
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
    <channel>
        <title><![CDATA[ The Cloudflare Blog ]]></title>
        <description><![CDATA[ Get the latest news on how products at Cloudflare are built, technologies used, and join the teams helping to build a better Internet. ]]></description>
        <link>https://blog.cloudflare.com</link>
        <atom:link href="https://blog.cloudflare.com/" rel="self" type="application/rss+xml"/>
        <language>en-us</language>
        <image>
            <url>https://blog.cloudflare.com/favicon.png</url>
            <title>The Cloudflare Blog</title>
            <link>https://blog.cloudflare.com</link>
        </image>
        <lastBuildDate>Wed, 08 Apr 2026 10:52:21 GMT</lastBuildDate>
        <item>
            <title><![CDATA[See risk, fix risk: introducing Remediation in Cloudflare CASB]]></title>
            <link>https://blog.cloudflare.com/remediation-in-cloudflare-casb/</link>
            <pubDate>Tue, 03 Mar 2026 06:00:00 GMT</pubDate>
            <description><![CDATA[ Cloudflare CASB Remediation lets security teams go beyond visibility to fix risky file sharing in Microsoft 365 and Google Workspace directly from Cloudflare One, all in just a few clicks. ]]></description>
            <content:encoded><![CDATA[ <p>Starting today, Cloudflare CASB customers can do more than see risky file-sharing across their SaaS apps: they can fix it, directly from the Cloudflare One dashboard.</p><p>This launch marks a huge advancement for Cloudflare’s <a href="https://www.cloudflare.com/zero-trust/products/casb/"><u>Cloud Access Security Broker</u></a> (CASB). Since its release, Cloudflare’s API-based CASB has focused on providing robust, comprehensive visibility and detection. It also connects to the SaaS tools your business runs on, surfacing misconfigurations, and flagging overshared data before it becomes tomorrow’s incident.</p><p>With today’s release of Remediation – a new way to fix problems with just a click, right from the CASB Findings page – CASB begins its next chapter, and moves from telling you what’s wrong to helping you make it right.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/3sl5Cse8hP3nZwE1deik09/1ee2d7d9f61eceb4a23868b9dab7bbbc/image4.png" />
          </figure><p><sub><i>An example of a Remediation Action (Remove Public File Sharing) in a CASB Finding.</i></sub></p>
    <div>
      <h2>CASB 101: A single place to see SaaS risk</h2>
      <a href="#casb-101-a-single-place-to-see-saas-risk">
        
      </a>
    </div>
    <p>Inside <a href="https://www.cloudflare.com/zero-trust/"><u>Cloudflare One</u></a>, our SASE platform, CASB connects to the SaaS and cloud tools your teams already use. By talking to providers over API, CASB gives security and IT teams:</p><ul><li><p>A consolidated view of misconfigurations, overshared files, and risky access patterns across apps like Microsoft 365, Google Workspace, Slack, Salesforce, Box, GitHub, Jira, and Confluence (<a href="https://developers.cloudflare.com/cloudflare-one/applications/scan-apps/casb-integrations/"><u>CASB Integrations</u></a>).</p></li><li><p>Continuous scanning for new issues as users collaborate, share, and adopt new tools.</p></li><li><p>Findings that are organized, searchable, and exportable for triage and reporting.</p></li></ul><p>But until now, the actual fixing usually happened somewhere else, whether it’s inside each app’s admin UI, or through a ticket to the team that owns that tool. Remediation closes that loop.</p>
    <div>
      <h2>Remediation: CASB’s next chapter</h2>
      <a href="#remediation-casbs-next-chapter">
        
      </a>
    </div>
    <p>The launch of CASB Remediation marks a major shift forward for the product and Cloudflare One, and we have a ton of big updates planned for the next year. </p><p>With today’s release, we focused on fixing file-share issues in <a href="https://developers.cloudflare.com/cloudflare-one/integrations/cloud-and-saas/microsoft-365/#file-sharing"><u>Microsoft 365</u></a> and <a href="https://developers.cloudflare.com/cloudflare-one/integrations/cloud-and-saas/google-workspace/#file-sharing"><u>Google Workspace</u></a>.</p><p>With Remediation, you can fix the highest-impact, most common file risks we see across customers, including:</p><ul><li><p>Public links that let anyone on the Internet view or edit a file.</p></li><li><p>Files shared company-wide across your tenant or domain, even when just a handful of people should have access.</p></li><li><p>Files shared outside your organization to personal accounts and external domains.</p></li><li><p>All of the above, when they also match a DLP Profile. For example, a document full of customer records, credentials, or financial details.</p></li></ul><p>When you trigger the ‘Remove sharing’ Remediation action on a supported finding, CASB immediately moves to remove the risky sharing configuration (for example, the public link or organization-wide access) from the file in question. And crucially, Remediation only removes risky sharing; it doesn’t delete files or change who owns them.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/3Te9jeJnI3TRXdxbyT19cf/9f429b27cfd5a6e9fe39b69656cc723c/image3.png" />
          </figure><p><sub><i>A new page to track the progress and success of Remediated CASB findings.</i></sub></p>
    <div>
      <h2>Two starting points: Microsoft 365 and Google Workspace</h2>
      <a href="#two-starting-points-microsoft-365-and-google-workspace">
        
      </a>
    </div>
    <p>We chose to start with Microsoft 365 and Google Workspace because, for many organizations, that’s where the bulk of their business-critical documents live: internal financials, product roadmaps, customer contracts, HR notes, and more.</p><p>They’re also where “temporary” sharing tends to linger too long:</p><ul><li><p>A spreadsheet shared “Anyone with the link can edit” for a quick review.</p></li><li><p>A doc made company-wide for an all-hands, then quietly forgotten.</p></li><li><p>A sheet of customer records shared to a contractor’s personal email.</p></li></ul><p>For Microsoft 365, that means cleaning up risky shares in places like OneDrive and SharePoint. For Google Workspace, it means tightening sharing on Docs, Sheets, Slides, and other files stored in Drive.</p><p>Instead of exporting a CSV of risky files out of CASB, sending it to app owners, and hoping everyone gets around to fixing their share settings, <b>you can drive the clean-up directly from CASB and know when those risks have actually been addressed</b>.</p><p>And when you and your team use <a href="https://developers.cloudflare.com/cloudflare-one/cloud-and-saas-findings/manage-findings/#remediate-findings"><u>CASB Remediation</u></a>, every action is logged in Cloudflare One’s <a href="https://developers.cloudflare.com/cloudflare-one/insights/logs/"><u>Admin logs</u></a>, so you can see who took action on which files and when, or export that activity to your security information and event management tool (SIEM).</p>
    <div>
      <h2>How it works</h2>
      <a href="#how-it-works">
        
      </a>
    </div>
    <p>When architecting the system that supports CASB Remediations, we knew it had to do three things really well:</p><ul><li><p>Be fast, even at scale</p></li><li><p>Durable execution to handle surprises gracefully</p></li><li><p>Be easy for our customers to use </p></li></ul><p>To meet these goals, we built a system using several Cloudflare products: <a href="https://workers.cloudflare.com/"><u>Workers</u></a>, <a href="https://workers.cloudflare.com/product/workflows/"><u>Workflows</u></a>, <a href="https://workers.cloudflare.com/product/queues/"><u>Queues</u></a>, <a href="https://workers.cloudflare.com/product/kv/"><u>Workers KV</u></a>, <a href="https://developers.cloudflare.com/secrets-store/"><u>Secrets Store</u></a>, and <a href="https://workers.cloudflare.com/product/hyperdrive/"><u>Hyperdrive</u></a>. </p><p>When a remediation job is initiated, an API call is made to a Worker. That Worker writes the job to a Queue which is consumed by a second Worker to kick off a Workflow. Workers KV and Secrets Store are used to securely distribute credentials for use in the Workflow. The Workflow runs a series of steps to collect information and execute third-party API calls to complete the remediation. The final outcome of the action is recorded in a database via Hyperdrive. </p><p>At scale, we are guaranteed to encounter 429s from vendor APIs. Workflows’ native retries simplify handling this, and built-in step logging gives visibility into each retry. This means that there was no need for us to build a complex, single-purpose, state-tracking system or dozens of serverless functions for each action.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6TMLm3Wqw5AQHPj6y26Ac4/9acc4fa8b1d1b8f378ab9a23f52e1bdd/image1.png" />
          </figure><p>Performance results from load testing and early access customers have shown strong performance even under heavy load. The average (p50) end-to-end job completion time is 48 seconds, and the p90 is 72 seconds. Durable Execution (via Workflows) has made job management completely hands-off for our team, even when the Workflow encounters issues with third-party APIs. The simplicity of the final system has made troubleshooting issues fast and straightforward.</p>
    <div>
      <h2>What’s next for CASB Remediation</h2>
      <a href="#whats-next-for-casb-remediation">
        
      </a>
    </div>
    <p>File-sharing Remediation for Microsoft 365 and Google Workspace is just the first step.</p><p>In the near term, we’re working on bringing our customers new Quarantine actions, which can move or isolate high-risk files to safer locations. We are also introducing Custom Webhook actions, hooks that let you trigger downstream workflows, like ticket creation, chat notifications, or your own automation.</p><p>And more broadly, we’re excited to explore ways to make CASB even more of an active control plane:</p><ul><li><p>Autoremediation policies for carefully scoped, policy-driven fixes where you’re comfortable letting CASB take action automatically.</p></li><li><p>Custom CASB findings so you can define the exact patterns, data types, or access conditions that matter most to your organization.</p></li><li><p>Bulk Remediation that allows you to remediate many similar findings in a single operation.</p></li><li><p>Extending Remediation to additional SaaS integrations beyond Microsoft 365 and Google Workspace, so the same experience applies to tools like Box, Dropbox, Salesforce, GitHub, Slack, Atlassian, and more over time.</p></li></ul>
    <div>
      <h2>How to get started</h2>
      <a href="#how-to-get-started">
        
