Home/Security
Topic

Security

1,018 articles on Security.

11,834 articles
Security — Safe in the sandbox: security hardening for Cloudflare Workers

Safe in the sandbox: security hardening for Cloudflare Workers

Cloudflare Workers are constantly being updated to be as secure and efficient as possible. We are further hardening Workers by making use of the latest software and hardware features. We use defense-in-depth, including V8 sandboxes and the CPU's memory protection keys, to keep your data safe.

ECErik Corry, Ketan GuptaErik Corry, Ketan Gupta·September 25, 2025Security
Security — Securing data in SaaS to SaaS applications

Securing data in SaaS to SaaS applications

The recent Salesloft breach taught us one thing: companies do not have visibility over data in SaaS applications. Cloudflare is committing to providing additional security tools to companies who use SaaS applications and downstream integrations.

MTMichael Tremante, Bill SobelMichael Tremante, Bill Sobel·September 24, 2025Security
Security — Our plan for a more secure npm supply chain

Our plan for a more secure npm supply chain

Addressing a surge in package registry attacks, GitHub is strengthening npm’s security with stricter authentication, granular tokens, and enhanced trusted publishing to restore trust in the open source ecosystem.

XRXavier René-CorailXavier René-Corail·September 22, 2025Security
Security — crates.io phishing attempt

crates.io phishing attempt

Earlier this week, an npm supply chain attack . It’s turn for crates.io , the main public repository for Rust crates (packages). The phishing e-mail looks like this: Andrew Gallant on BlueSky And it leads to a GitHub login page that looks like this: Barre on GitHub Several maintainers received it — the issue is being discussed on GitHub . The crates.io team has acknowledged the attack and said the

AWAmos WengerAmos Wenger·September 12, 2025Security
Security — color npm package compromised

color npm package compromised

On September 8 2025, around 13:00 UTC, someone compromised Josh Junon’s npm account (qix) and started publishing backdoored versions of his package. Someone noticed and let Josh know: Charlie Eriksen on BlueSky Josh confirmed he’d gotten pwned by a fake 2FA (two-factor authentication) reset e-mail: Josh Junon on BlueSky The phishing e-mail came from npmsj.help (registered 3 days prior) and claimed

AWAmos WengerAmos Wenger·September 8, 2025Security
Security — Building Slack’s Anomaly Event Response

Building Slack’s Anomaly Event Response

As cyberattacks evolve to unprecedented levels of sophistication and speed, the time gap between breach detection and response has never been more critical. Traditional security approaches often operate reactively, identifying compromises only after damage has occurred. This delay grants attackers a tactical advantage, forcing security teams to focus on damage assessment and remediation rather tha

NLNathan Lehotsky·September 4, 2025Security
Security — Unmasking the Unseen: Your Guide to Taming Shadow AI with Cloudflare One

Unmasking the Unseen: Your Guide to Taming Shadow AI with Cloudflare One

The digital landscape of corporate environments has always been a battleground between efficiency and security. For years, this played out in the form of "Shadow IT" — employees using unsanctioned laptops or cloud services to get their jobs done faster. Security teams became masters at hunting these rogue systems, setting up firewalls and policies to bring order to the chaos. But the new frontier

NJNoelle, Joey SteinbergerNoelle, Joey Steinberger·August 25, 2025Security
Security — Safeguarding VS Code against prompt injections

Safeguarding VS Code against prompt injections

When a chat conversation is poisoned by indirect prompt injection, it can result in the exposure of GitHub tokens, confidential files, or even the execution of arbitrary code without the user’s explicit consent. In this blog post, we’ll explain which VS Code features may reduce these risks.

MSMichael StepankinMichael Stepankin·August 25, 2025Security
Security — How a volunteer-run wildfire site in Portugal stayed online during DDoS attacks

How a volunteer-run wildfire site in Portugal stayed online during DDoS attacks

Fogos.pt, a volunteer-run wildfire tracker in Portugal, grew from a side project into a critical national resource used by citizens, media, and government. During 2025 fire season it was hit by DDoS attacks, but stayed online thanks to Cloudflare’s protections under Project Galileo.How a volunteer-run wildfire site in Portugal stayed online during DDoS attacks

JTJoao TomeJoao Tome·August 21, 2025Security
Security — Redesigning Workers KV for increased availability and faster performance

Redesigning Workers KV for increased availability and faster performance

Workers KV is Cloudflare's global key-value store, serving millions of requests per second across hundreds of billions of stored objects. The service powers critical infrastructure for dozens of Cloudflare products—from Access authentication to Pages static assets—making its availability essential to our platform's reliability. After the incident on June 12, we accelerated work to re-architect KV’

ARAlex Robinson, Tyson TrautmannAlex Robinson, Tyson Trautmann·August 8, 2025Security
Security — v0: vibe coding, securely

v0: vibe coding, securely

Vibe coding makes it possible for anyone to ship a viral app. But every line of AI-generated code is a potential vulnerability. Security cannot be an afterthought, it must be the foundation. Turn ideas into secure apps with v0.

