
Learn about how Cloudflare's Cloud Email Security tackles QR phishing, why attackers favor QR codes, and Cloudflare's proactive defense strategy against evolving threats

2024 started with a bang. Cloudflare’s autonomous systems mitigated over 4.5 million DDoS attacks in the first quarter of the year — a 50% increase compared to the previous year. Read the full coverage

This blog post is an in-depth walkthrough on how we perform security research leveraging GitHub features, including code scanning, CodeQL, and Codespaces.

GitHub-hosted runners now support Azure private networking. Plus, we’ve added 2 vCPU Linux, 4 vCPU Windows, macOS L, macOS XL, and GPU hosted runners to our runner fleet.

Bindings don't just reduce boilerplate. They are a core design feature of the Workers platform which simultaneously improve developer experience and application security in several ways. Usually these two goals are in opposition to each other, but bindings elegantly solve for both at the same time

In this 2023-early 2024 email analysis, we examine how certain generic Top-Level Domains (TLDs) are primarily used for spam and phishing, and their evolution over a year.

Learn how Vercel protects the AI SDK Playground using our best-in-class DDoS mitigation, Next.js Middleware, and our partner Kasada.

Now in public beta for GitHub Advanced Security customers, code scanning autofix helps developers remediate more than two-thirds of supported alerts with little or no editing.
PT
Pierre Tempel, Eric Tooley·March 20, 2024Security 
In this post, I’ll look at CVE-2023-6241, a vulnerability in the Arm Mali GPU that allows a malicious app to gain arbitrary kernel code execution and root on an Android phone. I’ll show how this vulnerability can be exploited even when Memory Tagging Extension (MTE), a powerful mitigation, is enabled on the device.

The Workers AI and AI Gateway team recently collaborated closely with security researchers at Ben Gurion University regarding a report submitted through our Public Bug Bounty program. Through this process, we discovered and fully patched a vulnerability affecting all LLM providers. Here’s the story
CM
Celso, Michelle·March 14, 2024Security 
A summary of the blog posts and product announcements released during Security Week 2024

With the combined power of Security Analytics + Log Explorer, security teams can analyze, investigate, and monitor for security attacks natively within Cloudflare, reducing time to resolution and overall cost of ownership for customers by eliminating the need to forward logs to third-party SIEMs
JS
Jen Sells, Claudio·March 8, 2024Security 
The new Email Security section on Cloudflare Radar provides insights into the latest trends around threats found in malicious email, sources of spam and malicious email, and the adoption of technologies designed to prevent abuse of email

Cloudflare is the fastest provider in 44% of networks around the world for 95th percentile connection time. Let’s dig into the data and talk about how we do it

Our Security Center now houses Requests for Information (RFIs) and Priority Intelligence Requirements (PIRs). These features are available via API as well and Cloudforce One customers can start leveraging them today for enhanced security analysis
JA
Javier, Alexandra·March 8, 2024Security 
Discover the enhanced URL Scanner API: Now with direct access from the Security Center Investigate Portal, enjoy unlisted scans, multi-device screenshots, and seamless integration within the Cloudflare ecosystem

We're proud to introduce the Advanced DNS Protection system, a robust defense mechanism designed to protect against the most sophisticated DNS-based DDoS attacks
OC
Omer, Cody Doucette·March 7, 2024Security 
Protecting online privacy starts with knowing what cookies are used by your websites. Page Shield extends transparent monitoring to HTTP cookies, empowering security and compliance teams with an easy overview without the need for an external scanner, nor changing existing web applications

Introducing Magic Cloud Networking, a new set of capabilities to visualize and automate cloud networks to give our customers secure, easy, and seamless connection to public cloud environments
SW
Steve Welham, David Naylor·March 6, 2024Security 
This post illustrates some of the Linux Kernel features, which are helping us to keep our production systems more secure. We will deep dive into how they work and why you may consider enabling them as well

The Cybersecurity & Infrastructure Security Agency (CISA) recently issued an Emergency Directive due to the Ivanti Connect Secure and Policy Secure vulnerabilities. In this blog, we discuss the threat actor tactics exploiting these vulnerabilities
DH
Dan Hall, Michael Keane·March 6, 2024Security 
With this version, customers can choose how to best scale their security strategy, gain more control over deployments, and so much more.
VL
Van Ly, David Jarzebowski·March 6, 2024Security 
To comply with a new EU law, the Digital Markets Act (DMA), which comes into force on March 7th, we’ve made major changes to WhatsApp and Messenger to enable interoperability with third-party messaging services. We’re sharing how we enabled third-party interoperability (interop) while maintaining end-to-end encryption (E2EE) and other privacy guarantees in our services as […]

Today we are excited to introduce a new set of capabilities within the Security Center to directly address a common challenge: ensuring comprehensive deployment across your infrastructure. Gain precise insights into where and how to optimize your security posture

Cloudflare customers can now protect their APIs from broken authentication attacks by validating incoming JSON Web Tokens (JWTs) with API Gateway

Security considerations should be an integral part of software’s design, not an afterthought. Explore how Cloudflare adheres to CISA’s Secure by Design principles to shift the industry
KG
Kristina Galicova, Edo Royker·March 4, 2024Security 
From identifying phishing attempts to protect applications and APIs, Cloudflare uses AI to improve the effectiveness of its security solutions to fight against new and more sophisticated attacks

