependabot security updates, and GitHub Advanced Security enhancements.

Earlier today, Cloudflare announced that we have acquired Vectrix, a cloud-access security broker (CASB) company focused on solving the problem of control and visibility in the SaaS applications and public cloud providers that your team uses
SJ
Sam, John Graham Cumming·February 10, 2022Security 
We are excited to share that Vectrix has been acquired by Cloudflare! Vectrix helps IT and security teams detect security issues across their SaaS applications

A comprehensive guide for vulnerability reporters.
NG
Nancy Gariché·February 9, 2022Security 
This tutorial will work us through on how to implement user registration, verification, and authentication in React using Firebase.
TB
Taminoturoko Briggs·February 2, 2022Security 
Today we are launching Cloudflare’s paid public bug bounty program. We believe bug bounties are a vital part of every security team’s toolbox.

A deep dive into how GitHub adds support for new languages to CodeQL.

Starting today, we are rolling out mandatory 2FA to all maintainers of top-100 npm packages by dependents.

When it comes to secure database access, there’s more to consider than SQL injections. OWASP Top 10 Proactive Control C3 offers guidance.

More than 50% of all traffic processed by Cloudflare is API-based, and it’s growing twice as fast as traditional web traffic. This growth calls for the development of dedicated security solutions.

GitHub continues to improve account security and developer experience with a new 2FA mechanism in GitHub Mobile on iOS and Android.

We’re excited to announce the V4 release of the OpenSSF’s Scorecard project in partnership with Google.

We’re excited to announce that customers using our Free plan can now get real-time alerts about HTTP DDoS attacks that were automatically detected and mitigated by Cloudflare

My colleague Stormy Peters and I are proud to represent GitHub at the White House’s Open Source Software Security Summit.

Netlify Identity is a robust offering that provides authentication on a Jamstack site. It’s super easy to enable and opens up a bunch of possibilities.

Accessibility must be a permanent program within organizations, much like security. There are many ways to increase your team’s capacity for accessibility and it’s less important where you start than it is that you do start. Accessibility must be a permanent program within organizations, much like security. You wouldn’t just do one round of security testing and consider it taken care of. In this a
KK
Kate Kalcevich·January 12, 2022Security 
In Q4, we observed a 95% increase in L3/4 DDoS attacks and record-breaking levels of Ransom DDoS attacks. The Manufacturing industry was the most targeted alongside a 5,800% increase in SNMP-based DDoS attacks and massive campaigns against VoIP providers around the world

The GitHub Security Lab’s CodeQL bounty program fuels GitHub Advanced Security with queries written by the open source community.
XR
Xavier René-Corail·January 5, 2022Security 
We use and love Jetpack around here. It's a WordPress plugin that brings a whole suite of functionality to your site ranging from security to marketing with

I’ll bet you are using browser extensions right now. Some of them are extremely popular and useful, like ad blockers, password managers, and PDF viewers.

As the year winds down, we’re highlighting some of the incredible work from GitHub’s engineers, product teams, and security researchers.
BC
Becca Crockett·December 28, 2021Security 
In this post, I’ll discuss how to apply OWASP Proactive Control C2: Leverage security frameworks and libraries.
AM
Alvaro Munoz·December 20, 2021Security 
Looking to avoid security vulnerabilities, buttons that don’t work, slow site speeds, or manually writing release notes? This one’s for you.
BD
Brian Douglas·December 16, 2021Security 
This vulnerability is actively being exploited and anyone using Log4J should update to version 2.16.0 as soon as possible. Latest version is available on the Log4J download page.
GA
Gabriel, Andre Bluehs·December 15, 2021Security 
Recently, we received a bug bounty report regarding the GPG signing key used for pkg.cloudflareclient.com, the Linux package repository for our Cloudflare WARP products.
JM
Jeff, Matt Schulte·December 15, 2021Security 
We’re tackling the industry-wide issue of scraping by expanding our bug bounty program to reward valid reports of scraping bugs and unprotected data sets. To the best of our knowledge, this is an industry first. Looking toward the future, we’re also launching new educational opportunities for researchers and hosting our first BountyConEDU — a three-day […]
MEMeta Engineering·December 15, 2021Security 
This article covers WAF evasion patterns and exfiltration attempts, trend data on attempted exploitation, and information on exploitation that we saw prior to the public disclosure of CVE-2021-44228.
JG
John Graham Cumming, Celso·December 14, 2021Security 
Many Cloudflare customers consume their logs using software that uses Log4j, so we are mitigating any exploit attempts via Cloudflare Logs.

