
Today we are excited to introduce a new set of capabilities within the Security Center to directly address a common challenge: ensuring comprehensive deployment across your infrastructure. Gain precise insights into where and how to optimize your security posture

A deep dive into how we have deployed Zero Trust at Cloudflare while maintaining user privacy

Today, Cloudflare is excited to expand the Descaler program to Authorized Service Delivery Partners (ASDPs) who will now have exclusive access to the Descaler toolkit. Cloudflare is also launching Deskope, a new set of tooling to also help migrate existing Netskope customers to Cloudflare One

Cloudflare customers can now protect their APIs from broken authentication attacks by validating incoming JSON Web Tokens (JWTs) with API Gateway

Cloudflare One now supports Optical Character Recognition and detects source code as part of its Data Loss Prevention (DLP) service

Security considerations should be an integral part of software’s design, not an afterthought. Explore how Cloudflare adheres to CISA’s Secure by Design principles to shift the industry
KG
Kristina Galicova, Edo Royker·March 4, 2024Security 
Cloudflare is one of the first providers to safeguard LLM models and users in the era of AI

From identifying phishing attempts to protect applications and APIs, Cloudflare uses AI to improve the effectiveness of its security solutions to fight against new and more sophisticated attacks

Introducing AI Assistant for Security Analytics. Now it is easier than ever to get powerful insights about your web security. Use the new integrated natural language query interface to explore Security Analytics
JS
Jen Sells, Harley·March 4, 2024Security 
Cloudflare One is introducing user risk scoring, a new set of capabilities to detect risk based on user behavior, so that you can improve security posture across your organization

Generative AI is being used by malicious actors to make phishing attacks much more convincing. Learn how Cloudflare’s email security systems are able to see past the deception using advanced machine learning models

E-commerce websites were targeted by a sophisticated Magecart attack, involving a hidden JavaScript code designed to secretly steal Personally Identifiable Information (PII) and credit card details from users
HJ
Himanshu, Juan Miguel Cejuela·March 4, 2024Security 
Cloudflare’s Chief Security Officer introduces 2024 Security Week by sharing insights into the past year of threats, security incidents and key priorities and concerns for global CISOs

Polyfill.io is now available on cdnjs to reduce the risk of supply chain attacks. Replace your polyfill.io links today for a seamless experience

The new Cloudflare Zaraz pricing makes Zaraz the most affordable way to load third-party tools on your website, starting with 1 million free events per month and all features unlocked

Pingora, our framework for building programmable and memory-safe network services, is now open source. Get started using Pingora today
YE
Yuchen, Edward H Wang·February 28, 2024Networking 
We recently shared an introduction to Cloudflare’s approach to MLOps, which provides a holistic overview of model training and deployment processes at Cloudflare. In this post, we will dig deeper into monitoring, and how we continuously evaluate the models that power Bot Management
DM
Daniel Means·February 16, 2024AI & ML 
Brand Protection's Logo Matching feature enables users to upload an image of the user’s logo or other brand image. The system scans URLs to discover matching logos and then presents the results for users to review

Cloudflare excels in digital transformation, boasting a global network across 310 cities and 13,000 networks. The Global Partner Services Team fosters diverse partnerships with VARs, SIs, GSIs, MSPs, enhancing service delivery and expanding reach

The Cloudflare Zaraz ecosystem is expanding! Read more to learn how you can now connect with Certified Zaraz Developers to help you with migrating to Zaraz, maintaining your configuration and more

Last Thursday, on a clear, sunny morning in Waco, Texas, a jury returned a verdict after less than two hours of deliberation. The jury found that Cloudflare did not infringe the patent asserted against Cloudflare by patent trolls Sable IP and Sable Networks.
PN
Patrick Nemeroff, Emily Terrell·February 12, 2024Engineering 
This is our story of what we learned about the connect() implementation for TCP in Linux. Both its strong and weak points. How connect() latency changes under pressure, and how to open connection so that the syscall latency is deterministic and time-bound

Today, we are announcing a series of updates to our SASE platform, Cloudflare One, that further the promise of a single-vendor SASE architecture

Workers AI is now bigger and better with 8 new models and improved model performance

On Thanksgiving Day, November 23, 2023, Cloudflare detected a threat actor on our self-hosted Atlassian server. Our security team immediately began an investigation, cut off the threat actor’s access, and no Cloudflare customer data or systems were impacted by this event
MP
Matthew Prince, John Graham Cumming·February 1, 2024Security 
During Developer Week, we announced LangChain support for Cloudflare Workers. Since then, we’ve been working with the LangChain team on deeper integration of many tools across Cloudflare’s developer platform and are excited to share what we’ve been up to
RK
Ricky, Kristian·January 31, 2024AI & ML 
On Privacy Day 2024, we answer the EU Commission’s call for reflection on how the GDPR has been functioning by pointing out two ways in which the GDPR has been applied that actually may harm people’s privacy

Foundations is a foundational Rust library, designed to help scale programs for distributed, production-grade systems

The issuance of Emergency Rules by Cloudflare on January 17, 2024, helped give customers a big advantage in dealing with these threats
HR
Himanshu, Radwa·January 23, 2024AI & ML 
In this post, we review selected Internet disruptions observed by Cloudflare during the fourth quarter of 2023, supported by traffic graphs from Cloudflare Radar and other internal Cloudflare tools, and grouped by associated cause or common geography

