
We are excited to introduce support for private hostname and IP address-defined applications as well as reusable access policies. These updates extend Access’s capabilities to better protect private resources and streamline policy management for administrators.

We are closing the cleartext HTTP ports entirely for Cloudflare API traffic. This prevents the risk of clients unintentionally leaking their secret API keys in cleartext during the initial request, before we can reject the connection at the server side.

We’re introducing a new Application Security experience in the Cloudflare dashboard, with a reworked UI organized by use cases, making it easier for customers to navigate and secure their accounts, APIs, and more.
MT
Michael Tremante, Pete Thomas·March 20, 2025Security 
The dream is incomplete until we share it with our fellow Americans.

From simplifying the workflow of a developer to having an impact on the global water crisis, technology and AI are reshaping the way charity: water works.
PY
Paull Young·March 20, 2025AI & ML 
Vercel partners with xAI to bring Grok models directly to your Vercel projects through the Vercel Marketplace—and soon v0—with no additional signup required. xAI adds a new free tier through Vercel to enable quick prototyping and experimentation.

With Cloudflare for AI, developers, security teams and content creators can leverage Cloudflare’s network and portfolio of tools to secure, observe and make AI applications resilient and safe to use.
MT
Michael Tremante·March 19, 2025Security 
It's becoming increasingly difficult to tell the difference between web content produced by humans and web content produced by AI. In this post, we're going to look at a promising new approach to making AI content distinguishable as such without impacting the performance of the model.
TB
Teresa Brooks Mejia, Christopher Patton·March 19, 2025Performance 
By building and integrating a new heuristics framework into the Cloudflare Ruleset Engine, we now have a more flexible system to write rules, deploy new releases rapidly, and give Bot Management customers the explainability and control they were asking for.
CL
Curtis Lowder, Brian Mitchell·March 19, 2025SRE & Ops 
Learn more about how Cloudflare developed an AI model to uncover malicious JavaScript intent using a Graph Neural Network, from pre-processing data to inferencing at scale.This AI model is part of our Page Shield offering, helping make web surfing safer.
JM
Juan Miguel Cejuela, Xmflsct·March 19, 2025AI & ML 
How Cloudflare uses generative AI to slow down, confuse, and waste the resources of AI Crawlers and other bots that don’t respect “no crawl” directives.
RH
Reid, Harsh Saxena·March 19, 2025AI & ML 
Firewall for AI discovers and protects your public LLM-powered applications, and is seamlessly integrated with Cloudflare WAF. Join the beta now and take control of your generative AI security.
RC
Radwa, Clement Bertier·March 19, 2025Security 
Ooo, look at that: Safari Technology Preview 215 adds support for scroll-driven animations, anchor positioning, and text-wrap: pretty. That's a good sign that

Today, we’re announcing new features in Figma Slides that unlock high-fidelity design and cross-functional collaboration.

Ever wondered how to create checklists in your GitHub repositories, Issues, and PRs? Make task lists more manageable in your GitHub repositories, issues, and pull requests.

A look into building IssueOps workflows on GitHub to do everything from CI/CD to handling approvals and more.

Gain real-time insights into the ever-evolving landscape of cyber threats with our new threat events platform. This tool empowers your cybersecurity defense with actionable intelligence, allowing you to stay ahead of attacks and protect your critical assets.

Cloudflare introduces a single platform for unified security posture management, helping protect SaaS and web applications deployed across various environments. With asset discovery and threat detection, security risks can be easily managed for predictive security.
XN
Xmflsct, Noelle·March 18, 2025Security 
For Security Week 2025, we are adding several new DDoS-focused graphs, new insights into leaked credential trends, and a new Bots page to Cloudflare Radar. We are also refactoring Radar’s Security & Attacks page, breaking it out into Application Layer and Network Layer sections.

Log Explorer provides the ability to store and query Cloudflare logs natively within the Cloudflare network. Today we are excited to announce support for Zero Trust datasets, and custom dashboards where customers can monitor critical metrics for suspicious or unusual activity.

Introducing new Turnstile Analytics: Gain insight into your visitor traffic, bot behavior patterns, traffic anomalies, and attack attributes. Stay equipped with visitor attributes and the outcome of Turnstile challenges against ever-evolving attacks.
SA
Sallylee, Ana Foppa·March 18, 2025Security 
PostgreSQL powers many applications. In this blog posting you can read more about how to debug database applications effectively.
HS
Hans-Jürgen Schönig·March 18, 2025Databases 
Linear’s CEO shares his approach to quality and craft—catch him at Config 2025 alongside a lineup of makers redefining tech’s future.

We’re thrilled to announce that organizations can now protect their sensitive corporate network traffic against quantum threats by tunneling it through Cloudflare’s Zero Trust platform. Let us worry about your corporate network’s upgrade to post-quantum cryptography so that you don’t have to.

Cloudflare is now using a wall of waves in our Lisbon, Portugal office to create entropy and strengthen Internet security, turning liquid chaos into secure, unpredictable encryption.
JT
Joao Tome, Caroline·March 17, 2025Security 
Nearly half of observed login attempts across websites protected by Cloudflare involved leaked credentials. The pervasive issue of password reuse is enabling automated bot attacks and account takeovers on a massive scale.

Enhanced security, simplified control! This Security Week, Cloudflare unveils automated botnet protection, flexible cipher suites, and an upgraded URL Scanner.

We’re excited to announce that Cloudflare for Campaigns now includes Email Security, adding an extra layer of protection to email systems that power political campaigns.

