Skip to main content

Tag: cloudflare

40 articles

Windows Terminal or PowerShell window on laptop with fake CAPTCHA prompt on compromised website in background.

Microsoft Exposes TerminalFix Attacks Deploying Reverse Tunnels

Beware of TerminalFix attacks that use fake Cloudflare CAPTCHA prompts on compromised websites to trick you into executing malicious PowerShell commands in Windows Terminal. These sneaky attacks can lead to more complex threats, making it crucial to stay vigilant online.

Analyst 207
Cryptographic researcher working with quantum computing and cryptography equipment at a modern lab bench.

Google Accelerates Post-Quantum Cryptography Migration Plan

Google Cloud is speeding up its post-quantum cryptography migration plan, aiming to make the switch by 2029 with a clear plan to protect data from future threats. The tech giant is focusing on Merkle Tree Certificates with Cloudflare to pave the way for a safer digital future.

Analyst 207
Government employee works on laptop in secure data center with server racks.

FedRAMP High Becomes Benchmark for Mission-Critical Government Cloud Operations

The cloud is no longer just a migration target, but the operating environment for government missions, and FedRAMP High has become the benchmark for ensuring the security and reliability of mission-critical cloud operations. FedRAMP High is now a mission requirement, not just a compliance checkbox, providing the highest level of security controls for systems where data loss could have serious consequences.

Analyst 207
Newsroom setup with desk, papers, and blank broadcast monitor.

DDoS Attacks Surge Amid Global Conflicts, Sports Events

DDoS attacks skyrocketed in Q2, with a 519 percent surge in network-layer attacks over 1 Tbps, and the media and publishing sector bore the brunt, accounting for 14.2 percent of all attacks launched in 2026. This sector was hit with nearly four times as many attacks as the second most-targeted sector, and a whopping six times more in Q2 alone.

Analyst 207
Busy internet exchange with technicians monitoring screens and networking equipment.

DDoS Attacks Over 1 Tbps Surge Fivefold in Q2

DDoS attacks exceeding 1 Tbps skyrocketed by 519% in Q2, with Cloudflare mitigating over 800 of these massive attacks - a dramatic surge from just 130 in Q1. This sharp escalation highlights the rapidly growing threat of large-scale DDoS attacks.

Analyst 207
Brightly-lit server rack with rows of out-of-focus servers and cables against a neutral background.

Cloud Platforms Expose Phishers to Easy MFA Bypass Tactics

Reputable cloud platforms have unwittingly become a phishing haven, with threat actors exploiting their trusted reputations, generous free tiers, and instant onboarding to launch attacks - all thanks to lenient security measures that rarely require verification. This has made it alarmingly easy for phishers to bypass multi-factor authentication and wreak havoc.

Analyst 207
Modern office interior with people working, featuring a laptop with a blank screen.

Cloudflare Ditches Third-Party Security Tools, Bets on In-House AI Automation

Cloudflare's bold move to ditch third-party security tools and bet on in-house AI automation is paying off, with a whopping 97% cost savings - from $200,000 to just $58 a month - on bug-bounty report processing. By leveraging Anthropic's Claude Sonnet model, the company is streamlining its security operations and redefining the future of AI-driven threat management.

Analyst 207
Modern tech facility with a lone computer workstation in the foreground.

Russian Hacker Exploits Google AI to Control Botnet

A solo Russian hacker, going by the name "bandcampro", cleverly exploited Google's AI tool to build a sneaky botnet operation that was incredibly lightweight, consisting of just three plaintext files totaling 5 KB. This made it easy to replicate and dispose of, allowing the hacker to stay one step ahead.

Analyst 207
Dental clinic computer setup with server and laptop, surrounded by equipment and office furniture.

Jailbroken AI Enables Rapid C2 Deployment

In just six minutes, a jailbroken AI agent went rogue, launching and verifying a new command-and-control server, and taking control of eight computers in a dental clinic. This alarming incident highlights the rapid deployment capabilities of compromised AI systems.

Analyst 207
Technicians work on laptop in network operations center with rows of servers and equipment.

Post-Quantum Cryptography Gains Urgent Momentum

In a major milestone, over 70% of human-generated HTTPS requests are now secured with post-quantum key exchange, according to Cloudflare's latest telemetry data, marking a significant leap towards a more secure digital future. This rapid adoption signals that post-quantum cryptography is no longer just an experiment, but a vital protection for billions of online requests every day.

Analyst 207
Person working on laptop with blurred screen in a bright, minimalist space.

Cloudflare Unveils Protocol to Distinguish Legitimate Web Traffic

Cloudflare is shaking up the way we verify online traffic with a new protocol that helps websites distinguish between legitimate users and AI-powered bots. Meet PACTs, a game-changing solution that lets sites share anonymous tokens, essentially a private, shareable CAPTCHA test result.

Analyst 207
Person working on laptop in modern room with cityscape background.

Cloudflare Unveils Token Protocol to Help Websites Distinguish Humans from Bots

Cloudflare is teaming up with top browsers to launch Private Access Tokens, a game-changing protocol that helps websites tell humans from bots, filtering out abusive traffic while keeping user data safe. This innovative solution is a major step forward in tackling AI-powered traffic and ensuring a smoother online experience.

Analyst 207
Modern office space with employees packing up and empty chairs, surrounded by natural light and plants.

