
Cloudflare Workers are constantly being updated to be as secure and efficient as possible. We are further hardening Workers by making use of the latest software and hardware features. We use defense-in-depth, including V8 sandboxes and the CPU's memory protection keys, to keep your data safe.
EC
Erik Corry, Ketan Gupta·September 25, 2025Security 
The recent Salesloft breach taught us one thing: companies do not have visibility over data in SaaS applications. Cloudflare is committing to providing additional security tools to companies who use SaaS applications and downstream integrations.
MT
Michael Tremante, Bill Sobel·September 24, 2025Security 
We're expanding Cloudflare for Startups to include non-profits, civil society, and public interest orgs. Eligible organizations can now receive up to $250,000 in Cloudflare credits for our developer and core products, including AI, databases, and security.
PD
Patrick Day, Jocelyn·September 22, 2025Security 
Addressing a surge in package registry attacks, GitHub is strengthening npm’s security with stricter authentication, granular tokens, and enhanced trusted publishing to restore trust in the open source ecosystem.
XR
Xavier René-Corail·September 22, 2025Security 
Post-quantum cryptography protects against quantum threats using today’s hardware. Quantum tech like QKD may sound appealing, but it isn’t necessary or sufficient to secure organizations.

Use mcp-to-ai-sdk to generate MCP tools directly into your project. Gain security, reliability, and prompt-tuned control while avoiding dynamic MCP risks.

Cloudflare and CrowdStrike have partnered to help SOC teams minimize manual bottlenecks. By combining Cloudflare’s SASE platform with CrowdStrike’s Falcon® Fusion SOAR, security teams can now detect and remediate cross-domain threats automatically.

GitHub is introducing post-quantum secure key exchange methods for SSH access to better protect Git data in transit.
BM
brian m. carlson, Taylor Blau·September 15, 2025Security 
Cloudflare’s Dashboard and a set of related APIs were unavailable or partially available for an hour starting on Sep 12, 17:57 UTC. The outage did not affect the serving of cached files via the Cloudflare CDN or other security features at the Cloudflare Edge.
TL
Tom Lianza, Joaquin·September 13, 2025Security 
Earlier this week, an npm supply chain attack . It’s turn for crates.io , the main public repository for Rust crates (packages). The phishing e-mail looks like this: Andrew Gallant on BlueSky And it leads to a GitHub login page that looks like this: Barre on GitHub Several maintainers received it — the issue is being discussed on GitHub . The crates.io team has acknowledged the attack and said the
AW
Amos Wenger·September 12, 2025Security 
Connect commits to artifacts without switching tools.

On September 8 2025, around 13:00 UTC, someone compromised Josh Junon’s npm account (qix) and started publishing backdoored versions of his package. Someone noticed and let Josh know: Charlie Eriksen on BlueSky Josh confirmed he’d gotten pwned by a fake 2FA (two-factor authentication) reset e-mail: Josh Junon on BlueSky The phishing e-mail came from npmsj.help (registered 3 days prior) and claimed

How Vercel responded to the September 2025 npm supply chain attack on chalk, debug and 16 other packages. Incident timeline, impact analysis, and customer remediation.

Unauthorized TLS certificates were issued for 1.1.1.1 by a Certification Authority without permission from Cloudflare. These rogue certificates have now been revoked. Read our blog to see how this could affect you.
JA
Joe Abley, Thibault·September 4, 2025Security 
As cyberattacks evolve to unprecedented levels of sophistication and speed, the time gap between breach detection and response has never been more critical. Traditional security approaches often operate reactively, identifying compromises only after damage has occurred. This delay grants attackers a tactical advantage, forcing security teams to focus on damage assessment and remediation rather tha
NLNathan Lehotsky·September 4, 2025Security 
We're now leveraging our internal LLM, Cloudy, to generate automated summaries within our Email Security product, helping SOC teams better understand what's happening within flagged messages.
AN
Ayush, Nick Blazier·August 29, 2025Security 
GenAI tools bring power — and risk. Cloudflare CASB now scans ChatGPT, Claude, and Gemini for misconfigurations, sensitive data exposure, and compliance issues, helping organizations adopt AI with confidence.

This guide provides best practices for Security and IT leaders to securely adopt generative AI using Cloudflare’s SASE architecture as part of a strategy for AI Security Posture Management (AI-SPM).