Use GitHub’s security features to assess Apache Log4j exposure and, where possible, mitigate this vulnerability within your GitHub repositories.
BO
Brittany O'Shea·December 14, 2021Security 
Defining your security requirements is the most important proactive control you can implement for your project. Here’s how.
AM
Alvaro Munoz·December 14, 2021Security 
To be able to modify headers in a testing environment is a great thing to have, and a very powerful tool. It allows control over your application as one can bypass authentication, set cookies, and so on. In this article, Nafees Nehar explores some methods which allow modification of headers in an automation testing setup.
NN
Nafees Nehar·December 14, 2021Security 
How to exploit a double-free vulnerability in Ubuntu’s accountsservice (CVE-2021-3939)
KB
Kevin Backhouse·December 13, 2021Security 
On Thursday, December 9, 2021, GitHub was made aware of a vulnerability in the Log4j logging framework, CVE-2021-44228.
JM
Jill Moné-Corallo·December 13, 2021Security 
Customer confidence in our ability to handle their sensitive information in an ever-changing regulatory landscape has to be as solid as our offerings, so we have expanded the scope of our previously-existing compliance validations; not only that, we’ve also managed to obtain a couple of new ones.

While over time best practices and technologies change, we aim to ensure our platform meets the security needs and depth of control that our customers require. In that spirit, we have been busy over the past year delivering important updates to many of our platform services.
GT
Garrett, Tanushree·December 11, 2021Security 
Yesterday, December 9, 2021, when a serious vulnerability in the popular Java-based logging package log4j was publicly disclosed, our security teams jumped into action to help respond to the first question and answer the second question. This post explores the second.
RT
Rushil, Thomas Calderon·December 10, 2021Security 
I wrote earlier about how to mitigate CVE-2021-44228 in Log4j, how the vulnerability came about and Cloudflare’s mitigations for our customers. As I write we are rolling out protection for our FREE customers as well because of the vulnerability’s severity.
JG
John Graham Cumming·December 10, 2021Security 
A zero-day exploit affecting the popular Apache Log4j utility (CVE-2021-44228) was made public on December 9, 2021, that results in remote code execution (RCE).
GA
Gabriel, Andre Bluehs·December 10, 2021Security 
The vulnerability disclosed yesterday in the Java-based logging package, log4j, allows attackers to execute code on a remote server. We’ve updated Cloudflare’s WAF to defend your infrastructure against this 0-day attack.

We're launching Security Center, making attack surface management actionable and accessible, built on Cloudflare’s unique visibility into Internet activity and expertise on security best practices.

Cloudflare Enterprise customers using the Magic Transit and Spectrum services can now tune and tweak their L3/4 DDoS protection settings directly from the Cloudflare dashboard or via the Cloudflare API.

Gone are the days of the Secure Email Gateway (SEG) being an option. Cloud-native email protection with multiple deployment options are now changing the game. With winter in our minds, it’s time to start talking about “ICE.”

To improve security, we’re adding threat intel integration and geo-blocking. For visibility, we’re packet captures at the edge, a way to see packets arrive at the edge in near real-time.

We are excited to announce the acquisition of Zaraz by Cloudflare, and the launch of a beta version of the Zaraz product. You can use Zaraz (beta) to manage and load third-party tools on the cloud, and achieve significant speed, privacy and security improvements.

At Kudelski Security, we've been working on implementing our Zero Trust strategy for the last two years. In many aspects, it's been an incredible journey, and although we're not quite finished yet, we're excited by the progress made so far with Cloudflare.

An interesting (scary) trick of an nearly undetectable exploit. Wolfgang Ettlinger:

We're excited to announce that customers will soon be able to store their Cloudflare logs on Cloudflare R2 storage. Storing your logs on Cloudflare will give CIOs and Security Teams an opportunity to consolidate their infrastructure; creating simplicity, savings and additional security.

Protect your team from phishing attacks by controlling user input on suspicious and sensitive websites with Cloudflare Browser Isolation.

Today we’re introducing enhanced login verification to the npm registry, and we will begin a staged rollout to maintainers beginning Dec 7.

By combining the power of eBPF and Nftables, Magic Firewall can mitigate sophisticated attacks on infrastructure by enforcing a positive security model.

GitHub has partnered with the OpenSSF and Project Sigstore to add container image signing to our default “Publish Docker Container” workflow.
JH
Justin Hutchings·December 6, 2021Security