Home/Security
Topic

Security

1,018 articles on Security.

11,834 articles
Security — Open sourcing Winterfell: A STARK prover and verifier

Open sourcing Winterfell: A STARK prover and verifier

We are releasing Winterfell, our implementation of a STARK prover/verifier to Crates.io Winterfell is an easy to use open source implementation of STARKs for security and privacy applications. One potential application for Winterfell’s zero-knowledge proofs is blockchain privacy and scalability. “Any sufficiently advanced technology is indistinguishable from magic.” —Clarke’s Third Law What if the

MEMeta Engineering·August 4, 2021Security
Security — Cloudflare's Handling of an RCE Vulnerability in cdnjs

Cloudflare's Handling of an RCE Vulnerability in cdnjs

Recently, a RCE vulnerability in the way cdnjs’ backend is automatically keeping web resources up to date has been disclosed. Read about how Cloudflare handled the security incident and what will prevent similar exploits in the future.

GTGanz, Thomas CalderonGanz, Thomas Calderon·July 24, 2021Security
Security — DDoS attack trends for 2021 Q2

DDoS attack trends for 2021 Q2

The DDoS attack trends observed over Cloudflare’s network in 2021 Q2 paint a picture that reflects the overall global cyber threat landscape. Here are some highlights of DDoS attack trends observed in 2021 Q2.

VOVivek, OmerVivek, Omer·July 20, 2021Security
Security — How WhatsApp enables multi-device capability

How WhatsApp enables multi-device capability

For years, people have been asking us to create a true multi-device experience that allows people to use WhatsApp on other devices without requiring a smartphone connection. Today, we’re announcing the rollout of a limited public beta test for WhatsApp’s updated multi-device capability. With this new capability, you can now use WhatsApp on your phone […]

CWChris Wiltz·July 14, 2021Security
Security — Enforcing encryption at scale

Enforcing encryption at scale

Our infrastructure supports thousands of services that handle billions of requests per second. We’ve previously discussed how we built our service encryption infrastructure to keep these globally distributed services operating securely and performantly. This post discusses the system we designed to enforce encryption policies within our network and shares some of the lessons we learned […] Read Mo

MEMeta Engineering·July 12, 2021Security
Security — Cloudflare’s SOC as a Service

Cloudflare’s SOC as a Service

Cloudflare SOC as a Service combines our best-in-class security products and a team of cybersecurity experts within Cloudflare that augment your security and network teams

OSOtto, ShashiOtto, Shashi·May 25, 2021Security
Security — How To Implement Authentication In Next.js With Auth0 — Smashing Magazine

How To Implement Authentication In Next.js With Auth0 — Smashing Magazine

At the moment of adding authentication and authorization to our web applications, there are some things that we should evaluate, e.g. whether we need to create our own security platform or whether we can rely on an existing third-party service. Let’s see how we can implement authentication and authorization in Next.js apps, with Auth0.

FGFacundo GiulianiFacundo Giuliani·May 20, 2021Security
Security — Designing the new Cloudflare Web Application Firewall

Designing the new Cloudflare Web Application Firewall

The Cloudflare Web Application Firewall (WAF) protects websites and applications from malicious traffic attempting to exploit vulnerabilities in server software. It’s a critical piece of the broader security posture of your application.

SSyeefSyeef·May 11, 2021Security
Security — Announcing Cloudflare for SaaS for Everyone

Announcing Cloudflare for SaaS for Everyone

Before today, SSL for SaaS was only available to Enterprise customers. Today, we are excited to announce that our SaaS solution is available to everyone. And to reflect the evolution of the product since it was first released, we’re changing the name: Cloudflare for SaaS.

DDinaDina·April 15, 2021Security
Security — Nour Daoud Bösing: Security Engineer

Nour Daoud Bösing: Security Engineer

These days, I don’t need an alarm clock – I get woken up bright and early by my daughter! I live in Jersey City, just across the river from the Spotify NY office, and often used to take the ferry into work. But now, there’s no need to commute – instead, I squeeze in an hour of yoga whilst Leya is entertained by her dad.

SESpotify Engineering·April 1, 2021Security
Security — Fuzzing sockets: Apache HTTP, Part 2: Custom Interceptors

Fuzzing sockets: Apache HTTP, Part 2: Custom Interceptors

In this second installment, I will focus on how to build our own custom ASAN interceptors in order to catch memory bugs when custom memory pools are implemented and also on how to intercept file system syscalls to detect logic errors in the target application.

AMAntonio MoralesAntonio Morales·March 30, 2021Security
Security — Heartbleed Revisited

Heartbleed Revisited

TLS key compromise is a risk for all web services. Taking lessons from Heartbleed, Cloudflare offers the latest features that make key compromise less of a risk.

NSNick SullivanNick Sullivan·March 27, 2021Security
Security — Using Cloudflare for Data Loss Prevention

Using Cloudflare for Data Loss Prevention

The increased use of cloud-based SaaS providers to store and access sensitive data introduces a swath of security risks as management of these resources can be unwieldy. The risk of data loss can be managed by using Cloudflare Access, API Shield, and Browser Isolation.

