The Cloudflare Blog
https://blog.cloudflare.com
Get the latest news on how products at Cloudflare are built, technologies used, and join the teams helping to build a better Internet.
フィード

From legacy architecture to Cloudflare One
The Cloudflare Blog
Learn how Cloudflare and CDW de-risk SASE migrations with a blueprint that treats legacy debt as an application modernization project.
1日後

Announcing Cloudflare Account Abuse Protection: prevent fraudulent attacks from bots and humans
The Cloudflare Blog
Blocking bots isn’t enough anymore. Cloudflare’s new fraud prevention capabilities — now available in Early Access — help stop account abuse before it starts.
3日前

Slashing agent token costs by 98% with RFC 9457-compliant error responses
The Cloudflare Blog
Cloudflare now returns RFC 9457-compliant structured Markdown and JSON error payloads to AI agents, replacing heavyweight HTML pages with machine-readable instructions. This reduces token usage by over 98%, turning brittle parsing into efficient control flow.
3日前

AI Security for Apps is now generally available
The Cloudflare Blog
Cloudflare AI Security for Apps is now generally available, providing a security layer to discover and protect AI-powered applications, regardless of the model or hosting provider. We are also making AI discovery free for all plans, to help teams find and secure shadow AI deployments.
3日前

Investigating multi-vector attacks in Log Explorer
The Cloudflare Blog
Log Explorer customers can now identify and investigate multi-vector attacks. Log Explorer supports 14 additional Cloudflare datasets, enabling users to have a 360-degree view of their network.
4日前

Building a security overview dashboard for actionable insights
The Cloudflare Blog
Cloudflare's new Security Overview dashboard transforms overwhelming security data into prioritized, actionable insights, empowering defenders with contextual intelligence on vulnerabilities.
4日前

Translating risk insights into actionable protection: leveling up security posture with Cloudflare and Mastercard
The Cloudflare Blog
Cloudflare will be integrating Mastercard’s RiskRecon attack surface intelligence capabilities to help you eliminate Internet-facing blind spots while continuously monitoring and closing security gaps.
5日前

Fixing request smuggling vulnerabilities in Pingora OSS deployments
The Cloudflare Blog
Today we’re disclosing request smuggling vulnerabilities when our open source Pingora service is deployed as an ingress proxy and how we’ve fixed them in Pingora 0.8.0.
5日前

Active defense: introducing a stateful vulnerability scanner for APIs
The Cloudflare Blog
Cloudflare’s new Web and API Vulnerability Scanner helps teams proactively find logic flaws. By using AI to build API call graphs, we identify vulnerabilities that standard defensive tools miss.
5日前

Complexity is a choice. SASE migrations shouldn’t take years.
The Cloudflare Blog
Discover how Cloudflare partners TachTech and Adapture are shattering the 18-month migration myth, deploying agile SASE for global enterprises in weeks by treating security as software.
6日前

From the endpoint to the prompt: a unified data security vision in Cloudflare One
The Cloudflare Blog
Cloudflare One unifies data security from endpoint to prompt: RDP clipboard controls, operation-mapped logs, on-device DLP, and Microsoft 365 Copilot scanning via API CASB.
8日前

Ending the "silent drop": how Dynamic Path MTU Discovery makes the Cloudflare One Client more resilient
The Cloudflare Blog
The Cloudflare One Client now features the ability to actively probe and adjust packet sizes. This update eliminates the problems caused by tunnel layering and MTU differences, providing more stability and resiliency.
9日前

How Automatic Return Routing solves IP overlap
The Cloudflare Blog
Automatic Return Routing (ARR) solves the common enterprise challenge of overlapping private IP addresses by using stateful flow tracking instead of traditional routing tables. This userspace-driven approach ensures return traffic reaches the correct origin tunnel without manual NAT or VRF configuration.
10日前

A QUICker SASE client: re-building Proxy Mode
The Cloudflare Blog
By transitioning the Cloudflare One Client to use QUIC streams for Proxy Mode, we eliminated the overhead of user-space TCP stacks, resulting in a 2x increase in throughput and significant latency reduction for end users.
10日前

Always-on detections: eliminating the WAF “log versus block” trade-off
The Cloudflare Blog
Cloudflare is introducing Attack Signature Detection and Full-Transaction Detection to provide continuous, high-fidelity security insights without the manual tuning of traditional WAFs. By correlating request payloads with server responses, we can now identify successful exploits and data exfiltration while minimizing false positives.
10日前

Mind the gap: new tools for continuous enforcement from boot to login
The Cloudflare Blog
Cloudflare’s mandatory authentication and independent MFA protect organizations by ensuring continuous enforcement, from the moment a machine boots until sensitive resources are accessed.
10日前

Defeating the deepfake: stopping laptop farms and insider threats
The Cloudflare Blog
Cloudflare One is partnering with Nametag to combat laptop farms and AI-enhanced identity fraud by requiring identity verification during employee onboarding and via continuous authentication.
11日前

Moving from license plates to badges: the Gateway Authorization Proxy
The Cloudflare Blog
Cloudflare’s Gateway Authorization Proxy adds support for identity-aware policies for clientless devices, securing virtual desktops, and guest networks without a device client.
11日前

Stop reacting to breaches and start preventing them with User Risk Scoring
The Cloudflare Blog
Cloudflare One now incorporates dynamic User Risk Scores into Access policies to enable automated, adaptive security responses. This update allows teams to move beyond binary "allow/deny" rules by evaluating continuous behavior signals from both internal and third-party sources.
11日前

Introducing the 2026 Cloudflare Threat Report
The Cloudflare Blog
There has been a fundamental shift toward industrialized cyber threats, highlighted by a record 31.4 Tbps DDoS attack and sophisticated session token theft. Our new report examines how nation-states and criminal actors have moved beyond traditional exploits to "living off the XaaS" within legitimate enterprise logic.
11日前