Home/Security
Topic

Security

1,018 articles on Security.

11,834 articles
Security — Enhancing the security of WhatsApp calls

Enhancing the security of WhatsApp calls

New optional features in WhatsApp have helped make calling on WhatsApp more secure. “Silence Unknown Callers” is a new setting on WhatsApp that not only quiets annoying calls but also blocks sophisticated cyber attacks. “Protect IP Address in Calls” is a new setting on WhatsApp that helps hide your location from other parties on the […]

CWChris Wiltz·November 8, 2023Security
Security — Understanding cookies

Understanding cookies

Learn how cookies function, how they are used by websites, and the importance of managing them for privacy and security.

VVercel·November 1, 2023Security
Security — DDoS threat report for 2023 Q3

DDoS threat report for 2023 Q3

In the past quarter, DDoS attacks surged by 65%. Gaming and Gambling companies were the most attacked and Cloudflare mitigated thousands of hyper-volumetric DDoS attacks. The largest attacks we saw peaked at 201 million rps and 2.6 Tbps.

OJOmer, JorgeOmer, Jorge·October 26, 2023Security
Security — Cyber attacks in the Israel-Hamas war

Cyber attacks in the Israel-Hamas war

Since the October 7 Hamas attack, DDoS attackers have been targeting Israeli newspaper and media websites as well as software companies and financial institutions.

OJOmer, JorgeOmer, Jorge·October 23, 2023Security
Security — ICYMI: improved C++ vulnerability coverage and CodeQL support for Lombok

ICYMI: improved C++ vulnerability coverage and CodeQL support for Lombok

The effectiveness of a static application security solution hinges on its ability to provide extensive vulnerability coverage and support for a wide range of languages and frameworks. Today, we’re highlighting two releases that’ll help you discover more vulnerabilities in your codebase, so you can ship more secure software.

WCWalker Chabbott, Mathias PedersenWalker Chabbott, Mathias Pedersen·October 19, 2023Security
Security — Network flow monitoring is GA, providing end-to-end traffic visibility

Network flow monitoring is GA, providing end-to-end traffic visibility

Network engineers often need better visibility into their network’s traffic when analyzing DDoS attacks or troubleshooting other traffic anomalies. To solve this problem, Cloudflare offers a network flow monitoring product that gives customers end-to-end traffic visibility across their network.

CCloudflare·October 18, 2023Security
Security — Detecting zero-days before zero-day

Detecting zero-days before zero-day

In this blog post we talk about our approach and ongoing research into detecting novel web attack vectors in our WAF before they are seen by a security researcher.

MTMichael TremanteMichael Tremante·September 29, 2023Security
Security — Understanding CSRF attacks

Understanding CSRF attacks

Understand the mechanics and risks of Cross-Site Request Forgery (CSRF) attacks, and discover crucial development practices, like anti-CSRF tokens and appropriate use of HTTP methods, to fortify web applications against such threats

VVercel·September 29, 2023Security
Security — EU hosting for Figma and FigJam files

EU hosting for Figma and FigJam files

Figma announces new EU hosting options for Figma and FigJam files. Read more on our commitment to data security and what this means for Enterprise plan customers.

FFigma·September 25, 2023Security
Security — Welcome to Birthday Week 2023

Welcome to Birthday Week 2023

Building the future is, in part, what Birthday Week is about. Over the past 13 years we’ve announced things like Universal SSL (doubling the size of the encrypted web overnight), or Cloudflare Workers (helping change the way people build and scale applications). This year will be no different

JGJohn Graham CummingJohn Graham Cumming·September 24, 2023Security
Security — Making Content Security Policies (CSPs) easy with Page Shield

Making Content Security Policies (CSPs) easy with Page Shield

We just deployed a number of updates to our Client-Side Security Product: Page Shield. As of today we support all major CSP directives, better suggestions, better violation reporting, Page Shield specific user role permissions, and domain insights

MTMichael TremanteMichael Tremante·September 15, 2023Security
Security — Meta Quest 2: Defense through offense