      </a>
    </div>
    <p>CASB Remediation requires a paid CASB license, but don’t let that stop you from trying CASB out today!</p><ul><li><p><b>For existing Cloudflare One / CASB customers:</b> Integrate your Microsoft 365 or Google Workspace tenant (or update your existing integration to Read-Write), and start remediating risky shares directly from the side panel within your file sharing-related finding types.</p></li><li><p><b>New to Cloudflare One?</b> <a href="https://dash.cloudflare.com/sign-up/zero-trust"><u>Sign up now</u></a> for 50 free seats to begin using CASB immediately. For larger deployments, request a <a href="https://www.cloudflare.com/contact/sase/?utm_medium=referral&amp;utm_source=blog"><u>consultation with our experts</u></a>.</p></li></ul><p>From there, talk to our team about enabling CASB with Remediation for your Microsoft 365 and Google Workspace tenants so you can find and fix overshared files in one place.</p><p>We’re excited to see how you use Remediation to clean up long-lived file-sharing risks — and to help shape what CASB’s next generation of remediation capabilities looks like.</p> ]]></content:encoded>
            <category><![CDATA[CASB]]></category>
            <category><![CDATA[Microsoft 365]]></category>
            <category><![CDATA[Google Workspace]]></category>
            <category><![CDATA[Cloudflare One]]></category>
            <category><![CDATA[SASE]]></category>
            <category><![CDATA[SAAS Security]]></category>
            <guid isPermaLink="false">5qLzg7UQ9OtFryC8YVeSo5</guid>
            <dc:creator>Alex Dunbrack</dc:creator>
            <dc:creator>Michael Leslie </dc:creator>
        </item>
        <item>
            <title><![CDATA[Securing data in SaaS to SaaS applications]]></title>
            <link>https://blog.cloudflare.com/saas-to-saas-security/</link>
            <pubDate>Wed, 24 Sep 2025 13:00:00 GMT</pubDate>
            <description><![CDATA[ The recent Salesloft breach taught us one thing: companies do not have visibility over data in SaaS applications. Cloudflare is committing to providing additional security tools for SaaS applications ]]></description>
            <content:encoded><![CDATA[ <p>The recent <a href="https://blog.cloudflare.com/response-to-salesloft-drift-incident/"><u>Salesloft breach</u></a> taught us one thing: connections between <a href="https://www.cloudflare.com/learning/cloud/what-is-saas/"><u>SaaS applications</u></a> are hard to monitor and create blind spots for security teams with disastrous side effects. This will likely not be the last breach of this type. </p><p>To fix this, Cloudflare is working towards a set of solutions that consolidates all SaaS connections via a single proxy, for easier monitoring, detection and response. A SaaS to SaaS proxy for everyone.</p><p>As we build this, we need feedback from the community, both data owners and SaaS platform providers. If you are interested in gaining early access, <a href="http://www.cloudflare.com/lp/saas-to-saas-security"><u>please sign up here</u></a>.</p><p>SaaS platform providers, who often offer marketplaces for additional applications, store data on behalf of their customers and ultimately become the trusted guardians. As integrations with marketplace applications take place, that guardianship is put to the test. A key breach in any one of these integrations can lead to widespread data exfiltration and tampering. As more apps are added the attack surface grows larger. Security teams who work for the data owner have no ability, today, to detect and react to any potential breach.</p><p>In this post we explain the underlying technology required to make this work and help keep your data on the Internet safe.</p>
    <div>
      <h2>SaaS to SaaS integrations</h2>
      <a href="#saas-to-saas-integrations">
        
      </a>
    </div>
    <p>No one disputes the value provided by SaaS applications and their integrations. Major SaaS companies implement flourishing integration ecosystems, often presented as marketplaces. For many, it has become part of their value pitch. Salesforce provides an <a href="https://appexchange.salesforce.com/"><u>AppExchange</u></a>. Zendesk provides a <a href="https://www.zendesk.co.uk/marketplace/apps/"><u>marketplace</u></a>. ServiceNow provides an <a href="https://www.servicenow.com/uk/products/integration-hub.html"><u>Integration Hub</u></a>. And so forth.</p><p>These provide significant value to any organisation and complex workflows. Data analysis or other tasks that are not supported natively by the SaaS vendor are easily carried out via a few clicks.</p><p>On the other hand, SaaS applications present security teams with a growing list of unknowns. Who can access this data? What security processes are put in place? And more importantly: how do we detect data leak, compromise, or other malicious intent?</p><p>Following the <a href="https://blog.cloudflare.com/response-to-salesloft-drift-incident/"><u>Salesloft breach</u></a>, which compromised the data of hundreds of companies, including Cloudflare, the answers to these questions are top of mind.</p>
    <div>
      <h2>The power of the proxy: seamless observability</h2>
      <a href="#the-power-of-the-proxy-seamless-observability">
        
      </a>
    </div>
    <p>There are two approaches Cloudflare is actively prototyping to address the growing security challenges SaaS applications pose, namely visibility into SaaS to SaaS connections, including anomaly detection and key management in the event of a breach. Let’s go over each of these, both relying on proxying SaaS to SaaS traffic.</p>
    <div>
      <h3>1) Giving control back to the data owner</h3>
      <a href="#1-giving-control-back-to-the-data-owner">
        
      </a>
    </div>
    <p>Cloudflare runs one of the world’s largest reverse proxy networks. As we terminate L7 traffic, we are able to perform security-related functions including blocking malicious requests, detecting anomalies, detecting automated traffic and so forth. This is one of the main use cases customers approach us for.</p><p>Cloudflare can proxy any hostname under the customer’s control.</p><p>It is this specific ability, often referred to as “vanity”, “branded” or “custom” hostnames, that allows us to act as a front door to the SaaS vendor on behalf of a customer. Provided a marketplace app integrates via a custom domain, the data owner can choose to use Cloudflare’s new SaaS integration protection capabilities. </p><p>For a customer (Acme Corp in this example) to access, say SaaS Application, the URL needs to become saas.acme.com as that is under Acme’s control (and not acme.saas.com).</p><p>This setup allows Cloudflare to be placed in front of SaaS Corp as the customer controls the DNS hostname. By proxying traffic, Cloudflare can be the only integration entity with programmatic access to SaaS Corp's APIs and data and transparently "swap" authorisation tokens with valid ones and issue separate tokens, using key splitting, to any integrations.  </p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/1diK7GrWICfbRyHu2fpvFt/26eec0f692686d7d4f769abd7e2db661/image__4_.png" />
          </figure><p>Note that in many cases, authorization and authentication flows fall outside any vanity/branded hostname. It is in fact very common for an <a href="https://www.cloudflare.com/learning/access-management/what-is-oauth/"><u>OAuth</u></a> flow to still hit the SaaS provider url oauth.saas.com. It is therefore required, in this setup, for marketplace applications to provide the ability to support vanity/branded URLs for their OAuth and similar flows, oauth.saas.acme.com in the diagram above.</p><p>Ultimately Cloudflare provides a full L7 <a href="https://www.cloudflare.com/learning/cdn/glossary/reverse-proxy/"><u>reverse proxy</u></a> for all traffic inbound/outbound to the given SaaS provider solving for the core requirements that would lessen the impact of a similar breach to the Salesloft example. Had Salesloft integrated via a Cloudflare-proxied domain, then data owners would be able to:</p><ul><li><p><b>Gain visibility into who or what can access data</b>, and where it’s accessed from, in the SaaS platform. Cloudflare already provides analytics and filtering tools to identify traffic sources, including hosting locations, IPs, user agents and other tools.</p></li><li><p><b>Instantly shut off access to the SaaS provider</b> without the need to rotate credentials on the SaaS platform, as Cloudflare would be able to block access from the proxy.</p></li><li><p><b>Detects anomalies </b>in data access by observing baselines and traffic patterns. For example a change in data exfiltration traffic flows would trigger an alert.</p></li></ul>
    <div>
      <h3>2) Improve SaaS platform security</h3>
      <a href="#2-improve-saas-platform-security">
        
      </a>
    </div>
    <p>The approach listed above assumes the end user is the company whose data is at risk. However, SaaS platforms themselves are now paying a lot of attention to marketplace applications and access patterns. From a deployment perspective, it’s actually easier to provide additional visibility to a SaaS provider as it is a standard reverse proxy deployment and we have tools designed for SaaS applications, such as <a href="https://developers.cloudflare.com/cloudflare-for-platforms/cloudflare-for-saas/"><u>Cloudflare for SaaS</u></a>.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/3ElxtRBMqeI0GBD45BR4UC/13eee60d852991a3dfe5b2beb172584c/BLOG-2997_3.png" />
          </figure><p>This deployment model allows Cloudflare to proxy all traffic to the SaaS vendor, including to all API endpoints therefore gaining visibility into any SaaS to SaaS connections. As part of this, we are building improvements to our <a href="https://www.cloudflare.com/en-gb/application-services/products/api-shield/"><u>API Shield solution</u></a> to provide SaaS security teams with additional controls:</p><ul><li><p><b>Token / session logging:</b> Ability to keep track of OAuth tokens and provide session logs for audit purposes.</p></li><li><p><b>Session anomaly detection:</b> Ability to warn when a given OAuth (or other session) shows anomalous behavior.</p></li><li><p><b>Token / session replacement:</b> Ability to substitute SaaS-generated tokens with Cloudflare-generated tokens to allow for fast rotation and access lock down.</p></li></ul><p>The SaaS vendor may of course expose some of the affordances to their end customer as part of their dashboard.</p>
    <div>
      <h2>How key splitting enables secure token management</h2>
      <a href="#how-key-splitting-enables-secure-token-management">
        
