MORE POSTS
September 15, 2023 1:00 PM
Making Content Security Policies (CSPs) easy with Page Shield
We just deployed a number of updates to our Client-Side Security Product: Page Shield. As of today we support all major CSP directives, better suggestions, better violation reporting, Page Shield specific user role permissions, and domain insights...
August 21, 2023 2:15 PM
Application Security Report: Q2 2023
We are back with a quarterly update of our Application Security report. Read on to learn about new attack trends and insights visible from Cloudflare’s global network...
August 21, 2023 1:00 PM
An August reading list about online security and 2023 attacks landscape
Here is a reading list with 2023 trends, what you need to know about attacks, and a guide on how to stay protected using Cloudflare...
August 09, 2023 1:00 PM
Introducing per hostname TLS settings — security fit to your needs
Starting today, customers that use Cloudflare’s Advanced Certificate Manager can configure TLS settings on individual hostnames within a domain...
August 04, 2023 6:29 PM
Unmasking the top exploited vulnerabilities of 2022
The Cybersecurity and Infrastructure Security Agency (CISA) just released a report highlighting the most commonly exploited vulnerabilities of 2022. ...
July 25, 2023 12:47 AM
How Cloudflare is staying ahead of the AMD vulnerability known as “Zenbleed”
The Google Information Security Team revealed a new flaw in AMD's Zen 2 processors in a blog post today. The 'Zenbleed' flaw affects the entire Zen 2 product stack, from AMD's EPYC data center processors to the Ryzen 3000 CPUs, and can be exploited to steal sensitive data process...
July 11, 2023 1:00 PM
Bring your own CA for client certificate validation with API Shield
API shield customers can now upload their own CA to use for client certificate validation. This ensures that only authorized clients and devices can make requests to your API endpoint or application. ...
June 08, 2023 2:00 PM
Cloudflare Area 1 earns SOC 2 report
Many customers want assurance that the sensitive information they send to us can be kept safe. One of the best ways to provide this assurance is a SOC 2 Type II report...
June 06, 2023 1:00 PM
Examining HTTP/3 usage one year on
With the HTTP/3 RFC celebrating its 1st birthday, we examined HTTP version usage trends between May 2022 - May 2023. We found that HTTP/3 usage by browsers continued to grow, but that search engine and social media bots continued to effectively ignore the latest version of the we...
May 18, 2023 1:00 PM
Announcing Cloudflare Secrets Store
Introducing Secrets Store by Cloudflare - the ultimate solution for managing your application secrets securely. Safeguard sensitive information, track access, and maintain ease of use....
May 18, 2023 1:00 PM
How to secure Generative AI applications
Earn best practices for securing generative AI applications based on Cloudflare's experience protecting some of the largest AI applications in the world...
April 25, 2023 1:07 PM
SLP: a new DDoS amplification vector in the wild
Researchers have recently published the discovery of a new DDoS reflection/amplification attack vector leveraging the SLP protocol. Cloudflare expects the prevalence of SLP-based DDoS attacks to rise in the coming weeks...
April 21, 2023 1:00 PM
Why I joined Cloudflare as Chief Security Officer
As someone who is passionate about technology, security, and its potential to improve our lives, I knew that I wanted to work for a company that shared those values. ...
April 20, 2023 1:44 PM
Secure by default: recommendations from the CISA’s newest guide, and how Cloudflare follows these principles to keep you secure
In this post we’ll review some of the authors’ recommendations, discuss how Cloudflare applies these principles to the products that we build, and provide some suggestions on what other organizations can do to support similar initiatives internally...