Home/Security
Topic

Security

1,018 articles on Security.

11,834 articles
Security — CVE-2022-47929: traffic control noqueue no problem?

CVE-2022-47929: traffic control noqueue no problem?

In the Linux kernel before 6.1.6, a NULL pointer dereference bug in the traffic control subsystem allows an unprivileged user to trigger a denial of service (system crash) via a crafted traffic control configuration that is set up with "tc qdisc" and "tc class" commands.

FFrederickFrederick·January 31, 2023Security
Security — Bypassing OGNL sandboxes for fun and charities

Bypassing OGNL sandboxes for fun and charities

Object Graph Notation Language (OGNL) is a popular, Java-based, expression language used in popular frameworks and applications, such as Apache Struts and Atlassian Confluence. Learn more about bypassing certain OGNL injection protection mechanisms including those used by Struts and Atlassian Confluence, as well as different approaches to analyzing this form of protection so you can harden similar

AMAlvaro MunozAlvaro Munoz·January 27, 2023Security
Security — What We Learned from Building GovSlack

What We Learned from Building GovSlack

Slack launched GovSlack in July 2022. With GovSlack, government agencies, and those they work with, can enable their teams to seamlessly collaborate in their digital headquarters, while keeping security and compliance at the forefront. Using GovSlack includes the following benefits: Supports key government security standards, such as FedRAMP High, DoD IL4, and ITAR Runs in…

AGArchie Gunasekara·January 24, 2023Security
Security — Pwning the all Google phone with a non-Google bug

Pwning the all Google phone with a non-Google bug

It turns out that the first “all Google” phone includes a non-Google bug. Learn about the details of CVE-2022-38181, a vulnerability in the Arm Mali GPU. Join me on my journey through reporting the vulnerability to the Android security team, and the exploit that used this vulnerability to gain arbitrary kernel code execution and root on a Pixel 6 from an Android app.

MYMan Yue MoMan Yue Mo·January 23, 2023Security
Security — CIO Week 2023 recap

CIO Week 2023 recap

Learn about all the new products, partnerships, and innovations Cloudflare announced during CIO Week to help organizations modernize their IT and security.

JCJames Chang, Corey MahanJames Chang, Corey Mahan·January 13, 2023Security
Security — A smarter, quieter Dependabot

A smarter, quieter Dependabot

Dependabot is getting a little smarter—and, a little quieter—by reducing bot-based noise from repositories based on your interaction with Dependabot.

ETEric Tooley, Erin HavensEric Tooley, Erin Havens·January 12, 2023Security
Security — Passwordless deployments to the cloud

Passwordless deployments to the cloud

Discovering passwords in our codebase is probably one of our worst fears. But what if you didn’t need passwords at all, and could deploy to your cloud provider another way? In this post, we explore how you can use OpenID Connect to trust your cloud provider, enabling you to deploy easily, securely and safely, while minimizing the operational overhead associated with secrets (for example, key rotat

CRChris ReddingtonChris Reddington·January 11, 2023Security
Security — Cloudflare DDoS threat report for 2022 Q4

Cloudflare DDoS threat report for 2022 Q4

In Q4, Cloudflare mitigated millions of DDoS attacks. Attack durations increase, volumetric attacks surged, and ransom DDoS attacks persist. Travel & events industries were hit hardest and over 90% of traffic to Chinese Internet properties were L3/4 DDoS attacks. Read more on our recent report.

OOmerOmer·January 10, 2023Security
Security — Welcome to CIO Week 2023

Welcome to CIO Week 2023

This CIO Week we’ll demonstrate how Cloudflare is helping CIOs keep data, devices and employees both safe and fast across hybrid and remote environments. We’ll show how Cloudflare accelerates digital transformation and modernizes networking and security towards a Zero Trust model

CMCorey Mahan, JuanCorey Mahan, Juan·January 8, 2023Security
Security — How Cloudflare can help stop malware before it reaches your app

How Cloudflare can help stop malware before it reaches your app

Today, we’re making the job of application security teams easier, by providing a content scanning engine integrated with our Web Application Firewall (WAF), so that malicious files being uploaded by end users, never reach origin servers in the first place

MTMichael TremanteMichael Tremante·January 4, 2023Security
Security — How Linear made the most of a DDoS

How Linear made the most of a DDoS

A conversation with the small, but mighty web team about why they made Figma files their homepage, and how they unintentionally threw the Figma party of the year.

CACarly AyresCarly Ayres·December 15, 2022Security
Security — Spotify’s Vulnerability Management Platform

Spotify’s Vulnerability Management Platform

We started developing our vulnerability management platform (VMP) at Spotify in Q2, 2020, and now that we’ve implemented it and use the system in our day-to-day work, we wanted to take a moment to share our journey to help reduce security risks in an efficient and scalable manner.

YMYukio Mizuta and Nurit Izrailov·November 1, 2022Security
Security — Our approach to security at speed

Our approach to security at speed

Learn about how the Figma security team helps us ship products securely, without impacting the pace of development.Our approach to security at speed.

GGGreg Guthe·October 13, 2022Security