Introducing AI Assistant for Security Analytics. Now it is easier than ever to get powerful insights about your web security. Use the new integrated natural language query interface to explore Security Analytics
JS
Jen Sells, Harley·March 4, 2024Security 
Cloudflare One is introducing user risk scoring, a new set of capabilities to detect risk based on user behavior, so that you can improve security posture across your organization

Generative AI is being used by malicious actors to make phishing attacks much more convincing. Learn how Cloudflare’s email security systems are able to see past the deception using advanced machine learning models

E-commerce websites were targeted by a sophisticated Magecart attack, involving a hidden JavaScript code designed to secretly steal Personally Identifiable Information (PII) and credit card details from users
HJ
Himanshu, Juan Miguel Cejuela·March 4, 2024Security 
Cloudflare’s Chief Security Officer introduces 2024 Security Week by sharing insights into the past year of threats, security incidents and key priorities and concerns for global CISOs

Optimize your web presence for maximum uptime, scalability, and security. Discover the power of frontend clouds for enterprise resilience.

Repo-jacking is a specific type of supply chain attack. This blog post explains what it is, what the risk is, and what you can do to stay safe.
KB
Kevin Backhouse·February 21, 2024Security 
RKRachel Kroll·February 21, 2024Security 
A peek under the hood of GitHub Advanced Security code scanning autofix.
TG
Tiferet Gazit·February 14, 2024Security 
Learn how to use the Dropbox OAuth 2.0 app authorization flow with offline access
DPDropbox Platform Team·February 13, 2024Security 
More developers will have to fix security issues in the age of shifting left. Here, we break down how SAST tools can help them find and address vulnerabilities.

The Fundamentals program has helped us address tech debt, improve reliability, and enhance observability of our engineering systems.
DR
Deepthi Rao Coppisetty·February 8, 2024Security 
In practice, shifting left has been more about shifting the burden rather than the ability. But AI is bringing its promise closer to reality. Here’s how.

On Thanksgiving Day, November 23, 2023, Cloudflare detected a threat actor on our self-hosted Atlassian server. Our security team immediately began an investigation, cut off the threat actor’s access, and no Cloudflare customer data or systems were impacted by this event
MP
Matthew Prince, John Graham Cumming·February 1, 2024Security 
Consider deploying the GitHub Action: Evergreen so that you know each of your repositories are leveraging active dependency management with Dependabot.

Today, we’re releasing our 2024 API Security and Management Report. This blog introduces and is a supplement to the API Security and Management Report for 2024 where we detail exactly how we’re protecting our customers, and what it means for the future of API security
JC
John Cosgrove, Sabina·January 9, 2024Security 
Welcome to the sixteenth edition of Cloudflare’s DDoS Threat Report. This edition covers DDoS trends and key findings for the fourth and final quarter of the year 2023, complete with a review of major trends throughout the year

The GitHub Security Lab teamed up with Ekoparty once again to create some challenges for its yearly Capture the Flag competition!
LM
Logan MacLaren·January 8, 2024Security 
When socializing a new security tool, it IS possible to build a bottom-up security culture where engineering has a seat at the table. Let’s explore some effective strategies witnessed by the GitHub technical sales team to make this shift successful.

Developers care about security, but poorly integrated tools and other factors can cause frustration. Here are five best practices to reduce friction.

As the year winds down, we’re highlighting some of the incredible work from GitHub’s engineers, product teams, and security researchers.

In support of the Australian Cyber Security Strategy 2023-2030 (The Strategy), we want to share how we can help empower Australian organizations and individuals to become more secure
CF
Carly, Fernando·December 18, 2023Security 
Learn about how we run a scalable vulnerability management program built on top of GitHub.
SM
Stephan Miehe·December 14, 2023Security 
This blog post describes two linked vulnerabilities found in Frigate, an AI-powered security camera manager, that could have enabled an attacker to silently gain remote code execution.
LM
Logan MacLaren, Jorge Rosillo·December 13, 2023Security 
How the Figma security engineering team protects GitHub release branches.

Using CVE-2023-43641 as an example, I’ll explain how to develop an exploit for a memory corruption vulnerability on Linux. The exploit has to bypass several mitigations to achieve code execution.

We are beginning to upgrade people’s personal conversations on Messenger to use end-to-end encryption (E2EE) by default. Meta is publishing two technical white papers on end-to-end encryption: Our Messenger end-to-end encryption whitepaper describes the core cryptographic protocol for transmitting messages between clients. The Labyrinth encrypted storage protocol whitepaper explains our protocol f

Customers using GitHub Enterprise Server can gain more insight and understanding into the security of their code.
DJ
David Jarzebowski, Melody Mileski·December 5, 2023Security 
Learn how researchers and security experts at GitHub, Microsoft, and Santander came together to address the challenges presented by the post-quantum cryptography world.
WC
Walker Chabbott·December 5, 2023Security 
Vercel's Conformance and Code Owners bring automated static analysis and framework-defined code ownership to enterprise teams, catching performance and security issues before production while ensuring the right reviewers approve every change.

The GitHub Security Lab examined the most popular open source software running on our home labs, with the aim of enhancing its security. Here’s what we found and what you can do to better protect your own smart home.
AM
Alvaro Munoz·November 30, 2023Security 
Improve your GitHub Action’s security posture by securing your source repository, protecting your maintainers, and making it easy to report security incidents.
MM
Matthew Manning·November 16, 2023Security 
GitHub is announcing general availability of GitHub Copilot Chat and previews of the new GitHub Copilot Enterprise offering, new AI-powered security features, and the GitHub Copilot Partner Program.
TD
Thomas Dohmke·November 8, 2023Security