
Internet shut down in Kazakhstan amid unrest
In Kazakhstan, the year had barely got going when yesterday disruptions of Internet access ended up in a nationwide Internet shutdown from today, January 5, 2022
2,099 articles from Cloudflare.

In Kazakhstan, the year had barely got going when yesterday disruptions of Internet access ended up in a nationwide Internet shutdown from today, January 5, 2022

On the morning of January 4, 2022, citizens of The Gambia woke up to a country-wide Internet outage

As we approach the end of the year, let's look ahead at some trends and predictions for 2022

In 2021, we continued to live with the effects of the COVID pandemic and Internet traffic was also impacted (differently than in 2020) from it.

Join us in our Year in Review 2021 focused on the most popular domains-websites

Cloudflare Pages now natively supports full stack Remix applications

Cloudflare Is reducing the environmental impact of web searches with 20+ billions crawler hints delivered so far. This blog describes the technical solution of how we built the Crawler Hints system that makes all this possible.

This vulnerability is actively being exploited and anyone using Log4J should update to version 2.16.0 as soon as possible. Latest version is available on the Log4J download page.

Recently, we received a bug bounty report regarding the GPG signing key used for pkg.cloudflareclient.com, the Linux package repository for our Cloudflare WARP products.

This article covers WAF evasion patterns and exfiltration attempts, trend data on attempted exploitation, and information on exploitation that we saw prior to the public disclosure of CVE-2021-44228.

Many Cloudflare customers consume their logs using software that uses Log4j, so we are mitigating any exploit attempts via Cloudflare Logs.

Bulk Redirects is a new product that allows an administrator to upload and enable hundreds of thousands of URL redirects within minutes, without having to write a single line of code.

Today, we are announcing a closed beta of HTTP Applications: a new way to safely test and deploy changes to your HTTP traffic

Customer confidence in our ability to handle their sensitive information in an ever-changing regulatory landscape has to be as solid as our offerings, so we have expanded the scope of our previously-existing compliance validations; not only that, we’ve also managed to obtain a couple of new ones.

Instant network provisioning in over 1000 new locations coming over the next year makes it faster and easier than ever to interconnect with Cloudflare.

We know that notifications are incredibly important to our customers. Cloudflare sits in between your Internet property and the rest of the world. When something goes wrong, you want to know right away because it could have a huge impact on your end users.

While over time best practices and technologies change, we aim to ensure our platform meets the security needs and depth of control that our customers require. In that spirit, we have been busy over the past year delivering important updates to many of our platform services.

Yesterday, December 9, 2021, when a serious vulnerability in the popular Java-based logging package log4j was publicly disclosed, our security teams jumped into action to help respond to the first question and answer the second question. This post explores the second.

I wrote earlier about how to mitigate CVE-2021-44228 in Log4j, how the vulnerability came about and Cloudflare’s mitigations for our customers. As I write we are rolling out protection for our FREE customers as well because of the vulnerability’s severity.

Today we are announcing secure domain registrations bundled into enterprise contracts.

A zero-day exploit affecting the popular Apache Log4j utility (CVE-2021-44228) was made public on December 9, 2021, that results in remote code execution (RCE).

Today, we’re announcing the general availability of Argo for Packets, which provides IP layer network optimizations to supercharge your Cloudflare network services products.

Cloudflare One partners with Microsoft to optimize user connectivity to Microsoft 365

Today, we’re excited to announce new integrations with mobile device management vendors Microsoft, Ivanti, JumpCloud, Kandji, and Hexnode to make the deployment of Cloudflare WARP even easier.

Today we are excited to announce our zero trust agent now has feature parity across all major platforms.

The vulnerability disclosed yesterday in the Java-based logging package, log4j, allows attackers to execute code on a remote server. We’ve updated Cloudflare’s WAF to defend your infrastructure against this 0-day attack.

Cloudflare partners with leading cyber insurers and incident response providers to help customers reduce their insurance premiums and improve cyber risk.

We're launching Security Center, making attack surface management actionable and accessible, built on Cloudflare’s unique visibility into Internet activity and expertise on security best practices.

Cloudflare Enterprise customers using the Magic Transit and Spectrum services can now tune and tweak their L3/4 DDoS protection settings directly from the Cloudflare dashboard or via the Cloudflare API.

Gone are the days of the Secure Email Gateway (SEG) being an option. Cloud-native email protection with multiple deployment options are now changing the game. With winter in our minds, it’s time to start talking about “ICE.”

