
In this blog, I’ll look at CVE-2022-46395, a variant of CVE-2022-36449 (Project Zero issue 2327), and use it to gain arbitrary kernel code execution and root privileges from the untrusted app domain on an Android phone that uses the Arm Mali GPU. I’ll also explain how root cause analysis of CVE-2022-36449 led to the discovery of CVE-2022-46395.

GitHub Advanced Security for Azure DevOps is now available for public preview, making GitHub’s same application security testing tools natively available on Azure Repos.

Secure your team’s usage of AI tools with Cloudflare One

Code scanning detects ReDoS vulnerabilities automatically, but fixing them isn’t always easy. This blog post describes a 4-step strategy for fixing ReDoS bugs.

Learn how Clerk is reimagining authentication to embrace the architecture of framework-defined infrastructure.

Code scanning’s tool status gives you a bird’s eye view of your application security stack, allowing you to quickly confirm everything is working, or troubleshoot any tool in your application security arsenal.
WC
Walker Chabbott, Alona Hlobina·May 4, 2023Security 
Highlighting the advantages of self-hosted solutions over cloud-based alternatives and exploring collaborative password management and more, P demonstrates how to organize convenient and secure password management in a company.

We’re sharing our latest threat research and technical analysis into persistent malware campaigns targeting businesses across the internet, including threat indicators to help raise our industry’s collective defenses across the internet. These malware families – including Ducktail, NodeStealer and newer malware posing as ChatGPT and other similar tools– targeted people through malicious browser ex

A new alert rules engine for Dependabot leverages alert metadata to identify and auto-dismiss up to 15% of alerts as false positives.

Cloudflare proudly sponsored Australian Privacy Awareness Week 2023, championing privacy and security technologies to help customers protect sensitive data, forming the "new privacy basics."


Researchers have recently published the discovery of a new DDoS reflection/amplification attack vector leveraging the SLP protocol. Cloudflare expects the prevalence of SLP-based DDoS attacks to rise in the coming weeks
AF
Alex Forster, Omer·April 25, 2023Security 
As someone who is passionate about technology, security, and its potential to improve our lives, I knew that I wanted to work for a company that shared those values.

Dockerizing your Node.js apps can lead to smashing success—offering consistency, easy debugging, and hassle-free dependency management. When you host this container on Kinsta, you also benefit from high-speed performance, robust security, and top-notch scalability. By combining these two, you

Open source maintainers and security researchers embrace a new best practice to report and fix vulnerabilities.
ET
Eric Tooley, Kate Catlin·April 19, 2023Security 
How to verifiably link npm packages to their source repository and build instructions.
BD
Brian DeHamer, Philip Harrison·April 19, 2023Security 
Cloudflare Zero Trust named to Gartner® Magic Quadrant™ for Security Service Edge

Learn how the new and improved Network Analytics dashboard provides security professionals insights into their DDoS attack and traffic landscape

Threat actors kicked off 2023 with a bang. The start of the year was characterized by a series of hacktivist campaigns against Western targets, and record-breaking hyper volumetric attacks

In this post, I’ll look at a security-related change in version r40p0 of the Arm Mali driver that was AWOL in the January update of the Pixel bulletin, where other patches from r40p0 was applied, and how these two lines of changes can be exploited to gain arbitrary kernel code execution and root from a malicious app. This highlights how treacherous it can be when backporting security changes.

With enterprise accounts for all, your organization can take advantage of all that GitHub Enterprise has to offer, from GitHub Actions and GitHub Advanced Security, to Copilot.
MM
Melody Mileski, Erika Xu·April 5, 2023Security 
If you are a developer who wants to concentrate on delivering a killer application rather than worrying about countless security issues, threat model documents can help you do that. With small architectural changes, we can make these threats manageable and prevent them in the future.
ZG
Zack Grossbart Terry Yao·April 5, 2023Security 
This blog post outlines the root cause analysis and solution for a bug found in Cloudflare’s mTLS implementation

A high-quality audit log is an essential tool for enterprises to ensure compliance, maintain security, investigate issues, and promote accountability.

Learn more about static analysis and how to use it for security research! In this blog post series, we will take a closer look at static analysis concepts, present GitHub’s static analysis tool CodeQL, and teach you how to leverage static analysis for security research by writing custom CodeQL queries.
SB
Sylwia Budzynska·March 31, 2023Security 
Over the past 24 hours, Cloudflare has observed HTTP DDoS attacks targeting university websites in Australia. Universities were the first of several groups publicly targeted by the pro-Russian hacker group Killnet and their affiliate AnonymousSudan, as revealed in a recent Telegram post
PB
Patrick, Ben Munroe·March 29, 2023Security 
Dealing with sensitive data is an important topic for any app. In this article, you will find out how to handle sensitive or confidential information in your apps and what Row-Level Security means.

Passkeys are a new login credential based on public-key cryptography that replace the need for username and password sign-ins.
SEShopify Engineering·March 24, 2023Security 
Cloudflare will now allow customers that are managing DNS externally to auto-renew certificates through DCV Delegation

Writing secure code is as much of an art as writing functional code, and it is the only way to write quality code. Learn how our Secure Code Game can provide you with hands-on training to spot and fix security issues in your code so that you can build a secure code mindset.
JK
Joseph Katsioloudes·March 23, 2023Security 
Learn how Cloudflare made it easier to shift from protecting applications, to protecting employees, and making sure they are protected everywhere during Security Week 2023

Revealing Account Security Analytics and Events, new eyes on your account in Cloudflare dashboard to give holistic visibility. No matter how many zones you manage, they are all there!