MMishaMisha·March 24, 2021Security
Security — One day short of a full chain: Part 3 – Chrome renderer RCE

One day short of a full chain: Part 3 – Chrome renderer RCE

In this last post of the series, I’ll exploit a use-after-free in the Chrome renderer (CVE-2020-15972), a bug that I reported in September 2020 but turned out to be a duplicate, to gain remote code execution in the sandboxed renderer process in Chrome.

MYMan Yue MoMan Yue Mo·March 24, 2021Security
Security — New device security partnerships for Cloudflare One

New device security partnerships for Cloudflare One

Cloudflare launches new integrations with CrowdStrike, SentinelOne, and VMware Carbon Black. Cloudflare for Teams customers can now restrict access to their applications based on security signals from their devices.

SKSimon, KennySimon, Kenny·March 23, 2021Security
Security — Announcing antivirus in Cloudflare Gateway

Announcing antivirus in Cloudflare Gateway

We’re announcing support for malware detection and prevention directly from the Cloudflare edge, giving Gateway users an additional line of defense against security threats.

MPMalavika, PeteMalavika, Pete·March 23, 2021Security
Security — Anatomy of a Targeted Ransomware Attack

Anatomy of a Targeted Ransomware Attack

Imagine your most critical systems suddenly stop operating. And then someone demands a ransom to get your systems working again. Or someone launches a DDoS against you and demands a ransom to make it stop. That’s the world of ransomware and ransom DDoS.

CCloudflare·March 23, 2021Security
Security — GitHub Capture the Flag results

GitHub Capture the Flag results

Earlier this month, we challenged you to a Call to Hacktion—a CTF (Capture the Flag) competition to put your GitHub Workflow security skills to the test. Participants were invited to…

BABas AlbertsBas Alberts·March 22, 2021Security
Security — Welcome to Cloudflare Security Week 2021!

Welcome to Cloudflare Security Week 2021!

Today kicks off Cloudflare's 2021 Security Week. Like all innovation weeks at Cloudflare, we'll be announcing a dizzying number of new products, opening products that have been in beta to general availability.

MPMatthew PrinceMatthew Prince·March 21, 2021Security
Security — A deep-dive into Cloudflare’s autonomous edge DDoS protection

A deep-dive into Cloudflare’s autonomous edge DDoS protection

Introducing our autonomous DDoS (Distributed Denial of Service) protection system, globally deployed to all of Cloudflare’s 200+ data centers, and is actively protecting all our customers against DDoS attacks across layers 3 to 7 (in the OSI model) without requiring any human intervention.

OOmerOmer·March 18, 2021Security
Security — The Teams Dashboard: The Design Story

The Teams Dashboard: The Design Story

Here is the story of how we took Cloudflare for Teams from initial concepts, to an MVP, to now a comprehensive security platform that secures networks, users, devices, and applications.

BBethanyBethany·March 18, 2021Security
Security — One day short of a full chain: Part 1 – Android Kernel arbitrary code execution

One day short of a full chain: Part 1 – Android Kernel arbitrary code execution

In this series of posts, I’ll go through the exploit of three security bugs that I reported, which, when used together, can achieve remote kernel code execution in Qualcomm’s devices by visiting a malicious website in a beta version of Chrome. In this first post, I’ll exploit a use-after-free in Qualcomm’s kgsl driver (CVE-2020-11239), a bug that I reported in July 2020 and that was fixed in Janua

MYMan Yue MoMan Yue Mo·March 16, 2021Security
Security — One day short of a full chain: Part 2 – Chrome sandbox escape

One day short of a full chain: Part 2 – Chrome sandbox escape

In this second post of the series, I’ll exploit a use-after-free in the Payment component of Chrome (1125614/GHSL-2020-165), a bug that I reported in September 2020 that only affected version 86 of Chrome, which was in beta. I’ll use it to escape the Chrome sandbox to gain privilege of a third party App on Android from a compromised renderer.

MYMan Yue MoMan Yue Mo·March 16, 2021Security
Security — Dependabot ❤️s private dependencies

Dependabot ❤️s private dependencies

Dependabot’s mission is to keep all of your dependencies free of vulnerabilities and up-to-date, but until now, it hasn’t been able to update all of your private dependencies. That meant…

MMMike McDonaldMike McDonald·March 15, 2021Security
Security — Updates on Shopify's Bug Bounty Program 2021 - Shopify

Updates on Shopify's Bug Bounty Program 2021 - Shopify

For three years we, Shopify’s Application Security team, have set aside time to reflect on our bug bounty program and share recent insights. This past year has been quite a ride, as our program has been busier than ever! We’re excited to share what we have learned, and share some of the great things we have planned!

SEShopify Engineering·March 11, 2021Security
Security — Git clone vulnerability announced

Git clone vulnerability announced

Today, the Git project released new versions to address CVE-2021-21300: a security vulnerability in the delayed checkout mechanism used by Git LFS during git clone operations affecting versions 2.15 and…

TBTaylor BlauTaylor Blau·March 9, 2021Security
Security — Fuzzing sockets: Apache HTTP, Part 1: Mutations

Fuzzing sockets: Apache HTTP, Part 1: Mutations

In this first episode, I’ll do a brief introduction on how Apache HTTP works, and I’ll give you some insights into custom mutators and how they can be applied to the HTTP protocol effectively.

AMAntonio MoralesAntonio Morales·March 2, 2021Security