Home/Security
Topic

Security

1,023 articles on Security.

11,625 articles
Security — HPKE: Standardizing public-key encryption (finally!)

HPKE: Standardizing public-key encryption (finally!)

HPKE (RFC 9180) was made to be simple, reusable, and future-proof by building upon knowledge from prior PKE schemes and software implementations. This article provides an overview of this new standard, going back to discuss its motivation, design goals, and development process

CCloudflare·February 24, 2022Security
Security — BGP security and confirmation biases

BGP security and confirmation biases

On February 1, 2022, a configuration error on one of our routers caused a route leak of up to 2,000 Internet prefixes to one of our Internet transit providers. This leak lasted for 32 seconds and at a later time 7 seconds

CCloudflare·February 23, 2022Security
Security — GitHub Enterprise Server 3.4 is generally available

GitHub Enterprise Server 3.4 is generally available

GitHub Enterprise Server 3.4 is now generally available for all customers. This release makes software development faster and more secure with new features like reusable workflows, Dependabot security updates, and GitHub Advanced Security enhancements.

IMIan MarshIan Marsh·February 15, 2022Security
Security — Adding a CASB to Cloudflare Zero Trust

Adding a CASB to Cloudflare Zero Trust

Earlier today, Cloudflare announced that we have acquired Vectrix, a cloud-access security broker (CASB) company focused on solving the problem of control and visibility in the SaaS applications and public cloud providers that your team uses

SJSam, John Graham CummingSam, John Graham Cumming·February 10, 2022Security
Security — Landscape of API Traffic

Landscape of API Traffic

More than 50% of all traffic processed by Cloudflare is API-based, and it’s growing twice as fast as traditional web traffic. This growth calls for the development of dedicated security solutions.

DDanieleDaniele·January 26, 2022Security
Security — How To Hire For Digital Accessibility Roles — Smashing Magazine

How To Hire For Digital Accessibility Roles — Smashing Magazine

Accessibility must be a permanent program within organizations, much like security. There are many ways to increase your team’s capacity for accessibility and it’s less important where you start than it is that you do start. Accessibility must be a permanent program within organizations, much like security. You wouldn’t just do one round of security testing and consider it taken care of. In this a

KKKate KalcevichKate Kalcevich·January 12, 2022Security
Security — DDoS Attack Trends for Q4 2021

DDoS Attack Trends for Q4 2021

In Q4, we observed a 95% increase in L3/4 DDoS attacks and record-breaking levels of Ransom DDoS attacks. The Manufacturing industry was the most targeted alongside a 5,800% increase in SNMP-based DDoS attacks and massive campaigns against VoIP providers around the world

OVOmer, VivekOmer, Vivek·January 10, 2022Security
Security — How to Create a Browser Extension

How to Create a Browser Extension

I’ll bet you are using browser extensions right now. Some of them are extremely popular and useful, like ad blockers, password managers, and PDF viewers.

LKLars KölkerLars Kölker·January 3, 2022Security
Security — Charting the future of our bug bounty program

Charting the future of our bug bounty program

We’re tackling the industry-wide issue of scraping by expanding our bug bounty program to reward valid reports of scraping bugs and unprotected data sets. To the best of our knowledge, this is an industry first. Looking toward the future, we’re also launching new educational opportunities for researchers and hosting our first BountyConEDU — a three-day […]

MEMeta Engineering·December 15, 2021Security
Security — Updates to Cloudflare Security and Privacy Certifications and Reports

Updates to Cloudflare Security and Privacy Certifications and Reports

Customer confidence in our ability to handle their sensitive information in an ever-changing regulatory landscape has to be as solid as our offerings, so we have expanded the scope of our previously-existing compliance validations; not only that, we’ve also managed to obtain a couple of new ones.

CCloudflare·December 11, 2021Security
Security — How Cloudflare security responded to Log4j 2 vulnerability

How Cloudflare security responded to Log4j 2 vulnerability

Yesterday, December 9, 2021, when a serious vulnerability in the popular Java-based logging package log4j was publicly disclosed, our security teams jumped into action to help respond to the first question and answer the second question. This post explores the second.

RTRushil, Thomas CalderonRushil, Thomas Calderon·December 10, 2021Security
Security — Actual CVE-2021-44228 payloads captured in the wild

Actual CVE-2021-44228 payloads captured in the wild

I wrote earlier about how to mitigate CVE-2021-44228 in Log4j, how the vulnerability came about and Cloudflare’s mitigations for our customers. As I write we are rolling out protection for our FREE customers as well because of the vulnerability’s severity.

JGJohn Graham CummingJohn Graham Cumming·December 10, 2021Security
Security — Secure how your servers connect to the Internet today

Secure how your servers connect to the Internet today

The vulnerability disclosed yesterday in the Java-based logging package, log4j, allows attackers to execute code on a remote server. We’ve updated Cloudflare’s WAF to defend your infrastructure against this 0-day attack.

SSamSam·December 10, 2021Security
Security — Introducing Cloudflare Security Center

Introducing Cloudflare Security Center

We're launching Security Center, making attack surface management actionable and accessible, built on Cloudflare’s unique visibility into Internet activity and expertise on security best practices.

MMalavikaMalavika·December 9, 2021Security
Security — Magic Firewall gets Smarter

Magic Firewall gets Smarter

To improve security, we’re adding threat intel integration and geo-blocking. For visibility, we’re packet captures at the edge, a way to see packets arrive at the edge in near real-time.

CCloudflare·December 9, 2021Security
Security — Guest Blog: k8s tunnels with Kudelski Security

Guest Blog: k8s tunnels with Kudelski Security

At Kudelski Security, we've been working on implementing our Zero Trust strategy for the last two years. In many aspects, it's been an incredible journey, and although we're not quite finished yet, we're excited by the progress made so far with Cloudflare.

CCloudflare·December 8, 2021Security
Security — Store your Cloudflare logs on R2

Store your Cloudflare logs on R2

We're excited to announce that customers will soon be able to store their Cloudflare logs on Cloudflare R2 storage. Storing your logs on Cloudflare will give CIOs and Security Teams an opportunity to consolidate their infrastructure; creating simplicity, savings and additional security.

TTanushreeTanushree·December 7, 2021Security