      </a>
    </div>
    <p>Both deployment approaches described above rely on our ability to control access without storing complete credentials. While we already store SSL/TLS private keys for millions of web applications, storing complete SaaS bearer tokens would create an additional security burden. To solve this, and enable the token swapping and instant revocation capabilities mentioned above, we use key splitting.</p><p>Key splitting cryptographically divides bearer tokens into two mathematically interdependent fragments called Part A and Part B. Part A goes to the fourth-party integration (like Drift or Zapier) while Part B stays in Cloudflare's edge storage. Part A is just random noise that won't authenticate to Salesforce or any SaaS platform expecting complete tokens, so neither fragment is usable alone.</p><p>This creates an un-bypassable control point. Integrations cannot make API calls without going through Cloudflare's proxy because they only possess Part A. When an integration needs to access data, it must present Part A to our edge where we retrieve Part B, reconstruct the token in memory for microseconds, forward the authenticated request, and then immediately clear the token. This makes sure that the complete bearer token never exists in any database or log.</p><p>This forced cooperation means every API call flows through Cloudflare where we can monitor for anomalies, delete Part B to instantly revoke access (transforming incident response from hours to seconds), and maintain complete audit trails. Even more importantly, this approach minimizes our burden of storing sensitive credentials since a breach of our systems wouldn't yield usable tokens.</p><p>If attackers compromise the integration and steal Part A, or somehow breach Cloudflare's storage and obtain Part B, neither fragment can authenticate on its own. This fundamentally changes the security model from protecting complete tokens to managing split fragments that are individually worthless. It also gives security teams unprecedented visibility and control over how their data is accessed across third-party integrations.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/MmwLfTnQweqJiIFe4fTac/a9596a5a023ec147af4dc671ba3b5b8a/BLOG-2997_4.png" />
          </figure>
    <div>
      <h2>Regaining control of your data</h2>
      <a href="#regaining-control-of-your-data">
        
      </a>
    </div>
    <p>We are excited to develop solutions mentioned above to give better control and visibility around data stored in SaaS environments, or more generally, outside a customer’s network.</p><p>If you are a company worried about this risk, and would like to be notified to take part in our early access, please sign up <a href="http://www.cloudflare.com/lp/saas-to-saas-security"><u>here</u></a>.</p><p>If you are a SaaS vendor who would like to provide feedback and take part in developing better API security tooling for third party integrations towards your platform, <a href="http://www.cloudflare.com/lp/saas-to-saas-security"><u>sign up here</u></a>.</p><p>We are looking forward to helping you get better control of your data in SaaS to SaaS environments.</p> ]]></content:encoded>
            <category><![CDATA[Birthday Week]]></category>
            <category><![CDATA[Application Services]]></category>
            <category><![CDATA[Application Security]]></category>
            <category><![CDATA[SAAS Security]]></category>
            <category><![CDATA[SaaS]]></category>
            <guid isPermaLink="false">44zY8Y1rBmaNIVZVbUGJAL</guid>
            <dc:creator>Michael Tremante</dc:creator>
            <dc:creator>Bill Sobel</dc:creator>
            <dc:creator>Ed Conolly</dc:creator>
        </item>
        <item>
            <title><![CDATA[ChatGPT, Claude, & Gemini security scanning with Cloudflare CASB]]></title>
            <link>https://blog.cloudflare.com/casb-ai-integrations/</link>
            <pubDate>Tue, 26 Aug 2025 14:00:00 GMT</pubDate>
            <description><![CDATA[ Cloudflare CASB now scans ChatGPT, Claude, and Gemini for misconfigurations, sensitive data exposure, and compliance issues, helping organizations adopt AI with confidence.
 ]]></description>
            <content:encoded><![CDATA[ <p>Starting today, all users of <a href="https://www.cloudflare.com/zero-trust/"><u>Cloudflare One</u></a>, our <a href="https://www.cloudflare.com/learning/access-management/what-is-sase/"><u>secure access service edge (SASE)</u></a> platform, can use our API-based <a href="https://www.cloudflare.com/zero-trust/products/casb/"><u>Cloud Access Security Broker (CASB)</u></a> to assess the security posture of their generative AI (GenAI) tools: specifically, OpenAI’s <a href="https://chatgpt.com/"><u>ChatGPT</u></a>, <a href="https://www.anthropic.com/claude"><u>Claude</u></a> by Anthropic, and Google’s <a href="https://gemini.google.com/"><u>Gemini</u></a>. Organizations can connect their GenAI accounts and within minutes, start detecting misconfigurations, <a href="https://www.cloudflare.com/learning/access-management/what-is-dlp/"><u>Data Loss Prevention (DLP)</u></a> matches, data exposure and sharing, compliance risks, and more — all without having to install cumbersome software onto user devices.</p><p>As <a href="https://www.cloudflare.com/learning/ai/what-is-generative-ai/"><u>Generative AI</u></a> adoption has exploded in the enterprise, IT and Security teams need to hustle to keep themselves abreast of newly emerging <a href="https://www.cloudflare.com/the-net/generative-ai-zero-trust/"><u> security and compliance challenges</u></a> that come alongside these powerful tools. In this rapidly changing landscape, IT and Security teams need tools that help <a href="https://www.cloudflare.com/ai-security/">enable AI adoption while still protecting the security and privacy of their enterprise networks and data</a>. </p><p>Cloudflare’s API CASB and inline CASB work together to help organizations safely adopt AI tools. The API CASB integrations provide out-of-band visibility into data at rest and security posture inside popular AI tools like ChatGPT, Claude, and Gemini. At the same time, Cloudflare Gateway provides <a href="https://blog.cloudflare.com/ai-prompt-protection"><u>in-line prompt controls</u></a> and <a href="https://blog.cloudflare.com/shadow-AI-analytics"><u>Shadow AI</u></a> identification. It applies policies and DLP to traffic as it moves to these AI providers. Together, these features give organizations a unified control plane for <a href="https://blog.cloudflare.com/best-practices-sase-for-ai/">securing their use of GenAI</a>.</p>
    <div>
      <h3>What’s new</h3>
      <a href="#whats-new">
        
      </a>
    </div>
    <p>ChatGPT, Claude and Gemini are now all live in the integrations supported by <a href="https://developers.cloudflare.com/cloudflare-one/applications/scan-apps/casb-integrations/"><u>Cloudflare’s API CASB</u></a>. These integrations are available to all Cloudflare One users, account owners can easily connect their GenAI tenants, and CASB will scan for security issues across multiple domains:</p><ul><li><p><b>Agentless Connections:</b> Connect ChatGPT, Claude, and Gemini via agentless, API‑based integrations to scan posture and data risks; no endpoint software to install.</p></li><li><p><b>Posture Management:</b> Detect insecure settings and misconfigurations that can lead to data exposure or misuse.</p></li><li><p><b>DLP Detection:</b> Identify where <a href="https://developers.cloudflare.com/cloudflare-one/policies/data-loss-prevention/"><u>sensitive data</u></a> has been uploaded in chat attachments (prompts coming soon).</p></li><li><p><b>GenAI-specific Insights:</b> Surface risks associated with the unique capability of a given AI provider's toolsets.</p></li></ul><p>Admins can now answer questions like: What are our employees doing in ChatGPT? What data is being uploaded and used in Claude? Is Gemini configured correctly in Google Workspace?</p><p>Now let’s take a closer look at each integration.</p>
    <div>
      <h3>OpenAI ChatGPT</h3>
      <a href="#openai-chatgpt">
        
      </a>
    </div>
    
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6dO0h3q9modcmRPAQeiCOH/d8d54f5233e0026a63569b53cbb8d9a6/image2.png" />
          </figure><p>Cloudflare’s CASB integration with OpenAI’s ChatGPT scans for several types of insights, including:</p><ul><li><p><b>Capability Activation</b>: Highlights capabilities that are specific to ChatGPT’s feature set, like <a href="https://platform.openai.com/docs/actions/introduction"><u>actions</u></a>, <a href="https://platform.openai.com/docs/guides/tools-code-interpreter"><u>code execution</u></a>, <a href="https://help.openai.com/en/articles/9237897-chatgpt-search"><u>web access</u></a>.</p></li><li><p><b>External Exposure: </b>Finds chats and GPTs that are shared beyond the tenant, like GPTs shared publicly or listed on the <a href="https://openai.com/index/introducing-the-gpt-store/"><u>GPT Store</u></a>, and ties them back to their owners for quick triage.</p></li><li><p><b>Secrets, Keys and Invites</b>: Identifies API keys that aren’t rotated or are no longer used to maintain credential hygiene. Identifies over‑privileged or stale invites.</p></li><li><p><b>Sensitive Content (via DLP)</b>: Detects sensitive data (e.g. credential and secrets, financial / health information, source code, etc.) via <a href="https://developers.cloudflare.com/cloudflare-one/policies/data-loss-prevention/dlp-profiles/"><u>DLP profile</u></a> matches in uploaded chat attachments to enable targeted response.</p></li></ul>
    <div>
      <h3>Anthropic Claude</h3>
      <a href="#anthropic-claude">
        
      </a>
    </div>
    <p>For Claude, Cloudflare is able to provide the following out-of-band detections:</p><ul><li><p><b>Secrets, Keys and Invites:</b> Surfaces high‑risk invites and entitlement drift early so the least‑privilege access control stays tight. Spots unused API keys and rotation gaps before they turn into forgotten open doors.</p></li><li><p><b>Sensitive Content (via DLP)</b>: Monitors for <a href="https://developers.cloudflare.com/cloudflare-one/policies/data-loss-prevention/dlp-profiles/predefined-profiles/"><u>sensitive data</u></a> in uploaded files to help organizations safely enable Claude usage while maintaining compliance. Security teams get this information as quickly as CASB scans, giving them the visibility they need to help employees use Claude productively and securely with sensitive data.</p></li></ul><p>As Anthropic continues to expand Claude's API capabilities and features, Cloudflare will add corresponding security detections to match new functionality as it becomes available.</p>
    <div>
      <h3>Google Gemini</h3>
      <a href="#google-gemini">
        
