Home/Security
Topic

Security

1,018 articles on Security.

11,834 articles
Security — DDoS threat report for 2024 Q1

DDoS threat report for 2024 Q1

2024 started with a bang. Cloudflare’s autonomous systems mitigated over 4.5 million DDoS attacks in the first quarter of the year — a 50% increase compared to the previous year. Read the full coverage

OJOmer, JorgeOmer, Jorge·April 16, 2024Security
Security — Why Workers environment variables contain live objects

Why Workers environment variables contain live objects

Bindings don't just reduce boilerplate. They are a core design feature of the Workers platform which simultaneously improve developer experience and application security in several ways. Usually these two goals are in opposition to each other, but bindings elegantly solve for both at the same time

KVKenton VardaKenton Varda·April 1, 2024Security
Security — Gaining kernel code execution on an MTE-enabled Pixel 8

Gaining kernel code execution on an MTE-enabled Pixel 8

In this post, I’ll look at CVE-2023-6241, a vulnerability in the Arm Mali GPU that allows a malicious app to gain arbitrary kernel code execution and root on an Android phone. I’ll show how this vulnerability can be exploited even when Memory Tagging Extension (MTE), a powerful mitigation, is enabled on the device.

MYMan Yue MoMan Yue Mo·March 18, 2024Security
Security — Mitigating a token-length side-channel attack in our AI products

Mitigating a token-length side-channel attack in our AI products

The Workers AI and AI Gateway team recently collaborated closely with security researchers at Ben Gurion University regarding a report submitted through our Public Bug Bounty program. Through this process, we discovered and fully patched a vulnerability affecting all LLM providers. Here’s the story

CMCelso, MichelleCelso, Michelle·March 14, 2024Security
Security — Log Explorer: monitor security events without third-party storage

Log Explorer: monitor security events without third-party storage

With the combined power of Security Analytics + Log Explorer, security teams can analyze, investigate, and monitor for security attacks natively within Cloudflare, reducing time to resolution and overall cost of ownership for customers by eliminating the need to forward logs to third-party SIEMs

JSJen Sells, ClaudioJen Sells, Claudio·March 8, 2024Security
Security — Launching email security insights on Cloudflare Radar

Launching email security insights on Cloudflare Radar

The new Email Security section on Cloudflare Radar provides insights into the latest trends around threats found in malicious email, sources of spam and malicious email, and the adoption of technologies designed to prevent abuse of email

DBDavid BelsonDavid Belson·March 8, 2024Security
Security — Collect all your cookies in one jar with Page Shield Cookie Monitor

Collect all your cookies in one jar with Page Shield Cookie Monitor

Protecting online privacy starts with knowing what cookies are used by your websites. Page Shield extends transparent monitoring to HTTP cookies, empowering security and compliance teams with an easy overview without the need for an external scanner, nor changing existing web applications

CCloudflare·March 7, 2024Security
Security — Eliminate VPN vulnerabilities with Cloudflare One

Eliminate VPN vulnerabilities with Cloudflare One

The Cybersecurity & Infrastructure Security Agency (CISA) recently issued an Emergency Directive due to the Ivanti Connect Secure and Policy Secure vulnerabilities. In this blog, we discuss the threat actor tactics exploiting these vulnerabilities

DHDan Hall, Michael KeaneDan Hall, Michael Keane·March 6, 2024Security
Security — Making messaging interoperability with third parties safe for users in Europe

Making messaging interoperability with third parties safe for users in Europe

To comply with a new EU law, the Digital Markets Act (DMA), which comes into force on March 7th, we’ve made major changes to WhatsApp and Messenger to enable interoperability with third-party messaging services. We’re sharing how we enabled third-party interoperability (interop) while maintaining end-to-end encryption (E2EE) and other privacy guarantees in our services as […]

CWChris Wiltz·March 6, 2024Security
Security — Protecting APIs with JWT Validation

Protecting APIs with JWT Validation

Cloudflare customers can now protect their APIs from broken authentication attacks by validating incoming JSON Web Tokens (JWTs) with API Gateway

JCJohn CosgroveJohn Cosgrove·March 5, 2024Security
Security — Welcome to Security Week 2024

Welcome to Security Week 2024

Cloudflare’s Chief Security Officer introduces 2024 Security Week by sharing insights into the past year of threats, security incidents and key priorities and concerns for global CISOs

GGrantGrant·March 3, 2024Security
Security — Thanksgiving 2023 security incident

Thanksgiving 2023 security incident

On Thanksgiving Day, November 23, 2023, Cloudflare detected a threat actor on our self-hosted Atlassian server. Our security team immediately began an investigation, cut off the threat actor’s access, and no Cloudflare customer data or systems were impacted by this event

MPMatthew Prince, John Graham CummingMatthew Prince, John Graham Cumming·February 1, 2024Security
Security — Introducing Cloudflare’s 2024 API security and management report

Introducing Cloudflare’s 2024 API security and management report

Today, we’re releasing our 2024 API Security and Management Report. This blog introduces and is a supplement to the API Security and Management Report for 2024 where we detail exactly how we’re protecting our customers, and what it means for the future of API security

JCJohn Cosgrove, SabinaJohn Cosgrove, Sabina·January 9, 2024Security
Security — DDoS threat report for 2023 Q4

DDoS threat report for 2023 Q4

Welcome to the sixteenth edition of Cloudflare’s DDoS Threat Report. This edition covers DDoS trends and key findings for the fourth and final quarter of the year 2023, complete with a review of major trends throughout the year

OJOmer, JorgeOmer, Jorge·January 9, 2024Security
Security — Frenemies to friends: Developers and security tools

Frenemies to friends: Developers and security tools

When socializing a new security tool, it IS possible to build a bottom-up security culture where engineering has a seat at the table. Let’s explore some effective strategies witnessed by the GitHub technical sales team to make this shift successful.

SGShelby GluckShelby Gluck·January 8, 2024Security
Security — GitHub’s top blog posts of 2023

GitHub’s top blog posts of 2023

As the year winds down, we’re highlighting some of the incredible work from GitHub’s engineers, product teams, and security researchers.

GGitHub·December 27, 2023Security
Security — Securing our home labs: Frigate code review

Securing our home labs: Frigate code review

This blog post describes two linked vulnerabilities found in Frigate, an AI-powered security camera manager, that could have enabled an attacker to silently gain remote code execution.

LMLogan MacLaren, Jorge RosilloLogan MacLaren, Jorge Rosillo·December 13, 2023Security
Security — Building end-to-end security for Messenger

Building end-to-end security for Messenger

We are beginning to upgrade people’s personal conversations on Messenger to use end-to-end encryption (E2EE) by default. Meta is publishing two technical white papers on end-to-end encryption: Our Messenger end-to-end encryption whitepaper describes the core cryptographic protocol for transmitting messages between clients. The Labyrinth encrypted storage protocol whitepaper explains our protocol f

CWChris Wiltz·December 6, 2023Security
Security — Securing our home labs: Home Assistant code review

Securing our home labs: Home Assistant code review

The GitHub Security Lab examined the most popular open source software running on our home labs, with the aim of enhancing its security. Here’s what we found and what you can do to better protect your own smart home.

AMAlvaro MunozAlvaro Munoz·November 30, 2023Security