
Besides following a docs-as-code approach, at Cloudflare we handle our documentation changes in a public repository. The contributions we get from the entire Cloudflare community help us make our documentation better every day

We named the botnet that launched the 26M rps (requests per second) DDoS attack "Mantis" as it is also like the Mantis shrimp, small but very powerful

We show how the July 11-12 James Webb Telescope images that were revealed had an impact on DNS traffic in NASA and ESA websites, video and image hosting platforms, and news websites. The ‘cosmic’ results may be surprising

Cloudflare is proud to announce the first 35,000 trees from our commitment to help clean up bad bots (and the climate) have been planted

With Event Scheduling for Waiting Room, you can protect your servers from being overloaded during your event while delivering a user experience that is unique to the occasion and consistent with your brand

Location-Aware DDoS Protection is now available in beta for Cloudflare Enterprise customers that are subscribed to the Advanced DDoS service
OJ
Omer, Julien Desgats·July 11, 2022Security 
On Tuesday, the US National Institute of Standards and Technology (NIST) announced which post-quantum cryptography they will standardize.

An outage at one of the largest ISPs in Canada, Rogers Communications, started earlier today, July 8, 2022, and is ongoing (eight hours and counting), and is impacting businesses and consumers.
JT
Joao Tome, Tom Strickx·July 8, 2022SRE & Ops 
Automatic Signed Exchanges may dramatically boost your site visitor numbers

Today, we are announcing experimental support for WASI (the WebAssembly System Interface) on Cloudflare Workers and support within wrangler2 to make it a joy to work with

Cloudflare is expanding our WAF’s threat intelligence capabilities by adding four new managed IP lists that can be used as part of any custom firewall rule

Welcome to our 2022 Q2 DDoS report. This report includes insights and trends about the DDoS threat landscape — as observed across the global Cloudflare network

In this post, we review selected Internet disruptions observed by Cloudflare during the second quarter of 2022, supported by traffic graphs from Cloudflare Radar and other internal Cloudflare tools.

In this post we go over improvements to script status, metadata and categorization.

Here’s a short list of recent technical blog posts to give you something to read today

In this post, we describe how we modified the Linux kernel to optimize for both low latency and high throughput concurrently

Customize multiple HTTP headers with a single click using Cloudflare Managed Transforms

Learn how to patch Linux security vulnerabilities without rebooting the hardware and how to tighten the security of your Linux operating system with eBPF Linux Security Module

With the recent retirement of Microsoft Internet Explorer 11, we analyzed Internet Explorer traffic trends. Breaking the traffic down by bot score revealed much of this traffic is “likely automated”

Hertzbleed is a brand-new family of side-channel attacks that monitors changes on CPU frequency

Today, we want to reinforce our commitment to our hosting ecosystem and small business partners that leverage Cloudflare to help bring a better Internet experience to their customers.

We’re excited to share that Cloudflare has the fastest provider in 1,290 of the top 3,000 most reported networks, up from 1,280 even one month ago during Platform Week

As a technical writer, it’s pretty common to do the thing you’re documenting. After all, it’s really hard to write step-by-step instructions if you haven’t been through those steps. It’s also a great opportunity to provide feedback to our product teams

How Cloudflare’s security team implemented Zero Trust controls
NT
Noelle, Tim Obezuk·June 24, 2022Security 
Using Cloudflare Zero Trust with Kubernetes to enable kubectl without SOCKS proxies

How does Cloudflare One compare to Zscaler's Trust Exchange. Read on to find out.

This blog offers Cloudflare’s perspective on how remote browser isolation can help organizations offload internal web application use cases currently secured by virtual desktop infrastructure (VDI)

Today we’re excited to announce the ability for administrators to apply Zero Trust inspection policies to HTTP/3 traffic

Browser Isolation with private network connectivity enables your users to securely access private web services without installing any software or agents on an endpoint device or absorbing the management and cost overhead of serving virtual desktops

Today, we’re announcing more enhancements to the Cloudflare One platform that make a transition from legacy architecture to the Zero Trust network of the future easier than ever

Cloudflare integrates with Microsoft Intune and combines the power of Cloudflare’s expansive network and Zero Trust suite with Endpoint Manager

During a time of uncertainty due to the global pandemic, a time when everyone was more online than ever before, Cloudflare, Google, and Shopify all came together to build and test Early Hints

How the Database team uses Cloudflare Tunnels internally to improve security and usability of adhoc DB queries

Cloudflare Gateway customers can now utilize dedicated egress IPs and soon will be able to control how these IPs are applied via egress policies

‘My home network is faster than my corporate network’’ is a common complaint of the employees returning to work. Legacy MPLS based networks were not built to support the shift in the applications.

