MORE POSTS
October 25, 2021 12:59 PM
Cloudflare Tunnel for Content Teams
See how we’re using Cloudflare Tunnel to share our technical writing with internal stakeholders for a faster, seamless feedback process....
October 22, 2021 3:31 PM
Cloudflare for SaaS for All, now Generally Available!
We are very excited to announce that Cloudflare for SaaS is generally available, so that every customer, big and small, can use Cloudflare for SaaS to continue scaling and building their SaaS business. ...
October 20, 2021 1:00 PM
Getting Cloudflare Tunnels to connect to the Cloudflare Network with QUIC
It is now possible to connect a Cloudflare Tunnel to the Cloudflare network with QUIC. While doing this, we ran into an interesting connectivity problem unique to UDP. ...
October 20, 2021 1:00 AM
Zero Trust — Not a Buzzword
Over the last few years, Zero Trust, a term coined by Forrester, picked up a lot of steam. Zero Trust, in its core, is a network architecture and security framework focusing on not having a distinction between external and internal access environments, and never trusting users/ro...
October 14, 2021 12:59 PM
Privacy-Preserving Compromised Credential Checking
Announcing a public demo and open-sourced implementation of a privacy-preserving compromised credential checking service...
October 14, 2021 12:59 PM
Research Directions in Password Security
We've been studying password problems, including malicious logins using compromised credentials. Here's what we learned and here's where we think we can go from here with safer password systems....
October 12, 2021 1:01 PM
Introducing SSL/TLS Recommender
Introducing customized recommendations to improve the security of your website....
October 12, 2021 12:59 PM
Dynamic Process Isolation: Research by Cloudflare and TU Graz
Cloudflare worked with TU Graz to study the impact of Spectre on Cloudflare Workers and to develop new defenses against it. Today we're publishing a paper about our research....
October 12, 2021 12:59 PM
Handshake Encryption: Endgame (an ECH update)
In this post, we’ll dig into ECH details and describe what this protocol does to move the needle to help build a better Internet....
October 12, 2021 12:59 PM
Privacy Pass v3: the new privacy bits
A new version of Privacy Pass for reducing the number of CAPTCHAs....
October 08, 2021 10:29 AM
Helping Apache Servers stay safe from zero-day path traversal attacks (CVE-2021-41773)
On September 29th 2021, the Apache Security team was alerted of a path traversal vulnerability being actively exploited (zero-day) against Apache HTTP Server version 2.4.49. Customers running the affected Apache version, should update to 2.5.51 as soon as possible....
October 01, 2021 12:05 AM
May I ask who’s calling, please? A recent rise in VoIP DDoS attacks
Over the past month, multiple Voice over Internet Protocol (VoIP) providers have been targeted by Distributed Denial of Service (DDoS) attacks from entities claiming to be REvil. ...
September 14, 2021 12:58 PM
Data at Cloudflare just got a lot faster: Announcing Live-updating Analytics and Instant Logs
Today, we’re excited to introduce Live-updating Analytics and Instant Logs. For Pro, Business, and Enterprise customers, our analytics dashboards now update in real time. In addition to this, Enterprise customers can now view their HTTP request logs instantly in the Cloudflare da...
September 08, 2021 9:18 AM
How Cloudflare helped mitigate the Atlassian Confluence OGNL vulnerability before the PoC was released
On August 25, 2021, Atlassian released a security advisory affecting their Confluence application. The Cloudflare WAF soon after started mitigating an increase in malicious traffic to vulnerable endpoints ensuring customers remained protected....