Announcing WAF Attack Score Lite and Security Analytics for business customers
March 15, 2023 1:00PM
We are making the machine learning empowered WAF and Security analytics view available to our Business plan customers, to help detect and stop attacks before they are known...
Continue reading »
Cloudflare observations of Confluence zero day (CVE-2022-26134)
June 05, 2022 9:54PM
Vulnerabilities
WAF
Zero Day Threats
On 2022-06-02 at 20:00 UTC Atlassian released a Security Advisory relating to a remote code execution (RCE) vulnerability affecting Confluence Server and Confluence Data Center products. This post covers our current analysis of this vulnerability...
CVE-2022-1096: How Cloudflare Zero Trust provides protection from zero day browser vulnerabilities
March 29, 2022 4:51PM
Browser Isolation
Remote Browser Isolation
RBI
Zero Day Threats
Zero Trust
CVE-2022-1096 is yet another zero day vulnerability affecting web browsers. Cloudflare zero trust mitigates the risk of zero day attacks in the browser and has been patched...
Sanitizing Cloudflare Logs to protect customers from the Log4j vulnerability
December 14, 2021 10:23AM
Logs
Vulnerabilities
Zero Day Threats
Security
Log4J
Many Cloudflare customers consume their logs using software that uses Log4j, so we are mitigating any exploit attempts via Cloudflare Logs....
Secure how your servers connect to the Internet today
December 10, 2021 9:24PM
Cloudflare Zero Trust
Cloudflare One
Zero Trust
Cloudflare Gateway
Zero Day Threats
The vulnerability disclosed yesterday in the Java-based logging package, log4j, allows attackers to execute code on a remote server. We’ve updated Cloudflare’s WAF to defend your infrastructure against this 0-day attack....
December 10, 2021 6:36PM
Inside the Log4j2 vulnerability (CVE-2021-44228)
In this post we explain the history of this vulnerability, how it was introduced, how Cloudflare is protecting our clients. We will update later with actual attempted exploitation we are seeing blocked by our firewall service....