Preview Mode
Documentation

Security Week 2024

During this year's Security Week, we'll make Zero Trust even more accessible and enterprise-ready, better protect brands from phishing and fraud, streamline security management, deliver dynamic machine learning protections and more.

Updates and Annoucements

Welcome to Security Week 2024

Cloudflare’s Chief Security Officer introduces 2024 Security Week by sharing insights into the past year of threats, security incidents and key priorities and concerns for global CISOs.

Read the blog
Changing the industry with CISA’s Secure by Design principles

Security considerations should be an integral part of software’s design, not an afterthought. Explore how Cloudflare adheres to CISA’s Secure by Design principles to shift the industry.

Read the blog
Cloudflare announces Firewall for AI

Cloudflare is one of the first providers to safeguard LLM models and users in the era of AI.

Read the blog
Cloudflare launches AI Assistant for Security Analytics

Introducing AI Assistant for Security Analytics. Now it is easier than ever to get powerful insights about your web security. Use the new integrated natural language query interface to explore Security Analytics.

Read the blog
Dispelling the Generative AI fear: how Cloudflare secures inboxes against AI-enhanced phishing

Generative AI is being used by malicious actors to make phishing attacks much more convincing. Learn how Cloudflare’s email security systems are able to see past the deception using advanced machine learning models.

Read the blog
Introducing behavior-based user risk scoring in Cloudflare One

Cloudflare One is introducing user risk scoring, a new set of capabilities to detect risk based on user behavior, so that you can improve security posture across your organization.

Read the blog
Navigating the maze of Magecart: a cautionary tale of a Magecart impacted website

E-commerce websites were targeted by a sophisticated Magecart attack, involving a hidden JavaScript code designed to secretly steal Personally Identifiable Information (PII) and credit card details from users. Disguised as a harmless script, it meticulously targeted specific input fields, using data encoding and local storage techniques to mask and ensure comprehensive data capture. This incident underscores the critical need for robust cybersecurity, highlighting the effectiveness of Cloudflare's multi-layered application defense, including its Web Application Firewall (WAF) and Page Shield, in protecting against such advanced threats and maintaining user trust.

Read the blog
The rise of Defensive AI: Cloudflare’s framework for defending against next-gen threats

From identifying phishing attempts to protect applications and APIs, Cloudflare uses AI to improve the effectiveness of its security solutions to fight against new and more sophisticated attacks.

Read the blog
Secure your unprotected assets with Security Center: quick view for CISOs

Today we are excited to introduce a new set of capabilities within the Security Center to directly address a common challenge: ensuring comprehensive deployment across your infrastructure. Gain precise insights into where and how to optimize your security posture.

Read the blog
Announcing two highly requested DLP enhancements: Optical Character Recognition (OCR) and Source Code Detections

Cloudflare One now supports Optical Character Recognition and detects source code as part of its Data Loss Prevention (DLP) service

Read the blog
Simpler migration from Netskope and Zscaler to Cloudflare: introducing Deskope and a Descaler partner update

Today, Cloudflare is excited to expand the Descaler program to Authorized Service Delivery Partners (ASDPs) who will now have exclusive access to the Descaler toolkit. Cloudflare is also launching Deskope, a new set of tooling to also help migrate existing Netskope customers to Cloudflare One.

Read the blog
Protecting APIs with JWT Validation

Cloudflare customers can now protect their APIs from broken authentication attacks by validating incoming JSON Web Tokens (JWTs) with API Gateway.

Read the blog
Securing Cloudflare with Cloudflare: a Zero Trust journey

A deep dive into how we have deployed Zero Trust at Cloudflare while maintaining user privacy.

Read the blog
The state of the post-quantum Internet

Today, nearly two percent of all TLS 1.3 connections established with Cloudflare are secured with post-quantum cryptography. What once was the topic of futuristic tech demos will soon be the new security baseline for the Internet. In this blog post we’ll take measure of where we are now in early 2024, what to expect for the coming years, and what you can do today.

Read the blog
Simplifying how enterprises connect to Cloudflare with Express Cloudflare Network Interconnect

Express Cloudflare Network Interconnect makes it fast and easy to connect your network to Cloudflare. Customers can now order Express CNIs directly from the Cloudflare dashboard, and they will be ready to use in 3 minutes. Express CNI also simplifies setting up Magic Transit and Magic WAN.

Read the blog
Linux kernel security tunables everyone should consider adopting

This post illustrates some of the Linux Kernel features, which are helping us to keep our production systems more secure. We will deep dive into how they work and why you may consider enabling them as well.

