Home/Security
Topic

Security

1,018 articles on Security.

11,834 articles
Security — AI Security for Apps is now generally available

AI Security for Apps is now generally available

Cloudflare AI Security for Apps is now generally available, providing a security layer to discover and protect AI-powered applications, regardless of the model or hosting provider. We are also making AI discovery free for all plans, to help teams find and secure shadow AI deployments.

LRLiam Reese, XmflsctLiam Reese, Xmflsct·March 11, 2026Security
Security — How Advanced Browsing Protection Works in Messenger

How Advanced Browsing Protection Works in Messenger

We’re sharing the technical details behind how Advanced Browsing Protection (ABP) in Messenger protects the privacy of the links clicked on within chats while still warning people about malicious links. We hope that this post has helped to illuminate some of the engineering challenges and infrastructure components involved for providing this feature for our users. […]

CWChris Wiltz·March 9, 2026Security
Security — Introducing the 2026 Cloudflare Threat Report

Introducing the 2026 Cloudflare Threat Report

There has been a fundamental shift toward industrialized cyber threats, highlighted by a record 31.4 Tbps DDoS attack and sophisticated session token theft. Our new report examines how nation-states and criminal actors have moved beyond traditional exploits to "living off the XaaS" within legitimate enterprise logic.

CCloudforceCloudforce·March 3, 2026Security
Security — The truly programmable SASE platform

The truly programmable SASE platform

As the only SASE platform with a native developer stack, we’re giving you the tools to build custom, real-time security logic and integrations directly at the edge.

AAbeAbe·March 2, 2026Security
Security — An Exploit ... in CSS?!

An Exploit ... in CSS?!

Read an explanation of the recent CVE-2026-2441 vulnerability that was labeled a "CSS exploit" that "allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page."

LMLee MeyerLee Meyer·February 25, 2026Security
Security — Security boundaries in agentic architectures

Security boundaries in agentic architectures

A framework for drawing security boundaries in agentic architectures. Most agents run with zero isolation between the agent and the code it generates. Learn where to draw the boundaries, from secret injection to full application sandboxing.

VVercel·February 24, 2026Security
Security — No Display? No Problem: Cross-Device Passkey Authentication for XR Devices

No Display? No Problem: Cross-Device Passkey Authentication for XR Devices

We’re sharing a novel approach to enabling cross-device passkey authentication for devices with inaccessible displays (like XR devices). Our approach bypasses the use of QR codes and enables cross-device authentication without the need for an on-device display, while still complying with all trust and proximity requirements. This approach builds on work done by the FIDO […]

CWChris Wiltz·February 4, 2026Security
Security — Rust at Scale: An Added Layer of Security for WhatsApp

Rust at Scale: An Added Layer of Security for WhatsApp

WhatsApp has adopted and rolled out a new layer of security for users – built with Rust – as part of its effort to harden defenses against malware threats. WhatsApp’s experience creating and distributing our media consistency library in Rust to billions of devices and browsers proves Rust is production ready at a global scale. […]

CWChris Wiltz·January 27, 2026Security
Security — Stop Picking Sides

Stop Picking Sides

Many teams have turned into tribes wedded to exclusively adaptation or optimization. But this misses the point that both of these are important, and we need to manage the tension between them. We can do this by thinking of two operating modes: explore (adaptation-dominant) and exploit (optimization dominant). We tailor a team's operating model to a particular blend of the two - considering uncerta

JHJim Highsmith·January 13, 2026Security
Security — Stopping the slow death of internal tools

Stopping the slow death of internal tools

Internal tools often decay due to high maintenance costs and security tradeoffs. Learn how Vercel uses v0 to build secure, sustainable custom software that business teams can ship and maintain without pulling engineers off the roadmap.

VVercel·December 27, 2025Security
Security — Cloudflare outage on December 5, 2025

Cloudflare outage on December 5, 2025

Cloudflare experienced a significant traffic outage on December 5, 2025, starting approximately at 8:47 UTC. The incident lasted approximately 25 minutes before resolution. We are sorry for the impact that it caused to our customers and the Internet. The incident was not caused by an attack and was due to configuration changes being applied to attempt to mitigate a recent industry-wide vulnerabili

DKDane KnechtDane Knecht·December 5, 2025Security
Security — Streamlining Security Investigations with Agents

Streamlining Security Investigations with Agents

Slack’s Security Engineering team is responsible for protecting Slack’s core infrastructure and services. Our security event ingestion pipeline handles billions of events per day from a diverse array of data sources. Reviewing alerts produced by our security detection system is our primary responsibility during on-call shifts. We’re going to show you how we’re using AI…

DMDominic Marks·December 1, 2025Security
Security — Key Transparency Comes to Messenger

Key Transparency Comes to Messenger

We’re excited to share another advancement in the security of your conversations on Messenger: the launch of key transparency verification for end-to-end encrypted chats. This new feature enables an additional level of assurance that only you — and the people you’re communicating with — can see or listen to what is sent, and that no […]

CWChris Wiltz·November 20, 2025Security
Security — Helping protect the 2025 Moldova elections

Helping protect the 2025 Moldova elections

Cloudflare mitigated a 12-hour DDoS attack against Moldova's Central Election Commission, blocking over 898 million malicious requests that peaked at 324,333 requests per second. This defense kept critical election infrastructure online and accessible for citizens during a critical parliamentary vote.

JJocelynJocelyn·October 29, 2025Security
Security — Defending QUIC from acknowledgement-based DDoS attacks

Defending QUIC from acknowledgement-based DDoS attacks

We identified and patched two DDoS vulnerabilities in our QUIC implementation related to packet acknowledgements. Cloudflare customers were not affected. We examine the "Optimistic ACK" attack vector and our solution, which dynamically skips packet numbers to validate client behavior.

AKApoorv Kothari, Louis NavarreApoorv Kothari, Louis Navarre·October 29, 2025Security
Security — State of the post-quantum Internet in 2025

State of the post-quantum Internet in 2025

Today over half of human-initiated traffic with Cloudflare is protected against harvest-now/decrypt-later with post-quantum encryption. What once was a cool science project, is the new security baseline for the Internet. We’re not done yet: in this blog post we’ll take measure where we are, what we expect for the coming years, and what you can do today.

BBasBas·October 28, 2025Security
Security — Agentic AI and Security

Agentic AI and Security

Agentic AI systems present unique security challenges. The fundamental security weakness of LLMs is that there is no rigorous way to separate instructions from data, so anything they read is potentially an instruction. This leads to the “Lethal Trifecta”: sensitive data, untrusted content, and external communication - the risk that the LLM will read hidden instructions that leak sensitive data to

KSKorny Sietsma·October 28, 2025Security
Security — Scaling Privacy Infrastructure for GenAI Product Innovation

Scaling Privacy Infrastructure for GenAI Product Innovation

How does Meta empower its product teams to harness GenAI’s power responsibly? In this post, we delve into how Meta addresses the challenges of safeguarding data in the GenAI era by scaling its Privacy Aware Infrastructure (PAI), with a particular focus on Meta’s AI glasses as an example GenAI use case. We’ll describe in detail […]

CWChris Wiltz·October 23, 2025Security
Security — Introducing REACT: Why We Built an Elite Incident Response Team

Introducing REACT: Why We Built an Elite Incident Response Team

We're launching Cloudforce One REACT, a team of expert security responders designed to eliminate the gap between perimeter defense and internal incident response. The team brings unmatched threat intelligence and network-native mitigation to help organizations prepare for and respond to security crises across any environment.

COChris Orourke, Utsav AdhikariChris Orourke, Utsav Adhikari·October 9, 2025Security