Cloudflare’s Area 1 Solution works with Knowbe4 to provide customers with security and awareness training

IBM and Cloudflare continue to partner together to help customers meet the unique security, performance, resiliency and compliance needs of their customers through the addition of exciting new product and service offerings.

Now, customers will be able to use our Cloudflare Tunnels product to send traffic to the key server through a secure channel, without publicly exposing it to the rest of the Internet

Cloudflare has developed proprietary models leveraging machine learning and other advanced analytical techniques to detect security threats that take advantage of the domain name system (DNS)

We are making the machine learning empowered WAF and Security analytics view available to our Business plan customers, to help detect and stop attacks before they are known

One year ago we published our first Application Security Report. For Security Week 2023, we are providing updated insights and trends around mitigated traffic, bot and API traffic, and account takeover attacks.
MT
Michael Tremante, David Belson·March 14, 2023Security 
Cloudflare is excited to launch the Descaler Program, a frictionless path to migrate existing Zscaler customers to Cloudflare One. Cloudflare is making it even easier for enterprise customers to make the switch to a faster, simpler, and more agile foundation for security and network transformation
CM
Corey Mahan, Aj·March 14, 2023Security 
The Cloudflare App for Sumo Logic now supports Zero Trust logs for out of the box, ready-made security dashboards
CM
Corey Mahan, Drew Horn·March 14, 2023Security 
In order to breach trust and trick unsuspecting victims, threat actors overwhelmingly use topical events as lures. The news about what happened at Silicon Valley Bank is the latest event to watch out for and stay vigilant against opportunistic phishing campaigns using SVB as the lure

Cloudflare CASB can now integrate and scan Atlassian products, Confluence and Jira, for critical security issues, like misconfigurations, data exposure, and third-party app risks. Start scanning in just a few clicks!

Cloudflare Access and Ping Identity offer a powerful solution for organizations looking to implement Zero Trust security controls to protect their applications and data.

Starting today, using Page Shield, Cloudflare’s client side security solution, you can ensure only vetted and secure JavaScript is being executed by your user’s browsers. Stop unwanted JavaScript and keep your end user data safe with Page Shield policies.
MT
Michael Tremante·March 13, 2023Security 
We’re expanding the phishing protections available to Cloudflare One customers by automatically identifying—and blocking—so-called “confusable” domains.
AP
Alexandra, Patrick·March 13, 2023Security 
Phishing attacks come in all sorts of ways to fool people. Email is definitely the most common, but there are others. Here are some tips to help you catch these scams before you fall for them.

Mutual TLS is used to secure a range of network services and applications: APIs, web applications, microservices, databases and IoT devices. With mTLS support for Workers you can use Workers to authenticate to any service secured by mTLS directly!
TD
Tanushree, Dina·March 13, 2023Security 
Welcome to Security Week 2023. This week we’ll demonstrate how Cloudflare is making it as easy as possible to shift from protecting applications, to protecting employees, and making sure they are protected everywhere.

Learn about using GitHub Advanced Security alerts with vulnerability management tools. Check out the integrations and learn about how to get started.
AD
Alexander De Michieli, Griffin Ashe·March 10, 2023Security 
In a world where software and hardware is ubiquitous, GitHub can help enable secure development for mission-critical embedded systems.
CR
Chris Reddington, Clay Nelson·March 9, 2023Security 
On March 13, we will officially begin rolling out our initiative to require all developers who contribute code on GitHub.com to enable one or more forms of two-factor authentication (2FA) by the end of 2023. Read on to learn about what the process entails and how you can help secure the software supply chain with 2FA.
LP
Laura Paine, Hirsch Singhal·March 9, 2023Security 
Multi-repository variant analysis lets you scale security research across thousands of repositories, giving you a powerful tool to find and respond to newly discovered vulnerabilities.
WC
Walker Chabbott, James Fletcher·March 9, 2023Security 
Learn how teams can leverage the power of GitHub Advanced Security’s code scanning and GitHub Actions to integrate the right security testing tools at the right time.
JP
Jose Palafox, Daniel Shanahan·March 8, 2023Security 
Join us virtually on March 28-31 for GitHub Galaxy, a global enterprise event focused on improving efficiency, security, and developer productivity.

With updates to GitHub Actions, repositories, and GitHub Advanced Security, this new version of GitHub Enterprise Server is focused on bringing the best developer experience to companies.
DJ
David Jarzebowski, Melody Mileski·March 7, 2023Security 
The GitHub Security Lab audited DataHub, an open source metadata platform, and discovered several vulnerabilities in the platform’s authentication and authorization modules. These vulnerabilities could have enabled an attacker to bypass authentication and gain access to sensitive data stored on the platform.

Learn how to enable developer productivity and collaboration while staying secure and compliant. Stay compliant without slowing down your business. From security to CI/CD, automate every step of your software workflow—so your developers can stay focused on what matters most: building.
MP
Mark Paulsen, Chris Reddington·February 24, 2023Security 
CVE-2022-25664, a vulnerability in the Qualcomm Adreno GPU, can be used to leak large amounts of information to a malicious Android application. Learn more about how the vulnerability can be used to leak information in both the user space and kernel space level of pages, and how the GitHub Security Lab used the kernel space information leak to construct a KASLR bypass.

Implementing Zero Trust can be challenging, and efforts may stall. The need for a Chief Zero Trust Officer (CZTO) is driven by the increasing importance of Zero Trust security in the face of escalating cyber attacks.
JE
John Engates·February 21, 2023Security 
This was a weekend of record-breaking DDoS attacks. Over the weekend, Cloudflare detected and mitigated dozens of hyper-volumetric DDoS attacks. The majority of attacks peaked in the ballpark of 50-70 million requests per second (rps) with the largest exceeding 71 million rps
OJ
Omer, Julien Desgats·February 13, 2023Security