Subscribe to receive notifications of new posts:

Always-on detections: eliminating the WAF “log versus block” trade-off

2026-03-04

Cloudflare is introducing Attack Signature Detection and Full-Transaction Detection to provide continuous, high-fidelity security insights without the manual tuning of traditional WAFs. By correlating request payloads with server responses, we can now identify successful exploits and data exfiltration while minimizing false positives....

Continue reading »
Always-on detections: eliminating the WAF “log versus block” trade-off

Mind the gap: new tools for continuous enforcement from boot to login

2026-03-04

Security WeekCloudflare Zero TrustCloudflare OneCloudflare AccessAccessZero TrustWARP

Cloudflare’s mandatory authentication and independent MFA protect organizations by ensuring continuous enforcement, from the moment a machine boots until sensitive resources are accessed....

Defeating the deepfake: stopping laptop farms and insider threats

2026-03-04

SASECloudflare Zero TrustCloudflare OneAccessCloudflare AccessPartners

Cloudflare One is partnering with Nametag to combat laptop farms and AI-enhanced identity fraud by requiring identity verification during employee onboarding and via continuous authentication....

Moving from license plates to badges: the Gateway Authorization Proxy

2026-03-04

SASESecure Web GatewayCloudflare GatewayCloudflare Zero Trust

Cloudflare’s Gateway Authorization Proxy adds support for identity-aware policies for clientless devices, securing virtual desktops, and guest networks without a device client....

Stop reacting to breaches and start preventing them with User Risk Scoring

2026-03-04

Cloudflare Zero TrustCloudflare OneAccessCloudflare AccessCloudflare One User Risk Score

Cloudflare One now incorporates dynamic User Risk Scores into Access policies to enable automated, adaptive security responses. This update allows teams to move beyond binary "allow/deny" rules by evaluating continuous behavior signals from both internal and third-party sources....

Introducing the 2026 Cloudflare Threat Report

2026-03-03

Threat IntelligenceCloudforce OneThreats

There has been a fundamental shift toward industrialized cyber threats, highlighted by a record 31.4 Tbps DDoS attack and sophisticated session token theft. Our new report examines how nation-states and criminal actors have moved beyond traditional exploits to "living off the XaaS" within legitimate enterprise logic....

Evolving Cloudflare’s Threat Intelligence Platform: actionable, scalable, and ETL-less

2026-03-03

Threat IntelligenceThreatsThreat DataDigital Forensics

Stop managing ETL pipelines and start threat hunting. Introducing new visualization, automation, and enrichment tools in the Cloudflare Threat Intelligence Platform to turn massive telemetry into instant security posture. ...

How Cloudy translates complex security into human action

2026-03-03

Email SecuritySecurityCloudflare OneCASB

Cloudy is our LLM-powered explanation layer built directly into Cloudflare One. Its explanations, now part of Phishnet and API CASB, can improve user decisions and SOC efficiency....

From reactive to proactive: closing the phishing gap with LLMs

2026-03-03

Email SecuritySecurityCloudflare OneZero Trust

Email security is a constant arms race. Like WWII engineers reinforcing only the planes that returned, survivorship bias hides real gaps. But LLMs can help us find the invisible weaknesses....

See risk, fix risk: introducing Remediation in Cloudflare CASB

2026-03-03

CASBMicrosoft 365Google WorkspaceCloudflare OneSASESAAS Security

Cloudflare CASB Remediation lets security teams go beyond visibility to fix risky file sharing in Microsoft 365 and Google Workspace directly from Cloudflare One, all in just a few clicks....

Modernizing with agile SASE: a Cloudflare One blog takeover

2026-03-02

Cloudflare OneSASE

In 2026, agile SASE is the engine for modernization. Discover how Cloudflare One secures humans, devices, and AI agents on a single, programmable connectivity cloud....

Beyond the blank slate: how Cloudflare accelerates your Zero Trust journey

2026-03-02

Cloudflare OneAutomation

Project Helix simplifies and accelerates the onboarding process for Cloudflare One. By using automation and Terraform templates, this tool allows customers to quickly deploy a comprehensive, best-practice configuration in minutes....

The truly programmable SASE platform

2026-03-02

Cloudflare OneZero TrustSASEDeveloper PlatformCloudflare Workers

As the only SASE platform with a native developer stack, we’re giving you the tools to build custom, real-time security logic and integrations directly at the edge....

Toxic combinations: when small signals add up to a security incident

2026-02-27

Application Security

Minor misconfigurations or request anomalies often seem harmless in isolation. But when these small signals converge, they can trigger a security incident known as a toxic combination. Here’s how to spot the signs. ...

We deserve a better streams API for JavaScript

2026-02-27

StandardsJavaScriptTypeScriptOpen SourceCloudflare WorkersNode.jsPerformanceAPI

The Web streams API has become ubiquitous in JavaScript runtimes but was designed for a different era. Here's what a modern streaming API could (should?) look like....

The most-seen UI on the Internet? Redesigning Turnstile and Challenge Pages

2026-02-27

Security WeekTurnstileChallenge PageDesignProduct DesignUser ResearchBotsBot ManagementWAFEngineeringProduct NewsAccessibility

We serve 7.6 billion challenges daily. Here’s how we used research, AAA accessibility standards, and a unified architecture to redesign the Internet’s most-seen user interface....

Bringing more transparency to post-quantum usage, encrypted messaging, and routing security

2026-02-27

RadarSecurityPrivacyPost-QuantumRoutingResearch

Cloudflare Radar has added new tools for monitoring PQ adoption, KT logs for messaging, and ASPA routing records to track the Internet's migration toward more secure encryption and routing standards. ...

ASPA: making Internet routing more secure

2026-02-27

Security WeekBGPRPKIRoutingRouting SecurityRadar

ASPA is the cryptographic upgrade for BGP that helps prevent route leaks by verifying the path network traffic takes. New features in Cloudflare Radar make tracking its adoption easy....

How we rebuilt Next.js with AI in one week

2026-02-24

AICloudflare WorkersWorkers AIDevelopersDeveloper PlatformJavaScriptOpen SourcePerformance

One engineer used AI to rebuild Next.js on Vite in a week. vinext builds up to 4x faster, produces 57% smaller bundles, and deploys to Cloudflare Workers with a single command....

Cloudflare One is the first SASE offering modern post-quantum encryption across the full platform

2026-02-23

Post-QuantumZero TrustCryptographyCloudflare OneIPsec

We’ve upgraded Cloudflare One to support post-quantum encryption by implementing the latest IETF drafts for hybrid ML-KEM into our Cloudflare IPsec product. This extends post-quantum encryption across all major Cloudflare One on-ramps and off-ramps....