      </a>
    </div>
    <p>Cloudflare’s detections for Google Gemini appear as part of our API CASB integration for Google Workspace:</p><ul><li><p><b>Identity &amp; MFA</b>: Identifies Gemini users and admins without MFA, leaving them prime targets for compromise. Imagine if an IT admin relied on Gemini daily to process corporate data, but their Google Workspace account lacked multi-factor authentication. One successful phishing email could give an attacker privileged access to Gemini and the wider Google Workspace environment — turning a minor oversight into an organization-wide breach. </p></li><li><p><b>License Hygiene</b>: Flags suspended accounts still holding Gemini or <a href="https://support.google.com/a/answer/16345165"><u>AI Ultra</u></a> licenses to cut cost and reduce exposure. An AI Ultra user has access to more powerful and riskier features, like <a href="https://deepmind.google/models/project-mariner/"><u>Project Mariner</u></a>, a research prototype that acts as an autonomous agent, capable of automating up to 10 tasks simultaneously across web browsers. An attacker can cause more damage by compromising an AI Ultra user, which is why we include this in our set of detections.</p></li></ul><p>The Gemini integration has a narrower scope because Google has structured their product and API differently than OpenAI or Anthropic. For organizations, Gemini is delivered as a <a href="https://workspace.google.com/"><u>Google Workspace</u></a> add-on. Enterprises enable Gemini features in Gmail, Docs, Sheets, and other Google Workspace apps through add-on licenses such as Gemini Enterprise or AI Ultra. Our CASB detections focus on identity, MFA, and license hygiene, rather than posture issues like public sharing or custom assistant publishing because Gemini does not yet provide those API endpoints.</p>
    <div>
      <h3>The Future of GenAI Posture Management</h3>
      <a href="#the-future-of-genai-posture-management">
        
      </a>
    </div>
    <p>Like countless other organizations, Cloudflare is adopting GenAI, on the same journey to make these environments even safer than they are today. We are excited to extend our management coverage to our customers so they can continue to innovate with GenAI. But looking ahead, we’re encouraged to see GenAI providers take concrete steps towards making security, compliance, and data privacy even more important tenets of their platforms.</p>
    <div>
      <h3>Secure GenAI beyond the reach of Inline Controls</h3>
      <a href="#secure-genai-beyond-the-reach-of-inline-controls">
        
      </a>
    </div>
    <p>Generative AI adoption brings new security requirements. Cloudflare CASB delivers out-of-band visibility across these tools, surfacing insights on top of inline controls. With posture, access, and data under control, organizations can embrace GenAI confidently and securely.</p><p><b>How to get started:</b></p><ul><li><p><b>For existing Cloudflare One customers:</b> Contact your account manager or enable the integrations directly in your dashboard today.</p></li><li><p><b>New to Cloudflare One?</b> <a href="https://dash.cloudflare.com/sign-up/zero-trust"><u>Sign up now</u></a> for 50 free seats to begin securely using Gen AI immediately. For larger deployments, request a <a href="https://www.cloudflare.com/products/zero-trust/plans/enterprise/?utm_medium=referral&amp;utm_source=blog&amp;utm_campaign=2025-q3-acq-gbl-connectivity-ge-ge-general-ai_week_blog"><u>consultation with our experts</u></a>.</p></li></ul><p>If you want to preview other new functionality and help shape our roadmap,<a href="https://www.cloudflare.com/lp/ai-security-user-research-program-2025"><u> express interest in our user research program</u></a> for <a href="https://www.cloudflare.com/learning/ai/what-is-ai-security/">AI security</a>. </p><div>
  
</div><p></p> ]]></content:encoded>
            <category><![CDATA[AI Week]]></category>
            <category><![CDATA[AI]]></category>
            <category><![CDATA[AI-SPM]]></category>
            <category><![CDATA[CASB]]></category>
            <category><![CDATA[Cloudflare One]]></category>
            <category><![CDATA[SASE]]></category>
            <category><![CDATA[SAAS Security]]></category>
            <guid isPermaLink="false">ZCOT8h5K8IwD7kDikj0G1</guid>
            <dc:creator>Alex Dunbrack</dc:creator>
        </item>
        <item>
            <title><![CDATA[Unmasking the Unseen: Your Guide to Taming Shadow AI with Cloudflare One]]></title>
            <link>https://blog.cloudflare.com/shadow-AI-analytics/</link>
            <pubDate>Mon, 25 Aug 2025 14:05:00 GMT</pubDate>
            <description><![CDATA[ Don't let "Shadow AI" silently leak your data to unsanctioned AI. This new threat requires a new defense. Learn how to gain visibility and control without sacrificing innovation. ]]></description>
            <content:encoded><![CDATA[ <p>The digital landscape of corporate environments has always been a battleground between efficiency and security. For years, this played out in the form of "<a href="https://www.cloudflare.com/learning/access-management/what-is-shadow-it/"><u>Shadow IT</u></a>" — employees using unsanctioned laptops or cloud services to get their jobs done faster. Security teams became masters at hunting these rogue systems, setting up firewalls and policies to bring order to the chaos.</p><p>But the new frontier is different, and arguably far more subtle and dangerous.</p><p>Imagine a team of engineers, deep into the development of a groundbreaking new product. They're on a tight deadline, and a junior engineer, trying to optimize his workflow, pastes a snippet of a proprietary algorithm into a popular public AI chatbot, asking it to refactor the code for better performance. The tool quickly returns the revised code, and the engineer, pleased with the result, checks it in. What they don't realize is that their query, and the snippet of code, is now part of the AI service’s training data, or perhaps logged and stored by the provider. Without anyone noticing, a critical piece of the company's intellectual property has just been sent outside the organization's control, a silent and unmonitored data leak.</p><p>This isn't a hypothetical scenario. It's the new reality. Employees, empowered by these incredibly powerful AI tools, are now using them for everything from summarizing confidential documents to generating marketing copy and, yes, even writing code. The data leaving the company in these interactions is often invisible to traditional security tools, which were never built to understand the nuances of a browser tab interacting with a large language model. This quiet, unmanaged usage is "Shadow AI," and it represents a new, high-stakes security blind spot.</p><p>To combat this, we need a new approach—one that provides visibility into this new class of applications and gives <a href=" https://blog.cloudflare.com/best-practices-sase-for-ai/">security teams the control they need</a>, without impeding the innovation that makes these tools so valuable.</p>
    <div>
      <h3><b>Shadow AI reporting</b></h3>
      <a href="#shadow-ai-reporting">
        
      </a>
    </div>
    <p>This is where the Cloudflare Shadow IT Report comes in. It’s not a list of threats to be blocked, but rather a visibility and analytics tool designed to help you understand the problem before it becomes a crisis. Instead of relying on guesswork or trying to manually hunt down every unsanctioned application, Cloudflare One customers can use the insights from their traffic to gain a clear, data-driven picture of their organization's application usage.</p><p>The report provides a detailed, categorized view of your application activity, and is easily narrowed down to AI activity. We’ve leveraged our network and threat intelligence capabilities to identify and classify AI services, identifying general-purpose models like ChatGPT, code-generation assistants like GitHub Copilot, and specialized tools used for marketing, data analysis, or other content creation, like Leonardo.ai. This granular view allows security teams to see not just <i>that</i> an employee is using an AI app, but <i>which</i> AI app, and what users are accessing it.</p>
    <div>
      <h3><b>How we built it</b></h3>
      <a href="#how-we-built-it">
        
      </a>
    </div>
    <p>Sharp eyed users may have noticed that we’ve had a <a href="https://www.cloudflare.com/learning/access-management/what-is-shadow-it/"><u>shadow IT</u></a> feature for a while — so what changed? While Cloudflare Gateway, our <a href="https://www.cloudflare.com/learning/access-management/what-is-a-secure-web-gateway/"><u>secure web gateway (SWG)</u></a>, has recorded some of this data for some time, users have wanted deeper insights and reporting into their organization's application usage. Cloudflare Gateway processes hundreds of millions of rows of app usage data for our biggest users daily, and that scale was causing issues with queries into larger time windows. Additionally, the original implementation lacked the filtering and customization capabilities to properly investigate the usage of AI applications. We knew this was information that our customers loved, but we weren’t doing a good enough job of showing it to them.</p><p>Solving this was a cross-team effort requiring a complete overhaul by our analytics and reporting engineers. You may have seen our work recently in <a href="https://blog.cloudflare.com/timescaledb-art/"><u>this July 2025 blog post </u></a>detailing how we adopted TimescaleDB to support our analytics platform, unlocking our analytics, allowing us to aggregate and compress long term data to drastically improve query performance. This solves the issue we originally faced around our scale, letting our biggest customers query their data for long time periods. Our crawler collects the original HTTP traffic data from Gateway, which we store into a Timescale database.</p><p>Once the data are in our database, we built specific, materialized views in our database around the Shadow IT and AI use case to support analytics for this feature. Whereas the existing HTTP analytics we built are centered around the HTTP requests on an account, these specific views are centered around the information relevant to applications, for example: Which of my users are going to unapproved applications? How much bandwidth are they consuming? Is there an end-user in an unexpected geographical location interacting with an unreviewed application? What devices are using the most bandwidth?</p><p>Over the past year, the team has defined a set framework for the analytics we surface. Our timeseries graphs and top-n graphs are all filterable by duration and the relevant data points shown, allowing users to drill down to specific data points and see the details of their corporate traffic. We overhauled Shadow IT by examining the data we had and researching how AI applications were presenting visibility challenges for customers. From there we leveraged our existing framework and built the Shadow IT dashboard. This delivered the application-level visibility that we know our customers needed.</p>
    <div>
      <h3><b>How to use it</b></h3>
      <a href="#how-to-use-it">
        