Cloudflare's AI security suite now includes unsafe content moderation, integrated into the Application Security Suite via Firewall for AI. Built with Llama, it detects and blocks harmful prompts before they reach your AI applications.
RM
Radwa, Mathias Deschamps·August 26, 2025Security 
Our analysis showed that even with very high two-factor authentication trigger rates—which traditionally add friction to the checkout flow—France, the UK, and Japan still maintain high conversion rates.
AB
Amandeep Batra·August 26, 2025Security 
The digital landscape of corporate environments has always been a battleground between efficiency and security. For years, this played out in the form of "Shadow IT" — employees using unsanctioned laptops or cloud services to get their jobs done faster. Security teams became masters at hunting these rogue systems, setting up firewalls and policies to bring order to the chaos. But the new frontier
NJ
Noelle, Joey Steinberger·August 25, 2025Security 
When a chat conversation is poisoned by indirect prompt injection, it can result in the exposure of GitHub tokens, confidential files, or even the execution of arbitrary code without the user’s explicit consent. In this blog post, we’ll explain which VS Code features may reduce these risks.
MS
Michael Stepankin·August 25, 2025Security 
Fogos.pt, a volunteer-run wildfire tracker in Portugal, grew from a side project into a critical national resource used by citizens, media, and government. During 2025 fire season it was hit by DDoS attacks, but stayed online thanks to Cloudflare’s protections under Project Galileo.How a volunteer-run wildfire site in Portugal stayed online during DDoS attacks

A new HTTP/2 denial-of-service (DoS) vulnerability called MadeYouReset was recently disclosed by security researchers. Cloudflare HTTP DDoS mitigation, already protects from MadeYouReset.
AF
Alex Forster, Noah·August 14, 2025Security 
Workers KV is Cloudflare's global key-value store, serving millions of requests per second across hundreds of billions of stored objects. The service powers critical infrastructure for dozens of Cloudflare products—from Access authentication to Pages static assets—making its availability essential to our platform's reliability. After the incident on June 12, we accelerated work to re-architect KV’
AR
Alex Robinson, Tyson Trautmann·August 8, 2025Security 
Vibe coding makes it possible for anyone to ship a viral app. But every line of AI-generated code is a potential vulnerability. Security cannot be an afterthought, it must be the foundation. Turn ideas into secure apps with v0.

An upcoming vulnerability disclosure in Cloudflare’s SSL for SaaSv1 is detailed, explaining the steps we’ve taken towards deprecation and how the newer Cloudflare for SaaS mitigates this risk through hostname verification.
MA
Mia, Albert Pedersen·August 1, 2025Security 
Build a custom Azure DevOps extension that eliminates the complexity of JWT generation and token management, enabling powerful automation and enhanced security controls.

Meta has developed Privacy Aware Infrastructure (PAI) and Policy Zones to enforce purpose limitations on data, especially in large-scale batch processing systems. Policy Zones integrates with Meta’s exabyte-scale data warehouse and processing systems, using runtime enforcement and SQL parsing to propagate and enforce privacy annotations across millions of daily data flows per day, performing trill

Microsoft disclosed two critical vulnerabilities, CVE-2025-53771 and CVE-2025-53770, that are exploited to attack SharePoint servers. Possession of these cryptographic machine keys allows an attacker to forge authentication tokens and maintain access even if the server is patched. Therefore, it is critical for customers to apply emergency patches to mitigate this threat.

Strengthen your repositories against actions workflow injections — one of the most common vulnerabilities.

Welcome to the 22nd edition of the Cloudflare DDoS Threat Report. Published quarterly, this report offers a comprehensive analysis of the evolving threat landscape of Distributed Denial of Service (DDoS) attacks based on data from the Cloudflare network. In this edition, we focus on the second quarter of 2025.

On July 14th, 2025, Cloudflare made a change to our service topologies that caused an outage for 1.1.1.1 on the edge, resulting in downtime for 62 minutes for customers using the 1.1.1.1 public DNS Resolver as well as intermittent degradation of service for Gateway DNS. We’re deeply sorry for this outage. This outage was the result of an internal configuration error and not the result of an attack
AP
Ash Pallarito, Joe Abley·July 15, 2025Security 
Gartner has recognized Cloudflare as a Visionary in the 2025 Gartner® Magic Quadrant™ for SASE Platforms report. We view this evaluation as a significant recognition of our strategy to help connect and secure workspace security and coffee shop networking, through our unique connectivity cloud approach.
AC
Abe, Corey Mahan·July 15, 2025Security 
Discover how to increase the coverage of your CodeQL CORS security by modeling developer headers and frameworks.

Today, the Git project released new versions to address seven security vulnerabilities that affect all prior versions of Git.

DjVuLibre has a vulnerability that could enable an attacker to gain code execution on a Linux Desktop system when the user tries to open a crafted document.
KB
Kevin Backhouse, Antonio Morales·July 3, 2025Security 
Here's how we scaled Santa, an open-source binary authorization tool, across all Figmates’ laptops to boost endpoint security while keeping workflows seamless.