Read the blog
Eliminate VPN vulnerabilities with Cloudflare One

The Cybersecurity & Infrastructure Security Agency (CISA) recently issued an Emergency Directive due to the Ivanti Connect Secure and Policy Secure vulnerabilities. In this blog, we discuss the threat actor tactics exploiting these vulnerabilities, the risk inherent in legacy VPN appliance solutions, and how Cloudflare One can mitigate these risks.

Read the blog
Magic Cloud Networking simplifies security, connectivity, and management of public clouds

Introducing Magic Cloud Networking, a new set of capabilities to visualize and automate cloud networks to give our customers secure, easy, and seamless connection to public cloud environments.

Read the blog
Zero Trust WARP: tunneling with a MASQUE

This blog discusses the introduction of MASQUE to Zero Trust WARP and how Cloudflare One customers will benefit from this modern protocol.

Read the blog
Cloudflare treats SASE anxiety for VeloCloud customers

The turbulence in the SASE market is driving many customers to seek help. We’re doing our part to help VeloCloud customers who are caught in the crosshairs of shifting strategies.

Read the blog
Cloudflare protects global democracy against threats from emerging technology during the 2024 voting season

In 2024, more than 80 national elections are slated to occur, directly impacting approximately 4.2 billion individuals. At Cloudflare, we’re ready to support a range of players in the election space by providing security, performance, and reliability tools to help facilitate the democratic process.

Read the blog
Collect all your cookies in one jar with Page Shield Cookie Monitor

Protecting online privacy starts with knowing what cookies are used by your websites. Page Shield extends transparent monitoring to HTTP cookies, empowering security and compliance teams with an easy overview without the need for an external scanner, nor changing existing web applications.

Read the blog
Free network flow monitoring for all enterprise customers

Today, we’re excited to announce that a free version of Cloudflare’s network flow monitoring product, Magic Network Monitoring, is now available to all Enterprise Customers.

Read the blog
Advanced DNS Protection: mitigating sophisticated DNS DDoS attacks

We're proud to introduce the Advanced DNS Protection system, a robust defense mechanism designed to protect against the most sophisticated DNS-based DDoS attacks.

Read the blog
Building secure websites: a guide to Cloudflare Pages and Turnstile Plugin

Learn how to use Cloudflare Pages and Turnstile to deploy your website quickly and easily while protecting it from bots, without compromising user experience. Follow our tutorial here for a seamless integration!

Read the blog
General availability for WAF Content Scanning for file malware protection

Announcing the General Availability of WAF Content Scanning, protecting your web applications and APIs from malware by scanning files in-transit.

Read the blog
Log Explorer: monitor security events without third-party storage

With the combined power of Security Analytics + Log Explorer, security teams can analyze, investigate, and monitor for security attacks natively within Cloudflare, reducing time to resolution and overall cost of ownership for customers by eliminating the need to forward logs to third-party SIEMs.

Read the blog
Network performance update: Security Week 2024

Cloudflare is the fastest provider in 44% of networks around the world for 95th percentile connection time. Let’s dig into the data and talk about how we do it.

Read the blog
Cloudflare’s URL Scanner, new features, and the story of how we built it

Discover the enhanced URL Scanner API: Now with direct access from the Security Center Investigate Portal, enjoy unlisted scans, multi-device screenshots, and seamless integration within the Cloudflare ecosystem. Perfect for developers and security professionals looking to elevate their website security assessments.

Read the blog
Protocol detection with Cloudflare Gateway

Cloudflare Gateway, our secure web gateway (SWG), now supports the detection, logging, and filtering of network protocols using packet payloads without the need for inspection. Protocol detection makes it easier to set precise policies without filtering specific ports and without the risk of over/under-blocking activity.

Read the blog
Introducing Requests for Information (RFIs) and Priority Intelligence Requirements (PIRs) for threat intelligence teams

Our Security Center now houses Requests for Information (RFIs) and Priority Intelligence Requirements (PIRs). These features are available via API as well and Cloudforce One customers can start leveraging them today for enhanced security analysis.

Read the blog
Launching email security insights on Cloudflare Radar

The new Email Security section on Cloudflare Radar provides insights into the latest trends around threats found in malicious email, sources of spam and malicious email, and the adoption of technologies designed to prevent abuse of email.

Read the blog
Harnessing chaos in Cloudflare offices

In the children’s book The Snail and Whale, after an unexpectedly far-flung adventure, the principal character returns to declarations of “How time’s flown” and “Haven’t you grown?” It has been about four years since we last wrote about LavaRand and during that time the story of how Cloudflare uses physical sources of entropy to add to the security of the Internet has continued to travel and be a source of interest to many.

Read the blog
Security Week 2024 wrap up
Security Week 2024 wrap up

In this post we review the blogs released during Security Week 2024.

Read the blog