      </a>
    </div>
    
    <div>
      <h4><b>1. Proxy your traffic with Gateway</b></h4>
      <a href="#1-proxy-your-traffic-with-gateway">
        
      </a>
    </div>
    <p>The core of the system is <b>Cloudflare Gateway</b>, an in-line filter and proxy for all your organization's Internet traffic, regardless of where your users are. When an employee tries to access an AI application, their traffic flows through Cloudflare’s global network. Cloudflare can inspect the traffic, including the hostname, and map the traffic to our application definitions. <a href="https://developers.cloudflare.com/learning-paths/secure-internet-traffic/build-http-policies/tls-inspection/"><u>TLS inspection</u></a> is optional for Gateway customers, but it is required for ShadowIT analytics.</p><p>Interactions are logged and tied to user identity, device posture, bandwidth consumed and even the geographic location. This rich context is crucial for understanding who is using which AI tools, when, and from where.</p>
    <div>
      <h4><b>2. Review application use</b></h4>
      <a href="#2-review-application-use">
        
      </a>
    </div>
    <p>All this granular data is then presented in an our <b>Shadow IT Report</b> within your Cloudflare One dashboard. Simply filter for AI applications so you can:</p><ul><li><p><b>High-Level Overview:</b> Get an immediate sense of your organization's AI adoption. See the top AI applications in use, overall usage trends, and the volume of data being processed. This will help you identify and target your security and governance efforts.</p></li><li><p><b>Granular Drill-Downs:</b> Need more detail? Click on any AI application to see specific users or groups accessing it, their usage frequency, location, and the amount of data transferred. This detail helps you pinpoint teams using AI around the company, as well as how much data is flowing to those applications.</p></li></ul>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/13FSCu9Bn8ZZhybqyJdmt8/d9782da02555de7fca7010e0c5d83ed0/BLOG-2884_2.png" />
          </figure><p><sub><i>ShadowIT analytics dashboard</i></sub></p>
    <div>
      <h4><b>3. Mark application approval statuses</b></h4>
      <a href="#3-mark-application-approval-statuses">
        
      </a>
    </div>
    <p>We understand that not all AI tools are created equal, and your organization's comfort level will vary. The Shadow AI Report introduces a flexible framework for <b>Application Approval Status</b>, allowing you to formally categorize each detected AI application:</p><ul><li><p><b>Approved:</b> These are the AI applications that have passed your internal security vetting, comply with your policies, and are officially sanctioned for use. </p></li><li><p><b>Unapproved:</b> These are the red-light applications. Perhaps they have concerning data privacy policies, a history of vulnerabilities, or simply don’t align with your business objectives.</p></li><li><p><b>In Review:</b> For those gray-area applications, or newly discovered tools, this status lets your teams acknowledge their usage while conducting thorough due diligence. It buys you time to make an informed decision without immediate disruption.</p></li></ul>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/70NE2YxZSd3NQMSg63ltCc/981b6ae2241434120668431a13b1495b/BLOG-2884_3.png" />
          </figure><p><sup><i>Review and mark application statuses in the dashboard</i></sup></p>
    <div>
      <h4><b>4. Enforce policies</b></h4>
      <a href="#4-enforce-policies">
        
      </a>
    </div>
    <p>These approval statuses come alive when integrated with <b>Cloudflare Gateway policies</b>. This allows you to automatically enforce your AI decisions at the edge of Cloudflare’s network, ensuring consistent security for every employee, anywhere they work.</p><p>Here’s how you can translate your decisions into inline protection:</p><ul><li><p><b>Block unapproved AI:</b> The simplest and most direct action. Create a Gateway HTTP policy that blocks all traffic to any AI application marked as "Unapproved." This immediately shuts down risky data exfiltration.</p></li><li><p><b>Limit "In Review" exposure:</b> For applications still being assessed, you might not want a hard block, but rather a soft limit on potential risks:</p></li><li><p><b>Data Loss Prevention (DLP):</b> Cloudflare <a href="https://www.cloudflare.com/zero-trust/products/dlp/"><u>DLP</u></a> inspects and analyzes traffic for indicators of sensitive data (e.g., credit card numbers, PII, internal project names, source code) and can then block the transfer. By applying DLP to "In Review" AI applications, you can prevent AI prompts containing this proprietary data, as well as notify the user why the prompt was blocked. This could have saved our poor junior engineer from their well-intended mistake.. </p></li><li><p><b>Restrict Specific Actions:</b> Block only file uploads allowing basic interaction but preventing mass data egress. </p></li><li><p><b>Isolate Risky Sessions:</b> Route traffic for "In Review" applications through <b>Cloudflare's Browser Isolation</b>. <a href="https://www.cloudflare.com/zero-trust/products/browser-isolation/"><u>Browser Isolation</u></a> executes the browser session in a secure, remote container, isolating all data interactions from your corporate network. With it, you can control file uploads, clipboard actions, reduce keyboard inputs and more, reducing interaction with the application while you review it.</p></li><li><p><b>Audit "Approved" usage:</b> Even for AI tools you trust, you might want to log all interactions for compliance auditing or apply specific data handling rules to ensure ongoing adherence to internal policies.</p></li></ul><p>This workflow enables your team to consistently audit your organization’s AI usage and easily update policies to quickly and <a href="https://www.cloudflare.com/ai-security/">easily reduce security risk</a>.</p>
    <div>
      <h3><b>Forensics with Cloudflare Log Explorer</b></h3>
      <a href="#forensics-with-cloudflare-log-explorer">
        
      </a>
    </div>
    <p>While the Shadow AI Report provides excellent insights, security teams often need to perform deeper forensic investigations. For these advanced scenarios, we offer <a href="https://blog.cloudflare.com/logexplorer-ga/"><b><u>Cloudflare Log Explorer</u></b></a>.</p><p>Log Explorer allows you to store and query your Cloudflare logs directly within the Cloudflare dashboard or via API, eliminating the need to send massive log volumes to third-party <a href="https://www.cloudflare.com/learning/security/what-is-siem/"><u>SIEMs</u></a> for every investigation. It provides raw, unsampled log data with full context, enabling rapid and detailed analysis.</p><p>Log Explorer customers can dive into Shadow AI logs with pre-populated SQL queries from <a href="https://www.cloudflare.com/application-services/products/analytics/"><u>Cloudflare Analytics</u></a>, enabling deeper investigations into AI usage:</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/1gnzmDIkhlSxmV4sJwHSjh/403151b70be25e43886db973617a6a14/BLOG-2884_4.png" />
          </figure><p><sub><i>Log Search’s SQL query interface</i></sub></p><p><b>How to investigate Shadow AI with Log Explorer:</b></p><ul><li><p><b>Trace Specific User Activity:</b> If the Shadow AI Report flags a user with high activity on an "In Review" or "Unapproved" AI app, you can jump into Log Explorer and query by user, application category, or specific AI services. </p></li><li><p><b>Analyze Data Exfiltration Attempts:</b> If you have DLP policies configured, you can search for DLP matches in conjunction with AI application categories. This helps identify attempts to upload sensitive data to AI applications and pinpoint exactly what data was being transmitted.</p></li><li><p><b>Identify Anomalous AI Usage:</b> The Shadow AI Report might show a spike in usage for a particular AI application. In Log Explorer, you can filter by application status (In Review or Unapproved) for a specific time range. Then, look for unusual patterns, such as a high number of requests from a single source IP address, or unexpected geographic origins, which could indicate compromised accounts or policy evasion attempts.</p></li></ul><p>If <a href="https://www.cloudflare.com/ai-security/">AI visibility</a> is a challenge for your organization, the Shadow AI Report is available now for Cloudflare One customers, as part of our broader shadow IT discovery capabilities. Log in to <a href="https://dash.cloudflare.com/login"><u>your dashboard</u></a> to start regaining visibility and shaping your AI governance strategy today. </p><p>Ready to modernize how you secure access to AI apps? <a href="https://www.cloudflare.com/products/zero-trust/plans/enterprise/?utm_medium=referral&amp;utm_source=blog&amp;utm_campaign=2025-q3-acq-gbl-connectivity-ge-ge-general-ai_week_blog"><u>Reach out for a consultation</u></a> with our Cloudflare One security experts about how to regain visibility and control. </p><p>Or if you’re not ready to talk to someone yet,  nearly every feature in Cloudflare One is available at no cost for up to 50 users. Many of our largest enterprise customers start by exploring the products themselves on our free plan, and <a href="https://dash.cloudflare.com/sign-up/teams"><u>you can get started here</u></a>.</p><p>If you’ve got feedback or want to help shape how Cloudflare enhances visibility across shadow AI, <a href="https://www.cloudflare.com/lp/ai-security-user-research-program-2025"><u>please consider joining our user research program</u></a>. </p><div>
  
