Cloudflare
Latest Cloudflare news, announcements & analysis
Infra
Cloudflare Fixed a Bug That Stalled New Connections
Cloudflare discovered a subtle bug in its open-source QUIC code that failed to handle heavy packet loss at the start of a connection. The fix improves network reliability for services using their modern protocol implementation.
Ashish Kale ·
Infra
Cloudflare Tool Migrates Security Setups in Hours
Cloudflare has released a new open-source tool to help companies move to its Zero Trust security platform. It includes automated logic to migrate from competitors like Zscaler and Palo Alto Networks, cutting migration times from months to hours.
Ashish Kale ·
Infra
Cloudflare Replaces API Tokens with Secure Logins
Cloudflare now lets all developers use OAuth for third-party app integrations. This offers a more secure alternative to traditional API tokens, giving users granular control over what data and actions an application can access.
Ashish Kale ·
Infra
Cloudflare and Browsers Are Killing the CAPTCHA
Cloudflare is working with all major web browsers, including Chrome and Firefox, to create a new protocol called PACT. It aims to prove you're human without needing to solve annoying CAPTCHAs, using an anonymous token.
Ashish Kale ·
AI
Cloudflare Built an AI Team to Find Code Flaws
Cloudflare has detailed its new system that uses multiple AI models working together to find security vulnerabilities. This multi-agent approach offers a powerful blueprint for companies looking to automate and improve their own code security.
Neeraj Dhiman ·
AI
Cloudflare Adds Support for Claude Agents
Cloudflare has integrated support for Claude Managed Agents, allowing developers to build, deploy, and manage AI agents directly on its global network. This enables connecting agents to private systems, choosing runtime environments, and using Cloudflare's tools for monitoring and management.
Neeraj Dhiman ·
Security
Critical HTTP/2 Flaw Affects Servers
A new remote denial-of-service vulnerability, named HTTP/2 Bomb, affects major web servers including NGINX, Apache, Microsoft IIS, Envoy, and Cloudflare. The flaw exists in the default HTTP/2 configuration of these servers, making them susceptible to attack without any special setup, according to researchers.
Neeraj Dhiman ·
Security
Ghost CMS Flaw Hijacks Websites
A critical vulnerability in the Ghost CMS is being actively exploited to hijack over 700 websites. Attackers inject a fake Cloudflare verification page, tricking visitors into running a malicious Windows command. This social engineering tactic, dubbed "ClickFix," ultimately installs malware onto the user's system.
Neeraj Dhiman ·
Infra
Cloudflare Now Automates Defenses Against Live Threats
Cloudflare has launched a new feature that automatically converts its real-time threat intelligence into active security rules. This helps teams proactively block emerging attacks without manual intervention, saving time and improving security posture.
Ashish Kale ·
Data
How Cloudflare Fixed a Critical Database Bottleneck
Cloudflare traced a major billing system slowdown to a bottleneck in its ClickHouse database. The team fixed it by changing a single lock type, offering a key performance lesson for anyone running large-scale data systems.
Taranpreet Singh ·
AI
Cloudflare Tests AI for Code Security
Cloudflare tested Anthropic's security-focused AI model, Mythos Preview, on its own infrastructure. As part of Project Glasswing, they used the model to scan over fifty internal code repositories to identify potential vulnerabilities and understand how attackers might leverage similar advanced AI tools in the future.
Neeraj Dhiman ·