Showing 25 of 25 items
No results in My stack.
Follow the thread: a new dashboard to investigate account abuse
Fraudsters are increasingly using AI to bypass stateless security checks. Cloudflare's new Account Abuse Protection dashboard uses stateful analysis and edge-generated Hashed User IDs to help teams investigate and block account abuse.
Protected Quick Tunnels: simple accountless authentication for your next dev project
Quick Tunnels now support email authentication. Add --allowed-mail to one cloudflared command, and only the addresses or domains you list can reach your local app. No Cloudflare account required on either side.
Enhancing Cloud Security and Networking: The Power of pfSense Plus Software
Cloud computing means different things to different people. You might have significant experience with cloud platforms, networking and computing, or you might be feeling like you should learn more about “the cloud.” At its essence, the cloud is simply someone else’s computer.
One year later: Sovereign AI and the fight for choice
AI sovereignty is not a zero-sum game, but many governments now believe it is. Cloudflare's answer: more local open-source models, model-agnostic security tools, and a commitment to giving nations genuine choice.
Docker Engine v29.8.2
29.8.2 For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones: docker/cli, 29.8.2 milestone moby/moby, 29.8.2 milestone Security This release fixes the following security vulnerabilities in Docker Engine: CVE-2026-53493 : Pulling a crafted OCI image…
Docker Engine v25.0.18
For a full list of pull requests and changes in this release, refer to the relevant GitHub milestone: moby/moby, 25.0.18 milestone Changes to the Engine API, see API version history . Bug fixes and enhancements Fix CVE-2026-17106 : crafted tar archive can write outside the extraction directory…
Using AI to chart a course for our post-quantum migration
We’re building CryptoLabe, an internal AI-powered tool that discovers cryptography across our codebase, surfaces dependencies, and helps us progress toward a full post-quantum migration by 2029. Here’s what we’ve learned so far.
Is your domain using post-quantum encryption? Now you can see for yourself
Cloudflare has added visibility into post-quantum (PQ) encryption in TLS 1.3 directly into HTTP Analytics, Log Explorer, and Logpush. Learn how to make sure your domain is protected with PQ encryption.
Introducing Threat Signals: agentic skills for open-source threat intelligence, free for every Cloudflare account
We are expanding access to Cloudforce One's Threat Events Platform to every Cloudflare account and introducing Threat Signals. Threat Signals automatically parses open-source threat reporting, extracts structured indicators, and connects threat context directly to your WAF rules.
Enforce positive security with Cloudflare Application Profiles
Cloudflare learns the structure of your HTTP requests and identifies deviations. You can add a positive security layer that helps reduce attack surface as AI makes it easier for attackers to generate and vary payloads.
Building a certificate authority for the whole Internet
Twelve years after launching Universal SSL, Cloudflare is applying to become a certificate authority. By combining an established root, an ACME-first approach, and Merkle Tree Certificates, we are building a post-quantum CA for the open web.
Building a post-quantum certificate authority with Merkle Tree Certificates
As post-quantum signatures threaten to inflate TLS handshakes and certificate transparency logs, Merkle Tree Certificates offer a path to compact, auditable authentication. Cloudflare’s new certificate authority will support MTC issuance at scale.
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwrites its SOUL.md…
runc v1.5.2 -- "Всё сбудется, стоит только расхотеть!"
This is the second patch release in the 1.5.z release series of runc, which primarily includes a workaround for a Linux kernel bug causing random runc crashes when using cgroup v2, and other fixes. Fixed runc exec -p with a process.json lacking env now sets HOME again (a regression in runc 1.3.0)…
Agents can now set up your website’s security with Turnstile Spin
Misconfiguring Turnstile by skipping backend validation leaves sites exposed to bots. Turnstile Spin fixes incomplete setups by using your preferred AI coding agent to wire up server-side verification.
How Cloudflare addressed a cross-tenant data exposure vulnerability in Containers
External security researchers at Accomplish identified a vulnerability in Cloudflare Containers that could expose residual disk data from previous workloads. We explain how the issue worked, how we investigated it, and the steps we took to remediate it.
Netgate and Open Source: Building a Better Network, Together
Open source has always been about more than free code. It's a global community of maintainers, contributors, testers, documentation writers, and users who have shown, over and over, that people working together in the open build better software than any one company can build alone. Netgate® has…
Docker Engine v29.8.1
29.8.1 For a full list of pull requests and changes in this release, refer to the relevant GitHub milestones: docker/cli, 29.8.1 milestone moby/moby, 29.8.1 milestone Bug fixes and enhancements containerd image store: Fix docker load leaving dangling images after loading an image that already…
Have it both ways: stay discoverable in search while disallowing AI training
Cloudflare is giving site owners a way to stay discoverable while disallowing AI training. New controls and an Accountable designation establish a shared model with Apple, Google, and Microsoft.
Give every teammate and agent the right level of access to your Workers
You can now scope access to individual Workers and assign narrower Developer Platform roles, so teammates, CI tokens, and agents get only the access they need to debug, deploy, or monitor safely.
nginx-1.30.5 stable and nginx-1.31.6 mainline versions have been released, with fixes for buffer overflow vulnerability when using ngx_http_v3_module (CVE-2026-90439).
2026-09-15 nginx-1.30.5 stable and nginx-1.31.6 mainline versions have been released, with fixes for buffer overflow vulnerability when using ngx_http_v3_module (CVE-2026-90439).
Netgate Releases Netgate Nexus Version 26.07_1
Netgate® Nexus enables Multi-Instance Management for pfSense® Plus, and enhances the security of the pfSense GUI. Designed to address the growing complexity of managing multiple pfSense Plus instances across distributed environments, Netgate Nexus empowers network operators to securely manage one…
1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it
1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44 algorithm. Here is how we manage 2,420-byte signatures and downgrade risks at scale.
Traefik v3.7.13
Important: Please read the migration guide . CVE fixed: Advisory GHSA-qqjf-53cj-pwvv Advisory GHSA-f52w-8j3h-j724 Advisory GHSA-v67p-phpq-fc8x Advisory GHSA-w4v4-9rw7-5326 Advisory GHSA-8fcf-v89g-xpg6 Bug fixes: [acme] Bump github.com/go-acme/lego/v5 to v5.4.1 ( #13759 @ldez ) [acme] Disable…
Traefik v2.11.57
Important: Please read the migration guide . CVE fixed: Advisory GHSA-qqjf-53cj-pwvv Advisory GHSA-f52w-8j3h-j724 Advisory GHSA-w4v4-9rw7-5326 Bug fixes: [acme] Disable recursive nss propagation by default for DNS challenge ( #13830 @rtribotte ) [http3] Dedicate a transport per HTTP/3 client…