</div><p></p> ]]></content:encoded>
            <category><![CDATA[AI Week]]></category>
            <category><![CDATA[Security]]></category>
            <category><![CDATA[AI]]></category>
            <category><![CDATA[SASE]]></category>
            <category><![CDATA[Cloudflare One]]></category>
            <category><![CDATA[Secure Web Gateway]]></category>
            <category><![CDATA[SAAS Security]]></category>
            <category><![CDATA[Analytics]]></category>
            <guid isPermaLink="false">71P5BbZ24GopRdhNUMLD7P</guid>
            <dc:creator>Noelle Kagan</dc:creator>
            <dc:creator>Joey Steinberger</dc:creator>
        </item>
        <item>
            <title><![CDATA[Aligning our prices and packaging with the problems we help customers solve]]></title>
            <link>https://blog.cloudflare.com/aligning-our-prices-and-packaging-with-the-problems-we-help-customers-solve/</link>
            <pubDate>Mon, 11 Aug 2025 23:03:00 GMT</pubDate>
            <description><![CDATA[ You asked for simplicity. We listened. Introducing Externa and Interna, two new use-case-driven packages to simplify how you connect and protect your entire infrastructure. ]]></description>
            <content:encoded><![CDATA[ <p>At Cloudflare, we have a simple but audacious goal: to help build a better Internet. That mission has driven us to build one of the <a href="https://www.cloudflare.com/network/"><u>world’s largest networks</u></a>, to <a href="https://blog.cloudflare.com/content-independence-day-no-ai-crawl-without-compensation/"><u>stand up for content providers</u></a>, and to innovate relentlessly to make the Internet safer, faster, and more reliable for everyone, everywhere.</p><p>Building world-class products is only part of the battle, however. Fulfilling our mission means making these products accessible, including a pricing model that is fair, predictable, and aligned with the value we provide. If our packaging is confusing, or if our pricing penalizes you for using the service, then we’re not living up to our <a href="https://www.cloudflare.com/about-overview/"><u>mission</u></a>. And the best way to ensure that alignment?</p><p>Listen to our customers.</p><p>Over the years, your feedback has shaped our product roadmap, helping us evolve to offer <a href="https://developers.cloudflare.com/products/"><u>nearly 100 products</u></a> across four solution areas — <a href="https://www.cloudflare.com/application-services/#application-services-case-products"><u>Application Services</u></a>, <a href="https://www.cloudflare.com/network-services/#network-services-products"><u>Network Services</u></a>, <a href="https://www.cloudflare.com/zero-trust/#platform-capabilities"><u>Zero Trust Services</u></a>, and our <a href="https://www.cloudflare.com/plans/developer-platform/"><u>Developer Platform</u></a> — on a single, unified platform and network infrastructure. Recently, we’ve heard a new theme emerge: the need for simplicity. You’ve asked us, “A hundred products is a lot. Can you please be more prescriptive?” and “Can you make your pricing more straightforward?”</p><p>We heard that feedback loud and clear. That's why we are incredibly excited to introduce <b>Externa</b> and <b>Interna</b>,<b> </b>two new families of <a href="http://cloudflare.com/plans/enterprise"><u>use-case bundles</u></a> designed to simplify your journey with Cloudflare.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6YAEafOTtpzusmVvdqDVXY/876ca11211dadf6bbe6750719a3df476/image6.png" />
          </figure>
    <div>
      <h2>Two challenges, two solutions</h2>
      <a href="#two-challenges-two-solutions">
        
      </a>
    </div>
    <p>When we speak with CIOs, CTOs, and CISOs, their challenges almost always boil down to connecting and protecting two fundamental domains: (1) their external, public-facing infrastructure and (2) their internal, private systems.</p><p>Historically, the industry has sold dozens of point products to solve these problems with a series of band-aids. A WAF from one vendor, a DDoS scrubber from another, a VPN from a third. The result is a mess of complexity, vendor lock-in, and a security posture riddled with gaps. It’s expensive, inefficient, and insecure. </p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6QQlNLsDlXy6KDC1CtlIt7/4adb4bb9fd09e6cdd4501193dabdbff8/image1.png" />
          </figure><p>We think that’s backwards. There’s a simpler, more integrated approach with our new solution packages:</p><ul><li><p><a href="http://cloudflare.com/plans/enterprise/externa"><b><u>Externa</u></b></a> to connect and protect the part of your business facing the public Internet — the websites, APIs, applications, and networks that are the front doors and face of your business</p></li><li><p><a href="http://cloudflare.com/plans/enterprise/interna"><b><u>Interna</u></b></a> to connect and protect your internal private systems and resources — the employees, devices, data, and networks that are at the heart of your organization</p></li></ul><p>These packages represent our prescriptive view on what a modern connectivity and security architecture should look like. And, they’re best when used together.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6fBZrEDR6ZjbyXI7H4A6ca/dc516fb5df17b3dfffe50e91046c7b77/image2.png" />
          </figure>
    <div>
      <h3>Externa: Connect and protect external, public-facing systems </h3>
      <a href="#externa-connect-and-protect-external-public-facing-systems">
        
      </a>
    </div>
    <p>With Externa, we’re solving for the complexity of connecting and protecting your public-facing infrastructure. A key principle here is fairness. We’ve seen competitors send customers astronomical bills after a DDoS attack because they charge for all traffic — clean or malicious. It’s like a fire department charging you for the water they use to save your house. We don’t do that and never have, which is why with Externa, you only pay for legitimate traffic.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/3WMMfD7mIQQiuErqQYdbEl/d93735230352c83164155eeb25f2c358/image7.png" />
          </figure><p>We believe a simple, integrated model will reduce total cost of ownership and lead to a stronger security posture. A patchwork of band-aids is a lot of overhead to manage. Externa bundles our WAF, DDoS, API security, networking, application performance services, and more, into a simple package with units of measure that scale with value.</p><p>What does this mean for you?</p><ul><li><p><b>No attack traffic tax:</b> your costs remain predictable, even during a massive DDoS attack.</p></li><li><p><b>Simple, value-driven price units: </b>no origin fetch fees, duplicate charges per request, or paying per rule.</p></li><li><p><b>Simplified connectivity costs:</b> free private interconnects to on-ramp easily, wherever you’re hosted.</p></li></ul><p>And because security shouldn’t stop at your perimeter, every Externa package includes 50 seats of Interna, our SASE solution package.</p>
    <div>
      <h3>Interna: Connect and protect internal, private systems </h3>
      <a href="#interna-connect-and-protect-internal-private-systems">
        
      </a>
    </div>
    <p>With Interna, we’re fixing the broken economics of networking and security. The old models were built for a world where everyone came into an office. The world has changed: in today’s hybrid work environment, your internal network isn't just confined to your offices and data centers anymore. It's wherever your employees and data are. But many vendors still effectively charge you twice for the same user — once for the seat and again when they’re using the office network.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/4tj5DIu3g9Nt3Bofez1wrt/33e87281bc08e37aec8a7cd968bab7eb/image3.png" />
          </figure><p>We believe you should never pay for user bandwidth. Our model recognizes that a user is a user, wherever they are; we don’t double-charge for bandwidth; we actually subtract the traffic that’s generated from user device clients from your WAN meter. We’ve gone a step further: every Interna user license contributes to a shared bandwidth pool that you can use to build a modern, secure, and fast corporate WAN. With Interna, the budget you already have for security now builds your corporate network, too.</p><p>What does this mean for you?</p><ul><li><p><b>Never pay for user bandwidth:</b> a single per-seat price covers your users wherever they work, reducing your WAN bill and eliminating the hybrid work penalty.</p></li><li><p><b>Each license expands your WAN:</b> pooled bandwidth from user licenses helps you replace expensive, dedicated WAN contracts.</p></li><li><p><b>All-inclusive security: </b>premium features like Digital Experience Monitoring (DEM) and both in-line and API-based Cloud Access Security Broker (CASB) are included, not expensive add-ons.</p></li></ul>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/5WBGLrGyg3qtl7F3qCv02O/6175c2b9bb15676b42b50247675cb814/image5.png" />
          </figure>
    <div>
      <h2>The unifying Cloudflare advantage</h2>
      <a href="#the-unifying-cloudflare-advantage">
        
      </a>
    </div>
    <p>Our unique advantage has always been our network. Serving millions of customers — from individual developers on our <a href="https://www.cloudflare.com/plans/free/"><u>Free plan</u></a> to the world’s largest enterprises — on one platform and one global network gives us incredible leverage. It’s what allows us to offer robust <a href="https://blog.cloudflare.com/cloudflares-commitment-to-free/"><u>free services</u></a> and <a href="https://www.cloudflare.com/galileo/"><u>protect journalists and nonprofits</u></a>. It’s also what makes our platform structurally better: our AI models are trained on data from <a href="https://w3techs.com/technologies/history_overview/proxy/all/q"><u>20% of the web</u></a>, providing more effective threat detection than siloed platforms ever could.</p><p>We believe that the same structural advantage should help businesses of all sizes scale without compromise. As companies grow, they often face a difficult choice: does the patchwork of point products they started with become too complex to manage, or does the integrated platform they chose become too limited? You asked for a more prescriptive path, one that solves this false choice.</p><p>With our new Externa and Interna bundles, that trade-off is over. The Essentials, Advantage, and Premier tiers in each family are designed to provide a clear path for businesses of all sizes, allowing you to adopt stage-appropriate networking and security solutions that scale seamlessly. As your business grows, you move up the tiers from Essentials to Advantage to Premier, gaining access to more advanced features along the way. It’s growth, simplified.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/5XbdgSca7xaTYry7Px1BHp/016f33e4a7615be87f10564f7bb17007/image8.png" />
          </figure>
    <div>
      <h2>Ready for the next steps towards simplified security and connectivity?</h2>
      <a href="#ready-for-the-next-steps-towards-simplified-security-and-connectivity">
        