Today, we’re releasing our 2024 API Security and Management Report. This blog introduces and is a supplement to the API Security and Management Report for 2024 where we detail exactly how we’re protecting our customers, and what it means for the future of API security
JC
John Cosgrove, Sabina·January 9, 2024Security 
Welcome to the sixteenth edition of Cloudflare’s DDoS Threat Report. This edition covers DDoS trends and key findings for the fourth and final quarter of the year 2023, complete with a review of major trends throughout the year

In this post, we’re going to go over what that looks like, how we achieve high availability, and how we meet our Service Level Objectives (SLOs) while shipping close to a million log lines per second

Providing software and web services that deliver value for users often requires measuring user behavior. In this blog we discuss emerging cryptographic and statistical techniques that enable collecting such measurements without violating user privacy

Cloudflare has long supported the open Internet principles that are behind net neutrality, and we still do today. That’s why we filed comments with the FCC expressing our support for these principles

In August of this year, as part of the White House Back to School Safely: K-12 Cybersecurity Summit, Cloudflare announced Project Cybersafe Schools to help support eligible K-12 public school district

In support of the Australian Cyber Security Strategy 2023-2030 (The Strategy), we want to share how we can help empower Australian organizations and individuals to become more secure
CF
Carly, Fernando·December 18, 2023Security 
By editing or creating a new Turnstile widget with “Pre-Clearance” enabled, Cloudflare customers can now use Turnstile to issue a challenge when a page’s HTML loads, and enforce that all valid responses have a valid Turnstile token

In the last decade, IPv6 adoption on the client side went from under 1% to somewhere in the high 30 to low 40 percent, depending on who’s reporting, but there’s also the other end of the equation: the server side

The 2023 Cloudflare Radar Year in Review is our fourth annual review of Internet trends and patterns observed throughout the year at both a global and country/region level...

Building on similar reports we’ve done over the past two years, we have compiled a ranking of the top Internet properties of 2023
CCloudflare·December 12, 2023AI & ML 
This is what Cloudflare has been able to do so far with OpenBMC with respect to our GPU-equipped servers
RC
Ryan Chow, Giovanni·December 6, 2023AI & ML 
A recent decision from the Higher Regional Court of Cologne in Germany marked important progress for Cloudflare and the Internet in pushing back against misguided attempts to address online copyright infringement through the DNS system

Cloudflare Gen 12 Compute servers are moving to 2U1N form factor to optimize the thermal design to accommodate both high-power CPUs (>350W) and GPUs effectively while maintaining performance and reliability

How significant are Cyber Week days on the Internet? Is it a global phenomenon? Does e-commerce interest peak on Black Friday or Cyber Monday, and are attacks increasing during this time?

We provide many tools to help you debug Cloudflare Workers; from your local environment all the way into production. In this post, we highlight some of the tools we currently offer, and do a deep dive into one specific area - breakpoint debugging - a tool we recently added into our workerd runtime
AM
Adam Murray, Brendan Coll·November 28, 2023Systems 
We're excited to introduce Steve Bray as Cloudflare's new Head of Australia and New Zealand, as we continue to build and grow our customers, partners, and team in the region

Forrester has recognized Cloudflare as a leader in The Forrester Wave™: Edge Development Platforms, Q4 2023 with the top score in the current offering category
BI
Brendan Irvine Broque, Dawn·November 27, 2023Networking 
Which US states logged off on Thanksgiving Day? Is there a difference between coastal and central states? Do hackers take a Thanksgiving break? Are food delivery services gaining or losing traffic?

We're thrilled to announce that Stable Diffusion and Code Llama are now available as part of Workers AI, running in over 100 cities across Cloudflare’s global network.

Today we’re excited to announce that we’ve added the Mistral-7B-v0.1-instruct to Workers AI
JI
Jesse, Isaac Rehg·November 21, 2023AI & ML 
We want to ensure that all groups working to promote democracy around the world have the tools they need to stay secure online

The initial posts are dedicated to the x86 architecture. Since then, the fleet of our working machines has expanded to include a large and growing number of ARM CPUs. This time we’ll repeat this exercise for the aarch64 architecture.

Administrators can now easily audit all active user sessions and associated data used by their Cloudflare One policies. This enables the best of both worlds: extremely granular controls, while maintaining an improved ability to troubleshoot and diagnose

Today we are expanding Custom Lists by enabling you to create lists of hostnames and ASNs

Workers AI now supports streaming text responses for the LLM models in our catalog, including Llama-2, using server-sent events
JC
Jesse, Celso·November 14, 2023AI & ML 
Beginning on Thursday, November 2, 2023, at 11:43 UTC Cloudflare's control plane and analytics services experienced an outage. Here are the details

Multiple Cloudflare services were unavailable for 37 minutes on October 30, 2023, due to the misconfiguration of a deployment tool used by Workers KV.
SK
Silverlock, Kris Evans·November 1, 2023SRE & Ops 
Today we're excited to announce Traffic Anomalies notifications, which proactively alert you when your Internet property is seeing an unexpected change in traffic patterns

In the past quarter, DDoS attacks surged by 65%. Gaming and Gambling companies were the most attacked and Cloudflare mitigated thousands of hyper-volumetric DDoS attacks. The largest attacks we saw peaked at 201 million rps and 2.6 Tbps.