To improve security, we’re adding threat intel integration and geo-blocking. For visibility, we’re packet captures at the edge, a way to see packets arrive at the edge in near real-time.

We are excited to announce the acquisition of Zaraz by Cloudflare, and the launch of a beta version of the Zaraz product. You can use Zaraz (beta) to manage and load third-party tools on the cloud, and achieve significant speed, privacy and security improvements.

Today we're excited to announce that Cloudflare has acquired Zaraz. The Zaraz value proposition aligns with Cloudflare's mission. They aim to make the web more secure, more reliable, and faster. And they built their solution on Cloudflare Workers.

At Kudelski Security, we've been working on implementing our Zero Trust strategy for the last two years. In many aspects, it's been an incredible journey, and although we're not quite finished yet, we're excited by the progress made so far with Cloudflare.

Safely browse risky and sensitive websites on any device without installing any software

Last year, we launched a new feature which empowered users to begin building a private network on Cloudflare. Today, we’re excited to announce even more features which make your Zero Trust migration easier than ever.

To help identify and mitigate supply chain attacks in the context of web applications, today we are launching Page Shield in General Availability (GA).

Earlier this year, we announced the ability to build a private network on Cloudflare’s network with identity-driven access controls. We’re excited to share that you will soon be able to extend that control to sessions and login intervals as well.

Zaraz fundamentally changes how third-parties are loaded on the web. Learn how we built it from the ground up, and why we chose Cloudflare Worker to power it.

We're excited to announce that customers will soon be able to store their Cloudflare logs on Cloudflare R2 storage. Storing your logs on Cloudflare will give CIOs and Security Teams an opportunity to consolidate their infrastructure; creating simplicity, savings and additional security.

Cloudflare’s Data Localisation Suite now helps customers localise metadata about their HTTP traffic.

Protect your team from phishing attacks by controlling user input on suspicious and sensitive websites with Cloudflare Browser Isolation.

Today, we’re excited to announce new capabilities to help customers make the switch from hardware firewall appliances to a true cloud-native firewall built for next-generation networks.

Cloudflare One helps enterprises build modern enterprise networks, operate efficiently and securely, and throw out on-premise hardware.

By combining the power of eBPF and Nftables, Magic Firewall can mitigate sophisticated attacks on infrastructure by enforcing a positive security model.

Today, we're excited to announce support for IPsec as an on-ramp to Cloudflare One.

Today, a more modern approach is to use SD-WAN to configure your networks and connect them to Cloudflare’s network, leveraging that as the new corporate backbone. It's quick and easy!

Today we’re excited to announce a combination of two features, Zero Trust role-based access and selective logging. With these features, administrators will be able to protect not only their users but also the data their users generate.

This week, we’ll demonstrate how Cloudflare One, our Zero Trust Network-as-a-Service, is helping CIOs transform their corporate networks.

Cloudflare can now send proactive notifications about any application security event spike, so you are warned whenever an attack might be targeting your application.

Bots moved quickly this holiday season, launching over 1 trillion requests on Black Friday but quickly receding after the weekend.

November comes, the temperatures start to get colder for most of the planet's population (87% live in the Northern Hemisphere) and many are also starting to prepare for the festive season.

We love line and bar graphs, but some data is best represented with different visualizations. We’re introducing world maps and sankey visualizations as part of Radar Maps, which are being used today to show you the top layer 7 attacks in real time.

Throughout the pandemic we saw different trends caused by people being more at home than usual, but Internet patterns also change at specific times of the year (like when students go back to school or when it’s colder outside) or on some holidays like Thanksgiving.

Global in-person events are back. We present a few ideas from Web Summit 2021 about the future and where the Internet is going. Check the interviews we’ve done at the event (from the lack of Internet access to Web3).

Historically Cloudflare's core competency was operating an HTTP reverse proxy. We've spent significant effort optimizing traditional HTTP/1.1 and HTTP/2 servers running on top of TCP.

Announcing general availability of Argo for Spectrum, a way to turbo-charge any TCP based application.

People living in Burkina Faso are facing an Internet shutdown. Cloudflare Radar shows that after 22:00 UTC (the same local time) Internet traffic went down significantly, something that has happened in the context of social tensions in the country that started on November 14, 2021.

The Internet started to come back to Sudan (with limitations) this past Thursday, November 18. This happens after 25 days (three weeks and four days) of an almost complete shutdown that affected the whole country.

Several months ago, we shared extensive benchmarking results of edge networks around the world, and made a commitment that we would improve in 10% of networks where we were not #1. Here are our results today.