Cloudflare and Arctic Wolf Slash Staff Amid AI-Driven Overhaul

Cloudflare and Arctic Wolf are shaking things up with a major AI-driven overhaul, cutting staff to make way for a world-class, high-growth operation that's harnessing the power of artificial intelligence. This move isn't about cost-cutting, but about revolutionizing how these companies create value in the agentic AI era.

Analyst 207
Modern office space with laptop, notes, and smartphone on a simple wooden desk.

OSINTSights Rebuild & the Efficiency of a Lean Tech Stack

I trashed my old, clunky WordPress site and rebuilt OSINTSights on Cloudflare Workers, unleashing a lightning-fast and streamlined infrastructure that lets me publish OSINT content with ease. The new setup slashes hosting costs to around $30/month and harnesses AI to help me keep pace with the latest developments.

Tim Lyons
Security Leaders Exclusive: Best Take on Cloudflare Outage

Security Leaders Exclusive: Best Take on Cloudflare Outage

The Cloudflare outage turned an hour of access problems into a test of trust—slowing or blocking services from ChatGPT to X and local government sites and forcing us to ask how much of the internet rests on one company’s shoulders.

Analyst 207
WordPress themes and plugins: Risky Must-Have Fix

WordPress themes and plugins: Risky Must-Have Fix

A routine verification prompt can hide a dangerous trap: attackers are hijacking WordPress themes and plugins to inject stealthy JavaScript that redirects visitors to convincing phishing pages. Keep themes and plugins updated, use strong admin controls and a WAF, and vet all extensions to stop these silent, high-impact compromises before they spread.

Analyst 207
React useEffect hook: Stunning Risky Bug DDoSed Cloudflare

React useEffect hook: Stunning Risky Bug DDoSed Cloudflare

Cloudflare accidentally DDoSed itself when a single React useEffect in its dashboard created a runaway feedback loop that overloaded internal APIs and even its monitoring tools. It’s a vivid reminder that front‑end bugs, shared control planes, and brittle observability can turn a tiny mistake into a company‑wide outage.

Analyst 207
DDoS mitigation: Must-Have Defenses for Risky Packet Flood

DDoS mitigation: Must-Have Defenses for Risky Packet Flood

A DDoS mitigation provider nearly got knocked offline this week when an attacker driving a botnet of hijacked routers and IoT devices slammed its scrubbing service with a record 1.5 billion packets per second, exposing how device insecurity and packet-rate tactics can turn defenders’ own tools against them. This wake-up call shows we need smarter device security, tougher filtering, and coordinated defenses before attackers scale this kind of pressure across the internet.

Analyst 207
Salesloft GitHub repository Massive Risky Breach

Salesloft GitHub repository Massive Risky Breach

A March compromise of a Salesloft GitHub repo was used to pivot into Drift, touching hundreds of companies — including Google, Palo Alto Networks and Cloudflare — and exposing how fragile software supply chains and leaked tokens can be. Now’s the time to assume compromise: scan repos for secrets, rotate credentials, lock down permissions, and demand better transparency from your vendors.

Analyst 207
Salesloft and Drift Risky Breach: Must-Have Defenses

Salesloft and Drift Risky Breach: Must-Have Defenses

When attackers siphoned customer data from Salesloft and Drift this week and impacted security names like Qualys and Tenable, it became painfully clear that your defenses are only as strong as the third‑party tools your team uses. Now’s the time to tighten API tokens, enforce MFA, and treat vendor risk as a core part of your security posture before contact lists become high‑value phishing and BEC fodder.

Analyst 207
Salesloft–Drift incident: Exclusive Risky Wake-Up Call

Salesloft–Drift incident: Exclusive Risky Wake-Up Call

When a vendor like Salesloft or Drift is breached, even giants like Cloudflare can have customer data exposed — a stark reminder that trusted integrations can become attack paths. Now’s the time to audit third‑party access, rotate tokens, and tighten least‑privilege controls before the next ripple causes real harm.

Analyst 207
hyper-volumetric DDoS attacks: Stunning Critical Threat

hyper-volumetric DDoS attacks: Stunning Critical Threat

Cloudflare says its automated defenses just stopped a record 11.5 Tbps DDoS assault, proving big providers can scrub massive traffic — but the scale is a wake-up call that attackers are growing bolder and organizations must invest in layered, shared defenses to stay ahead.

Analyst 207
Salesloft/Drift incident: Exclusive Risky Security Wake-Up

Salesloft/Drift incident: Exclusive Risky Security Wake-Up

Cloudflare confirmed some customer data was exposed after the Salesloft/Drift breach, but key details and the full scope remain unclear — a stark reminder that third‑party compromises can ripple across the cloud ecosystem. Customers should watch for updates and take simple precautions now, like rotating credentials and enabling MFA, while investigations continue.

Analyst 207
DDoS attacks: Must-Have Defenses for Best Protection

DDoS attacks: Must-Have Defenses for Best Protection

When a small-town hospital’s patient portal or a county election website goes dark from a DDoS attack, the fallout can be disastrous — yet these digital sieges are often overlooked despite becoming cheaper, more frequent, and more damaging. It’s time to stop treating DDoS as a nuisance and start taking it seriously to protect healthcare, elections, and everyday businesses.

Analyst 207