Meta Quest 2: Defense through offense

Meta’s Native Assurance team regularly performs manual code reviews as part of our ongoing commitment to improve the security posture of Meta’s products. In 2021, we discovered a vulnerability in the Meta Quest 2’s Android-based OS that never made it to production but helped us find new ways to improve the security of Meta Quest […]

CWChris Wiltz·September 12, 2023Security
Security — Application Security Report: Q2 2023

Application Security Report: Q2 2023

We are back with a quarterly update of our Application Security report. Read on to learn about new attack trends and insights visible from Cloudflare’s global network

MTMichael Tremante, David BelsonMichael Tremante, David Belson·August 21, 2023Security
Security — mTLS: When certificate authentication is done wrong

mTLS: When certificate authentication is done wrong

In this post, we’ll deep dive into some interesting attacks on mTLS authentication. We’ll have a look at implementation vulnerabilities and how developers can make their mTLS systems vulnerable to user impersonation, privilege escalation, and information leakages.

MSMichael StepankinMichael Stepankin·August 17, 2023Security
Security — Curbing Connection Churn in Zuul - Netflix TechBlog

Curbing Connection Churn in Zuul - Netflix TechBlog

When Zuul was designed and developed, there was an inherent assumption that connections were effectively free, given we weren’t using mutual TLS (mTLS). It’s built on top of Netty, using event loops…

NTNetflix TechBlog·August 16, 2023Security
Security — Hardening repositories against credential theft

Hardening repositories against credential theft

Some best practices and important defenses to prevent common attacks against GitHub Actions that are enabled by stolen personal access tokens, compromised accounts, or compromised GitHub sessions.

MMMatthew MasarikMatthew Masarik·August 15, 2023Security
Security — How Meta is improving password security and preserving privacy

How Meta is improving password security and preserving privacy

Meta is developing new privacy-enhancing technologies (PETs) to innovate and solve problems with less data. These technologies enable teams to build and launch privacy-enhanced products in a way that’s verifiable and safeguards user data. Using state-of-the-art cryptographic techniques, we have developed Private Data Lookup (PDL) that allows users to privately query a server-side data set. […] Rea

MEMeta Engineering·August 8, 2023Security
Security — DDoS threat report for 2023 Q2

DDoS threat report for 2023 Q2

Q2 2023 saw an unprecedented escalation in DDoS attack sophistication. Pro-Russian hacktivists REvil, Killnet and Anonymous Sudan joined forces to attack Western sites. Mitel vulnerability exploits surged by a whopping 532%, and attacks on crypto rocketed up by 600%.

OJOmer, JorgeOmer, Jorge·July 18, 2023Security
Security — GitHub achieves ISO/IEC 27701:2019, 27018:2019, and CSA STAR certifications

GitHub achieves ISO/IEC 27701:2019, 27018:2019, and CSA STAR certifications

GitHub’s Information Security and Privacy Management System (ISPMS) has been certified against ISO/IEC 27701:2019 (PII Processor) and 27018:2019 standards, as well as the Cloud Controls Matrix (CCM). These standards and frameworks are internationally recognized for security and privacy program best practices.

BGBrandon Griffeth, Glory FranckeBrandon Griffeth, Glory Francke·July 5, 2023Security
Security — Introduction to SELinux

Introduction to SELinux

SELinux is the most popular Linux Security Module used to isolate and protect system components from one another. Learn about different access control systems and Linux security as I introduce the foundations of a popular type system.

KSKevin StubbingsKevin Stubbings·July 5, 2023Security
Security — GitHub’s revamped VIP Bug Bounty Program

GitHub’s revamped VIP Bug Bounty Program

GitHub’s VIP Bug Bounty Program has been updated to include a clear and accessible criteria for receiving an invitation to the program and more. Learn more about the program and how you can become a Hacktocat, and join our community of researchers who are contributing to GitHub’s security with fun perks and access to staff and beta features!

JGJeff GuerraJeff Guerra·June 12, 2023Security