VVercel·August 4, 2025Security
Security — Policy Zones: How Meta enforces purpose limitation at scale in batch processing systems

Policy Zones: How Meta enforces purpose limitation at scale in batch processing systems

Meta has developed Privacy Aware Infrastructure (PAI) and Policy Zones to enforce purpose limitations on data, especially in large-scale batch processing systems. Policy Zones integrates with Meta’s exabyte-scale data warehouse and processing systems, using runtime enforcement and SQL parsing to propagate and enforce privacy annotations across millions of daily data flows per day, performing trill

CWChris Wiltz·July 23, 2025Security
Security — Cloudflare protects against critical SharePoint vulnerability, CVE-2025-53770

Cloudflare protects against critical SharePoint vulnerability, CVE-2025-53770

Microsoft disclosed two critical vulnerabilities, CVE-2025-53771 and CVE-2025-53770, that are exploited to attack SharePoint servers. Possession of these cryptographic machine keys allows an attacker to forge authentication tokens and maintain access even if the server is patched. Therefore, it is critical for customers to apply emergency patches to mitigate this threat.

CCloudflare·July 22, 2025Security
Security — Cloudflare 1.1.1.1 Incident on July 14, 2025

Cloudflare 1.1.1.1 Incident on July 14, 2025

On July 14th, 2025, Cloudflare made a change to our service topologies that caused an outage for 1.1.1.1 on the edge, resulting in downtime for 62 minutes for customers using the 1.1.1.1 public DNS Resolver as well as intermittent degradation of service for Gateway DNS. We’re deeply sorry for this outage. This outage was the result of an internal configuration error and not the result of an attack

APAsh Pallarito, Joe AbleyAsh Pallarito, Joe Abley·July 15, 2025Security
Security — Bypassing MTE with CVE-2025-0072

Bypassing MTE with CVE-2025-0072

In this post, I’ll look at CVE-2025-0072, a vulnerability in the Arm Mali GPU, and show how it can be exploited to gain kernel code execution even when Memory Tagging Extension (MTE) is enabled.

MYMan Yue MoMan Yue Mo·May 23, 2025Security
Security — Resolving a request smuggling vulnerability in Pingora

Resolving a request smuggling vulnerability in Pingora

Cloudflare patched a vulnerability (CVE-2025-4366) in the Pingora OSS framework, which exposed users of the framework and Cloudflare CDN’s free tier to potential request smuggling attacks. After being notified, Cloudflare mitigated the issue within 22 hours.

EHEdward H Wang, Andrew HauckEdward H Wang, Andrew Hauck·May 22, 2025Security
Security — Threat Modeling Guide for Software Teams

Threat Modeling Guide for Software Teams

Threat modeling is a systems engineering practice where teams examine how data flows through systems to identify what can go wrong - a deceptively simple act that reveals security risks that automated tools cannot anticipate. Rather than conducting security analysis as a separate or upfront activity, teams should integrate threat modeling into their development process through small, regular activ

GMGayathri Mohan and Jim Gumbley·May 20, 2025Security
Security — Building Private Processing for AI tools on WhatsApp

Building Private Processing for AI tools on WhatsApp

We are inspired by the possibilities of AI to help people be more creative, productive, and stay closely connected on WhatsApp, so we set out to build a new technology that allows our users around the world to use AI in a privacy-preserving way. We’re sharing an early look into Private Processing, an optional capability […]

CWChris Wiltz·April 29, 2025Security
Security — How Meta understands data at scale

How Meta understands data at scale

Managing and understanding large-scale data ecosystems is a significant challenge for many organizations, requiring innovative solutions to efficiently safeguard user data. Meta’s vast and diverse systems make it particularly challenging to comprehend its structure, meaning, and context at scale. To address these challenges, we made substantial investments in advanced data understanding technologi

CWChris Wiltz·April 28, 2025Security
Security — Implementing end-to-end encryption for Dropbox teams

Implementing end-to-end encryption for Dropbox teams

Learn more about our implementation of end-to-end encryption for teams, the threat model of our design and encryption algorithms, and our commitment to minimizing the risk of data loss with a team-centric key management approach.

RFRobert Freudenreich·April 23, 2025Security