A year after signing CISA’s Secure by Design pledge, Cloudflare has made significant progress in boosting multi-factor authentication (MFA) adoption. With the recent addition of Apple and Google social logins, we’ve made secure access easier for our users.
KG
Kristina Galicova, Justin Hutchings·March 17, 2025Security 
Get the most out of Copilot with code completion, inline chat, slash commands, Copilot code review, and more.
KK
Kedasha Kerr·March 17, 2025AI & ML 
Some critics question the agnostic nature of Web Components, with some even arguing that they are not real components. Gabriel Shoyomboa explores this topic in-depth, comparing Web Components and framework components, highlighting their strengths and trade-offs, and evaluating their performance.

The layer of security around today’s Internet is essential to safeguarding everything. Over the next week, we will discuss the latest trends in cyber security, announce new products and partnerships, and showcase the latest in Cloudflare technology. Welcome to Security Week 2025!

Scott Jehl released a course called Web Components Demystified. This is my full set of notes from Scott's course. You'll still want to take the course on your own, and I encourage you to because Scott is an excellent teacher who makes all of this stuff extremely accessible, even to noobs like me.

The CSSWG has voted to add a size keyword that's shorthand for the width and height properties.

Figma’s Dylan Field and YC’s Garry Tan discuss exploring the idea maze, vibe coding, and preserving craft even when the models are “cooking.”

The open source Git project just released Git 2.49. Here is GitHub’s look at some of the most interesting features and changes introduced since last time.

"PostgreSQL scales" - what does it mean? Find out what 1 trillion rows in Citus is all about in this blog post.
HS
Hans-Jürgen Schönig·March 13, 2025Databases 
Strategies to quickly get up to speed, whether you’re a seasoned engineer or a newcomer to the field.
BE
Brittany Ellich·March 13, 2025Frontend 
Have you thought about the security risks WordPress websites face? Anders Johansson explores why they are frequent hacker targets and shares how WordPress SQL injection attacks work and how to remove and prevent them.

Vercel welcomes Jeanne DeWitt Grosser as Chief Operating Officer. Jeanne helped take Stripe from $100M to billions, pioneered usage-based go-to-market strategies, and scaled influential developer platforms. Now, she brings that momentum to Vercel.

Critical authentication bypass vulnerabilities (CVE-2025-25291 + CVE-2025-25292) were discovered in ruby-saml up to version 1.17.0. In this blog post, we’ll shed light on how these vulnerabilities that rely on a parser differential were uncovered.

In February, we experienced two incidents that resulted in degraded performance across GitHub services.

This article describes the little known parameter stats_fetch_consistency and its potential applications for statistics collection.

For 30 years, Java has been a cornerstone of enterprise software development. Here’s why—and how to learn Java.


UX initiatives are often seen as a disruption rather than a means to solving existing problems in an organization. In this post, we’ll explore how you can build trust for your UX work, gain support, and make a noticeable impact. Part of [Measure UX and Design Impact](https://measure-ux.com/) by yours truly.

This post examines which Generative AI services are more popular, new entrants into the space, how these services have grown in traffic, where that traffic originates, and the evolution of cyberattacks targeting these services.

The videos from Smashing Magazine's recent event on accessibility were just posted the other day. I was invited to host the panel discussion with the speakers, including a couple of personal heroes of mine, Stéphanie Walter and Sarah Fossheim. But I was just as stoked to meet Kardo Ayoub who shared his deeply personal story as a designer with a major visual impairment.

Treating exposures as full and complete can help you respond more effectively to focus on what truly matters: securing systems, protecting sensitive data, and maintaining the trust of stakeholders.

Chrome has delayed shipping @function to Chrome 139! A wise choice, if you ask me; functions will set a before and after in CSS.
JD
Juan Diego Rodríguez·March 9, 2025Frontend 
With Cloudflare Stream’s new Media Transformations, content owners can resize, crop, clip, and optimize short-form video, all without migrating storage.

In this second article of a two-part series, Temani Afif demonstrates an alternative approach to creating the star rating component from the first article using experimental scroll-driven animations rather than using the border-image property.


Many don’t know that “Slack” is in fact a backronym—it stands for “Searchable Log of all Communication and Knowledge”. And these days, it’s not just a searchable log: with Slack AI, Slack is now an intelligent log, leveraging the latest in generative AI to securely surface powerful, time-saving insights. We built Slack AI from the…

A few months ago I wrote about what it means to stay gold — to hold on to the best parts of ourselves, our communities, and the American Dream itself. But staying gold isn’t passive. It takes work. It takes action. It takes hard conversations that ask us to confront where we’ve been, where we are, and who we want to be. That’s why I’m incredibly honored to be joining Alexander Vindman in giving a

The very first public draft of the CSS Form Control Styling Module Level 1 specification has been published as of yesterday. Still a work-in-progress but what

We are delighted to announce that PGDay Austria will be returning to Vienna in 2025. Find all updates on the event here.

Three maintainers talk about how they fostered their open source communities.

Struggling with slow Largest Contentful Paint (LCP)? Newly introduced by Google, LCP subparts help you pinpoint where page load delays come from. Now, in the Chrome UX Report, this data provides real visitor insights to speed up your site and boost rankings. Matt Zeunert unpacks what LCP subparts are, what they mean for your website speed, and how you can measure them.

Learn to automate dependency management using GitHub Copilot, GitHub Actions, and Dependabot to eliminate manual checks, improve security, and save time for what really matters.
AG
Andrea Griffiths·March 5, 2025Security