Bots can start authenticating to Cloudflare using public key cryptography, preventing them from being spoofed and allowing origins to have confidence in their identity.
MA
Mari, Akshat Mahajan·July 1, 2025Security 
The GitHub dependency graph maps every direct and transitive dependency in your project, so you can identify risks, prioritize fixes, and keep your code secure.

To celebrate United Nations Micro, Small, and Medium Sized Enterprises Day, Cloudflare is sharing success stories of small businesses building and growing on our platform and providing security guides to help protect their digital presence worldwide.
JS
Jocelyn, Smrithi Ramesh·June 27, 2025Security 
Use these insights to automate software security (where possible) to keep your projects safe.

Orange Meets, our open-source video calling web application, now supports end-to-end encryption using the MLS protocol with continuous group key agreement
MR
Michael Rosenberg, Kevin Kipp·June 26, 2025Security 
In mid-May 2025, blocked the largest DDoS attack ever recorded: a staggering 7.3 terabits per second (Tbps).

Dive into the novel security challenges AI introduces with the open source game that over 10,000 developers have used to sharpen their skills.
JK
Joseph Katsioloudes·June 3, 2025Security 
DNS rebinding attack without CORS against local network web applications. Explore the topic further and see how it can be used to exploit vulnerabilities in the real-world.
JL
Jaroslav Lobacevski·June 3, 2025Security 
Forrester has recognized Cloudflare Email Security as a Strong Performer in the ‘current offering’ category in “The Forrester Wave™: Email, Messaging, And Collaboration Security Solutions.

Maintaining and developing complex and risky code is never easy. See how we addressed the challenges of securing our SAML implementation with this behind-the-scenes look at building trust in our systems.
GO
Greg Ose, Taylor Reis·May 27, 2025Security 
For the third consecutive year, Gartner has named Cloudflare to the Gartner® Magic Quadrant™ for Security Service Edge (SSE) report.

In this post, I’ll look at CVE-2025-0072, a vulnerability in the Arm Mali GPU, and show how it can be exploited to gain kernel code execution even when Memory Tagging Extension (MTE) is enabled.

Since February, Vercel blocked over 148 billion attacks from 108 million IPs. This roundup highlights improvements to bot protection, DoS mitigation, and firewall tooling to help teams build securely by default.

Cloudflare patched a vulnerability (CVE-2025-4366) in the Pingora OSS framework, which exposed users of the framework and Cloudflare CDN’s free tier to potential request smuggling attacks. After being notified, Cloudflare mitigated the issue within 22 hours.
EH
Edward H Wang, Andrew Hauck·May 22, 2025Security 
Threat modeling is a systems engineering practice where teams examine how data flows through systems to identify what can go wrong - a deceptively simple act that reveals security risks that automated tools cannot anticipate. Rather than conducting security analysis as a separate or upfront activity, teams should integrate threat modeling into their development process through small, regular activ
GMGayathri Mohan and Jim Gumbley·May 20, 2025Security 
In line with CISA’s Secure By Design pledge, Cloudflare shares its vulnerability disclosure process, CVE issuance criteria, and CNA duties. This post outlines how findings are triaged based on real-world exploitability, coordinate disclosures, and contribute to the broader security community.
SP
Sri Pulla, Martin·May 16, 2025Security 
Learn how to effectively prioritize alerts using severity (CVSS), exploitation likelihood (EPSS), and repository properties, so you can focus on the most critical vulnerabilities first.
AG
Andrea Griffiths, Carlin Cherry·April 29, 2025Security 
We are inspired by the possibilities of AI to help people be more creative, productive, and stay closely connected on WhatsApp, so we set out to build a new technology that allows our users around the world to use AI in a privacy-preserving way. We’re sharing an early look into Private Processing, an optional capability […]

Managing and understanding large-scale data ecosystems is a significant challenge for many organizations, requiring innovative solutions to efficiently safeguard user data. Meta’s vast and diverse systems make it particularly challenging to comprehend its structure, meaning, and context at scale. To address these challenges, we made substantial investments in advanced data understanding technologi

DDoS attacks are surging. In 2025 Q1, Cloudflare blocked +20M attacks (a 358% YoY spike) along with 5.6 Tbps and 4.8 Bpps record-breaking attacks. And that's just the beginning. Read more in our latest DDoS Threat Report.


Learn more about our implementation of end-to-end encryption for teams, the threat model of our design and encryption algorithms, and our commitment to minimizing the risk of data loss with a team-centric key management approach.
RFRobert Freudenreich·April 23, 2025Security