Malicious “RedAlert - Rocket Alerts” Application Targets Israeli Phone Calls, SMS, and User Information
October 14, 2023 1:00AM
On October 13, 2023, Cloudflare’s Cloudforce One Threat Operations Team became aware of a malicious Google Android application impersonating the real-time rocket alert app, Red Alert, which provides real-time rocket alerts for Israeli citizens...
Continue reading »
HTTP/2 Rapid Reset: deconstructing the record-breaking attack
October 10, 2023 1:02PM
DDoS
Vulnerabilities
Trends
Attacks
Security
This post dives into the details of the HTTP/2 protocol, the feature that attackers exploited to generate the massive Rapid Reset attacks, and the mitigation strategies we took to ensure all our customers are protected...
HTTP/2 Zero-Day vulnerability results in record-breaking DDoS attacks
October 10, 2023 1:02PM
Security
Vulnerabilities
Attacks
DDoS
The “HTTP/2 Rapid Reset” attack exploits a weakness in the HTTP/2 protocol to generate enormous, hyper-volumetric DDoS attacks. Cloudflare has mitigated a barrage of these attacks in recent months, including an attack three times larger than any previous attack we’ve observed...
Uncovering the Hidden WebP vulnerability: a tale of a CVE with much bigger implications than it originally seemed
October 05, 2023 4:00PM
Vulnerabilities
Chrome
WebP
Security
Swift
Recently, Google announced a security issue in Google Chrome, titled "Heap buffer overflow in WebP in Google Chrome." Initially, it seemed like just another bug in the popular web browser. However, what we discovered was far more significant and had implications that extended well beyond Chrome...
Unmasking the top exploited vulnerabilities of 2022
August 04, 2023 7:29PM
WAF
Security
CISA
Vulnerabilities
The Cybersecurity and Infrastructure Security Agency (CISA) just released a report highlighting the most commonly exploited vulnerabilities of 2022....
July 25, 2023 1:47AM
How Cloudflare is staying ahead of the AMD vulnerability known as “Zenbleed”
The Google Information Security Team revealed a new flaw in AMD's Zen 2 processors in a blog post today. The 'Zenbleed' flaw affects the entire Zen 2 product stack, from AMD's EPYC data center processors to the Ryzen 3000 CPUs, and can be exploited to steal sensitive data processed in the CPU,...