      </a>
    </div>
    <p>We’ve aimed to deliver pricing and packaging that is fair, accessible, predictable, and scales with value. This is what it means to align our pricing and packaging with our principles. It’s another step toward a better Internet. </p><p>Learn more about these <a href="http://cloudflare.com/plans/enterprise/externa"><u>packages</u></a> or <a href="https://www.cloudflare.com/plans/enterprise/contact/"><u>contact our sales team</u></a> today to learn how to transform your business.</p> ]]></content:encoded>
            <category><![CDATA[Product News]]></category>
            <category><![CDATA[SAAS Security]]></category>
            <category><![CDATA[SASE]]></category>
            <category><![CDATA[Security]]></category>
            <guid isPermaLink="false">6ViGc4xZSNpFpya8MRegxQ</guid>
            <dc:creator>Liam Reese</dc:creator>
            <dc:creator>Phil Winslow</dc:creator>
        </item>
        <item>
            <title><![CDATA[One platform to manage your company’s predictive security posture with Cloudflare]]></title>
            <link>https://blog.cloudflare.com/cloudflare-security-posture-management/</link>
            <pubDate>Tue, 18 Mar 2025 13:00:00 GMT</pubDate>
            <description><![CDATA[ Cloudflare introduces a single platform for unified security posture management, helping protect SaaS and web applications deployed across various environments.  ]]></description>
            <content:encoded><![CDATA[ <p>In today’s fast-paced digital landscape, companies are managing an increasingly complex mix of environments — from SaaS applications and public cloud platforms to on-prem data centers and hybrid setups. This diverse infrastructure offers flexibility and scalability, but also opens up new attack surfaces.</p><p>To support both business continuity and security needs, “security must evolve from being <a href="https://blog.cloudflare.com/welcome-to-security-week-2025/#how-can-we-help-make-the-internet-better"><u>reactive to predictive</u></a>”. Maintaining a healthy security posture entails monitoring and strengthening your security defenses to identify risks, ensure compliance, and protect against evolving threats. With our newest capabilities, you can now use Cloudflare to achieve a healthy posture across your SaaS and web applications. This addresses any security team’s ultimate (daily) question: <i>How well are our assets and documents protected</i>?</p><p>A predictive security posture relies on the following key components:</p><ul><li><p>Real-time discovery and inventory of all your assets and documents</p></li><li><p>Continuous asset-aware threat detection and risk assessment</p></li><li><p>Prioritised remediation suggestions to increase your protection</p></li></ul><p>Today, we are sharing how we have built these key components across SaaS and web applications, and how you can use them to manage your business’s security posture.</p>
    <div>
      <h3>Your security posture at a glance</h3>
      <a href="#your-security-posture-at-a-glance">
        
      </a>
    </div>
    <p>Regardless of the applications you have <a href="https://developers.cloudflare.com/reference-architecture/architectures/security/#using-cloudflare-to-protect-your-business"><u>connected to</u></a> Cloudflare’s global network, Cloudflare actively scans for risks and misconfigurations associated with each one of them on a <a href="https://developers.cloudflare.com/security-center/security-insights/how-it-works/#scan-frequency"><u>regular cadence</u></a>. Identified risks and misconfigurations are surfaced in the dashboard under <a href="https://dash.cloudflare.com/?to=/:account/security-center"><u>Security Center</u></a> as insights.</p><p>Insights are grouped by their severity, type of risks, and corresponding Cloudflare solution, providing various angles for you to zoom in to what you want to focus on. When applicable, a one-click resolution is provided for selected insight types, such as setting <a href="https://developers.cloudflare.com/ssl/edge-certificates/additional-options/minimum-tls/"><u>minimum TLS version</u></a> to 1.2 which is <a href="https://developers.cloudflare.com/ssl/reference/protocols/#decide-which-version-to-use"><u>recommended by PCI DSS</u></a>. This simplicity is highly appreciated by customers that are managing a growing set of assets being deployed across the organization.</p><p>To help shorten the time to resolution even further, we have recently added <a href="https://www.cloudflare.com/learning/access-management/role-based-access-control-rbac/"><u>role-based access control (RBAC)</u></a> to <a href="https://developers.cloudflare.com/security-center/security-insights/"><u>Security Insights</u></a> in the Cloudflare dashboard. Now for individual security practitioners, they have access to a distilled view of the insights that are relevant for their role. A user with an <a href="https://developers.cloudflare.com/fundamentals/setup/manage-members/roles/"><u>administrator role</u></a> (a CSO, for example) has access to, and visibility into, all insights.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/bnaU55Fi2z9bxUxl5pf7o/818043fbba2ae13c5a7c4cb25e5e7ebc/1.png" />
          </figure><p>In addition to account-wide Security Insights, we also provide posture overviews that are closer to the corresponding security configurations of your SaaS and web applications. Let’s dive into each of them.</p>
    <div>
      <h3>Securing your SaaS applications</h3>
      <a href="#securing-your-saas-applications">
        
      </a>
    </div>
    <p>Without centralized posture management, SaaS applications can feel like the security wild west. They contain a wealth of sensitive information – files, databases, workspaces, designs, invoices, or anything your company needs to operate, but control is limited to the vendor’s settings, leaving you with less visibility and fewer customization options. Moreover, team members are constantly creating, updating, and deleting content that can cause configuration drift and data exposure, such as sharing files publicly, adding PII to non-compliant databases, or giving access to third party integrations. With Cloudflare, you have visibility across your SaaS application fleet in one dashboard.</p>
    <div>
      <h4>Posture findings across your SaaS fleet</h4>
      <a href="#posture-findings-across-your-saas-fleet">
        
      </a>
    </div>
    <p>From the account-wide Security Insights, you can review insights for potential SaaS security issues:</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/7JRKfYveWKayrMxdLxLvDB/1c3383209462917214ad9dc6584e98fe/2.png" />
          </figure><p>You can choose to dig further with <a href="https://developers.cloudflare.com/cloudflare-one/applications/casb/"><u>Cloud Access Security Broker (CASB)</u></a> for a thorough review of the misconfigurations, risks, and failures to meet best practices across your SaaS fleet. You can identify a wealth of security information including, but not limited to:</p><ul><li><p>Publicly available or externally shared files</p></li><li><p>Third-party applications with read or edit access</p></li><li><p>Unknown or anonymous user access</p></li><li><p>Databases with exposed credentials</p></li><li><p>Users without two-factor authentication</p></li><li><p>Inactive user accounts</p></li></ul><p>You can also explore the <i>Posture Findings </i>page, which provides easy searching and navigation across documents that are stored within the SaaS applications.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/6skScbapgiG31w5qRoTCjG/ba3b069de8cce0c0bfcb9f011a2df954/3.png" />
          </figure><p>Additionally, you can create policies to prevent configuration drift in your environment. Prevention-based policies help maintain a secure configuration and compliance standards, while reducing alert fatigue for Security Operations teams, and these policies can prevent the inappropriate movement or exfiltration of sensitive data. Unifying controls and visibility across environments makes it easier to lock down regulated data classes, maintain detailed audit trails via logs, and improve your security posture to reduce the risk of breaches.</p>
    <div>
      <h4>How it works: new, real-time SaaS documents discovery</h4>
      <a href="#how-it-works-new-real-time-saas-documents-discovery">
        
      </a>
    </div>
    <p>Delivering SaaS security posture information to our customers requires collecting vast amounts of data from a wide range of platforms. In order to ensure that all the documents living in your SaaS apps (files, designs, etc.) are secure, we need to collect information about their configuration — are they publicly shared, do third-party apps have access, is <a href="https://www.cloudflare.com/learning/access-management/what-is-multi-factor-authentication/"><u>multi-factor authentication (MFA)</u></a> enabled? </p><p>We previously did this with crawlers, which would pull data from the SaaS APIs. However, we were plagued with rate limits from the SaaS vendors when working with larger datasets. This forced us to work in batches and ramp scanning up and down as the vendors permitted. This led to stale findings and would make remediation cumbersome and unclear – for example, Cloudflare would be reporting that a file is still shared publicly for a short period after the permissions were removed, leading to customer confusion.</p><p>To fix this, we upgraded our data collection pipeline to be dynamic and real-time, reacting to changes in your environment as they occur, whether it’s a new security finding, an updated asset, or a critical alert from a vendor. We started with our Microsoft asset discovery and <a href="https://developers.cloudflare.com/cloudflare-one/applications/casb/casb-integrations/microsoft-365/"><u>posture findings</u></a>, providing you real-time insight into your Microsoft Admin Center, OneDrive, Outlook, and SharePoint configurations. We will be rapidly expanding support to additional SaaS vendors going forward.</p>
    <div>
      <h5>Listening for update events from Cloudflare Workers</h5>
      <a href="#listening-for-update-events-from-cloudflare-workers">
        
      </a>
    </div>
    <p>Cloudflare Workers serve as the entry point for vendor webhooks, handling asset change notifications from external services. The workflow unfolds as follows:</p><ul><li><p><b>Webhook listener:</b> An initial Worker acts as the webhook listener, receiving asset change messages from vendors.</p></li><li><p><b>Data storage &amp; queuing:</b> Upon receiving a message, the Worker uploads the raw payload of the change notification to Cloudflare R2 for persistence, and publishes it to a Cloudflare Queue dedicated to raw asset changes.</p></li><li><p><b>Transformation Worker:</b> A second Worker, bound as a consumer to the raw asset change queue, processes the incoming messages. This Worker transforms the raw vendor-specific data into a generic format suitable for CASB. The transformed data is then:</p><ul><li><p>Stored in Cloudflare R2 for future reference.</p></li><li><p>Published on another Cloudflare Queue, designated for transformed messages.</p></li></ul></li></ul>
    <div>
      <h5>CASB Processing: Consumers &amp; Crawlers</h5>
      <a href="#casb-processing-consumers-crawlers">
        