Offloading key applications from your traditional VPN to a cloud-native ZTNA solution like Cloudflare Access is a great place to start with Zero Trust and provides an approachable, meaningful upgrade for your business

Cloudflare recently won the Security Software Innovator award in recognition of our transformative technology in collaboration with Microsoft that makes work easier for our mutual customers

Rest easy knowing exactly who and what is being accessed within your private network. Introducing Private Network Discovery

Security teams that rely on Cloudflare Access can verify a user’s Apple device before they access a sensitive application — no additional software required

Starting today, we’re excited that Access policies can consider anything before allowing a user access to an application. And by anything, we really do mean absolutely anything.

Today, we’re excited to announce Cloudflare One Observability. Cloudflare One Observability will help customers work across Cloudflare One applications to troubleshoot network connectivity, security policies, and performance issues to ensure a consistent experience for employees everywhere

Cloudflare’s IDS capabilities operate across all of your network traffic - any IP port or protocol — whether it flows to your IPs that we advertise on your behalf, IPs we lease to you, or soon, traffic within your private network.

Meet our new threat operations and research team: Cloudforce One. While this team will publish research, that’s not its reason for being. Its primary objective: track and disrupt threat actors

Today, June 21, 2022, Cloudflare suffered an outage that affected traffic in 19 of our data centers
TS
Tom Strickx, Jeremy Hartman·June 21, 2022SRE & Ops 
Traditional SEG architectures were built for the email environments of yesterday. Learn how to seamlessly transition to cloud-native, preemptive email security

In-line Data Loss Prevention is launching in the Cloudflare platform. Customers will be able to scan traffic to identify and protect sensitive data

Today, we are announcing new integrations that enable our customers to integrate third-party threat intel data with the rich threat intelligence from Cloudflare One products — all within the Cloudflare dashboard

As part of our exciting journey to integrate Area 1 into our broader Zero Trust suite, Cloudflare Gateway customers can soon enable Remote Browser Isolation for email links. With Email Link Isolation, gain an unmatched level of protection from sophisticated multi-channel email-based attacks

Zero Trust can let your organization do more, let your organization do it better, and all this can come with cost savings.

If you’ve been thinking about Zero Trust or SASE, Cloudflare One Week will demonstrate why Cloudflare One is one of the most complete SASE offerings in the market, with some of the best performance, and why it will only continue to improve

Last week, the French National Data Protection Authority, CNIL, published guidelines for a GDPR-compliant way of loading Google Analytics. Today, Zaraz is launching a new set of features to help our customers use Google Analytics and similar tools, while meeting those strict standards

Last week, Cloudflare automatically detected and mitigated a 26 million request per second DDoS attack — the largest HTTPS DDoS attack on record

As they have done over the past several years, Syria and Sudan are implementing multi-hour nationwide Internet shutdowns. Algeria has also taken a similar approach in the past, but this year appears to be implementing more targeted website/app blocking

Cloudflare Japan is making a few important changes to our employee benefits

On June 7, the Africa-Asia-Europe-1 (AAE-1) and SEA-ME-WE-5 (SMW-5) submarine cables suffered cable cuts, impactingInternet connectivity for millions of Internet users across multiple countries in the Middle East, Africa, and Asia

To provide Galileo participants with one place to access resources, configuration tips, product explainers, and more, we built the Cloudflare Social Impact Projects Portal

The UK's Internet traffic was clearly impacted with less traffic than usual during this weekend's celebration of Queen Elizabeth II’s Platinum Jubilee. We also show impact from Canada to New Zealand and the royals and news websites

As we celebrate the eighth anniversary of Project Galileo, we want to provide a view into the type of cyber attacks experienced by organizations protected under the project

Today we’re announcing Private Access Tokens, a completely invisible, private way to validate that real users are visiting your site

We started Project Galileo in 2014 with the simple idea that organizations that work in vulnerable yet essential areas of human rights and democracy building should not be taken down because of cyber