      </a>
    </div>
    <p>Once the transformed messages reach the CASB layer, they undergo further processing:</p><ul><li><p><b>Polling consumer:</b> CASB has a consumer that polls the transformed message queue. Upon receiving a message, it determines the relevant handler required for processing.</p></li><li><p><b>Crawler execution:</b> The handler then maps the message to an appropriate crawler, which interacts with the vendor API to fetch the most up-to-date asset details.</p></li><li><p><b>Data storage:</b> The retrieved asset data is stored in the CASB database, ensuring it is accessible for security and compliance checks.</p></li></ul><p>With this improvement, we are now processing 10 to 20 Microsoft updates per second, or 864,000 to 1.72 million updates daily, giving customers incredibly fast visibility into their environment. Look out for expansion to other SaaS vendors in the coming months. </p>
    <div>
      <h3>Securing your web applications</h3>
      <a href="#securing-your-web-applications">
        
      </a>
    </div>
    <p>A unique challenge of securing web applications is that no one size fits all. An asset-aware posture management bridges the gap between a universal security solution and unique business needs, offering tailored recommendations for security teams to protect what matters.</p>
    <div>
      <h4>Posture overview from attacks to threats and risks</h4>
      <a href="#posture-overview-from-attacks-to-threats-and-risks">
        
      </a>
    </div>
    <p>Starting today, all Cloudflare customers have access to Security Overview, a new landing page customized for each of your onboarded domains. This page aggregates and prioritizes security suggestions across all your web applications:</p><ol><li><p>Any (ongoing) attacks detected that require immediate attention</p></li><li><p>Disposition (mitigated, served by Cloudflare, served by origin) of all proxied traffic over the last 7 days</p></li><li><p>Summary of currently active security modules that are detecting threats</p></li><li><p>Suggestions of how to improve your security posture with a step-by-step guide</p></li><li><p>And a glimpse of your most active and lately updated security rules</p></li></ol>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/3YhmhUZbZbAIZryUuTodpV/2b9563ac7768348bb4be46abc5fef7b3/4.png" />
          </figure><p>These tailored security suggestions are surfaced based on your traffic profile and business needs, which is made possible by discovering your proxied web assets.</p>
    <div>
      <h4>Discovery of web assets</h4>
      <a href="#discovery-of-web-assets">
        
      </a>
    </div>
    <p>Many web applications, regardless of their industry or use case, require similar functionality: user identification, accepting payment information, etc. By discovering the assets serving this functionality, we can build and run targeted threat detection to protect them in depth.</p><p>As an example, bot traffic towards marketing pages versus login pages have different business impacts. Content scraping may be happening targeting your marketing materials, which you may or may not want to allow, while credential stuffing on your login page deserves immediate attention.</p><p>Web assets are described by a list of endpoints; and labelling each of them defines their business goals. A simple example can be <code>POST</code> requests to path <code>/portal/login</code>, which likely describes an API for user authentication. While the <code>GET</code> requests to path <code>/portal/login</code> denote the actual login webpage.</p><p>To describe business goals of endpoints, labels come into play. <code>POST</code> requests to the <code>/portal/login</code> endpoint serving end users and to the<code> /api/admin/login</code> endpoint used by employees can both can be labelled using the same <code>cf-log-in</code> <a href="https://developers.cloudflare.com/api-shield/management-and-monitoring/endpoint-labels/#managed-labels"><u>managed label</u></a>, letting Cloudflare know that usernames and passwords would be expected to be sent to these endpoints.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/7jFh9mc7hyryXHIqeQwS9U/25ba022282b43cff9f09700d0ae81c76/5.png" />
          </figure><p>API Shield customers can already make use of <a href="https://developers.cloudflare.com/api-shield/management-and-monitoring/endpoint-labels/"><u>endpoint labelling</u></a>. In early Q2 2025, we are adding label discovery and suggestion capabilities, starting with three labels, <code>cf-log-in</code>, <code>cf-sign-up</code>, and <code>cf-rss-feed</code>. All other customers can manually add these labels to the <a href="https://developers.cloudflare.com/api-shield/management-and-monitoring/"><u>saved endpoints</u></a>. One example, explained below, is preventing disposable emails from being used during sign-ups. </p>
    <div>
      <h4>Always-on threat detection and risk assessment</h4>
      <a href="#always-on-threat-detection-and-risk-assessment">
        
      </a>
    </div>
    
    <div>
      <h5>Use-case driven threat detection</h5>
      <a href="#use-case-driven-threat-detection">
        
      </a>
    </div>
    <p>Customers told us that, with the growing excitement around generative AI, they need support to secure this new technology while not hindering innovation. Being able to discover LLM-powered services allows fine-tuning security controls that are relevant for this particular technology, such as inspecting prompts, limit prompting rates based on token usage, etc. In a separate Security Week blog post, we will share how we build Cloudflare Firewall for AI, and how you can easily protect your generative AI workloads.</p><p>Account fraud detection, which encompasses multiple attack vectors, is another key area that we are focusing on in 2025.</p><p>On many login and signup pages, a <a href="https://www.cloudflare.com/learning/bots/how-captchas-work/"><u>CAPTCHA</u></a> solution is commonly used to only allow human beings through, assuming only bots perform undesirable actions. Put aside that most visual CAPTCHA puzzles can be easily <a href="https://arstechnica.com/ai/2024/09/ai-defeats-traffic-image-captcha-in-another-triumph-of-machine-over-man/"><u>solved by AI</u></a> nowadays, such an approach cannot effectively solve the <i>root cause</i> of most account fraud vectors. For example, human beings using disposable emails to sign up single-use accounts to take advantage of signup promotions.</p><p>To solve this fraudulent sign up issue, a security rule currently under development could be deployed as below to block all attempts that use disposable emails as a user identifier, regardless of whether the requester was automated or not. All existing or future <code>cf-log-in</code> and <code>cf-sign-up</code> labelled endpoints are protected by this single rule, as they both require user identification.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/7sJzdnjp9UWrp35Hd3SsGB/db0959b457c555a4a1e93e5515a1e61f/6.png" />
          </figure><p>Our fast expanding use-case driven threat detections are all running by default, from the first moment you onboarded your traffic to Cloudflare. The instant available detection results can be reviewed through security analytics, helping you make swift informed decisions.</p>
    <div>
      <h5>API endpoint risk assessment</h5>
      <a href="#api-endpoint-risk-assessment">
        
      </a>
    </div>
    <p>APIs have their own set of risks and vulnerabilities, and today Cloudflare is delivering seven new risk scans through API Posture Management. This new capability of API Shield helps reduce risk by identifying security issues and fixing them early, before APIs are attacked. Because APIs are typically made up of many different backend services, security teams need to pinpoint which backend service is vulnerable so that development teams may remediate the identified issues.</p><p>Our new API posture management risk scans do exactly that: users can quickly identify which API endpoints are at risk to a number of vulnerabilities, including sensitive data exposure, authentication status, <a href="https://owasp.org/API-Security/editions/2023/en/0xa1-broken-object-level-authorization/"><u>Broken Object Level Authorization (BOLA)</u></a> attacks, and more.</p><p>Authentication Posture is one risk scan you’ll see in the new system. We focused on it to start with because sensitive data is at risk when API authentication is assumed to be enforced but is actually broken. <a href="https://developers.cloudflare.com/api-shield/security/authentication-posture/"><u>Authentication Posture</u></a> helps customers identify authentication misconfigurations for APIs and alerts of their presence. This is achieved by scanning for successful requests against the API and noting their authentication status. API Shield scans traffic daily and labels API endpoints that have missing and mixed authentication for further review.</p><p>For customers that have configured session IDs in API Shield, you can find the new risk scan labels and authentication details per endpoint in API Shield. Security teams can take this detail to their development teams to fix the broken authentication.</p>
          <figure>
          <img src="https://cf-assets.www.cloudflare.com/zkvhlag99gkb/21jVSrwsgfjKlyxyOZ5Qye/7963d95ea28a41f5e2b4f331ab5d5060/7.png" />
          </figure><p>We’re launching today with <a href="https://developers.cloudflare.com/api-shield/management-and-monitoring/endpoint-labels/"><u>scans</u></a> for authentication posture, sensitive data, underprotected APIs, BOLA attacks, and anomaly scanning for API performance across errors, latency, and response size.</p>
    <div>
      <h3>Simplify maintaining a good security posture with Cloudflare</h3>
      <a href="#simplify-maintaining-a-good-security-posture-with-cloudflare">
        
      </a>
    </div>
    <p>Achieving a good security posture in a fast-moving environment requires innovative solutions that can transform complexity into simplicity. Bringing together the ability to continuously assess threats and risks across both public and private IT environments through a single platform is our first step in supporting our customers’ efforts to maintain a healthy security posture.</p><p>To further enhance the relevance of security insights and suggestions provided and help you better prioritize your actions, we are looking into integrating Cloudflare’s global view of threat landscapes. With this, you gain additional perspectives, such as what the biggest threats to your industry are, and what attackers are targeting at the current moment. Stay tuned for more updates later this year.</p><p>If you haven’t done so yet, <a href="https://dash.cloudflare.com/?to=/:account/security-center"><u>onboard your SaaS and web applications</u></a> to Cloudflare today to gain instant insights into how to improve your business’s security posture.</p> ]]></content:encoded>
            <category><![CDATA[Security Week]]></category>
            <category><![CDATA[Security Posture Management]]></category>
            <category><![CDATA[Security]]></category>
            <category><![CDATA[Security Center]]></category>
            <category><![CDATA[SAAS Security]]></category>
            <category><![CDATA[Application Security]]></category>
            <category><![CDATA[API Security]]></category>
            <category><![CDATA[Email Security]]></category>
            <guid isPermaLink="false">41Rkgr3IVvWI5n1DpmMDkJ</guid>
            <dc:creator>Zhiyuan Zheng</dc:creator>
            <dc:creator>Noelle Kagan</dc:creator>
            <dc:creator>John Cosgrove</dc:creator>
            <dc:creator>Frank Meszaros</dc:creator>
            <dc:creator>Yugesha Sapte</dc:creator>
        </item>
    </channel>
</rss>