JUN 17, 2026
EngBrief
Search⌘K
LatestTopicsSourcesSaved
Eng&Brief

Engineering insights from the world's best tech companies, curated and summarized.

Weekly brief

Browse

TopicsSourcesFavorites

More

SearchRSS Feed
© 2026 EngBriefUpdated every 4 hours
← Sources
blog.cloudflare.com icon
Security

Cloudflare Blog

93 articles on EngBrief

The Cloudflare Blog is one of the most prolific technical blogs in the industry, covering internet security, networking, and edge computing. Posts explore DDoS mitigation, DNS infrastructure, TLS/cryptography, Cloudflare Workers, AI on the edge, HTTP standards, and the global network that serves over 20% of the web.

SecurityNetworkingEdge ComputingCryptographyPerformance
Visit blog →

Latest Articles

Cloudflare22h ago

Cloudflare DMARC Management is now generally available

Cloudflare has made its DMARC Management feature generally available, offering a user-friendly experience to help businesses easily enforce DMARC policies and protect their domains from email spoofing and brand impersonation. The feature provides a unified dashboard to view email authentication posture, along with in-depth reporting and analysis tools to identify and rectify authentication record configurations. This enables organizations to tighten their DMARC policies without breaking legitimate email flows.

NetworkingSecurity
1 min
Cloudflare1d ago

Growing the Cloudflare AI team with talent from Ensemble AI

Here's a 3-sentence summary of the blog post: Cloudflare is growing its AI team with talent from Ensemble AI, a company that has developed new approaches to model compression and efficient inference, enabling large language models to be faster, smaller, and more cost-effective. Ensemble's expertise in preserving model structure while reducing cost complements other efficiency techniques, pointing to a future where developers can run capable AI models with lower memory, compute, and cost requirements. Cloudflare will leverage Ensemble's work to improve the efficiency layer underneath its Workers AI platform, making AI more accessible, useful, and cost-efficient for developers.

NetworkingSecurity
1 min
Cloudflare4d ago

Scaling Security Insights: how we achieved a 10x increase in global scanning capacity

Cloudflare scaled Security Insights by achieving a 10x increase in global scanning capacity, enabling automatic scanning for all accounts and doubling scanning frequency. Key improvements included optimizing database queries, fixing API latency and timeouts, and rethinking the scheduler. By splitting consumer groups into 'fast' and 'slow' lanes, introducing parallel processing, and optimizing database queries, Cloudflare resolved issues with head-of-line blocking and API performance.

NetworkingSecurity
1 min
Cloudflare6d ago

Route public traffic to private applications with Cloudflare

Cloudflare launches Application Services for Private Origins, allowing customers to route public traffic to private applications without exposing them to the public Internet. This eliminates the need for public IPs, firewall exceptions, or complex networking, and enables Cloudflare's security, performance, and programmability services to protect private applications. Customers can now use Cloudflare's full Application Services stack with private origins, including WAF rules, bot management, rate limiting, caching, and Workers.

NetworkingSecurity
1 min
Cloudflare8d ago

Defend against frontier cyber models: Cloudflare's architecture as customer zero

Cloudflare's architecture serves as a model for defending against frontier cyber models. By leveraging its own products, Cloudflare creates a robust security stack that includes visibility, threat intelligence, and machine learning-based detection to address the challenges posed by frontier models, such as rapid discovery, exploit volume, and adaptation. Cloudflare's approach focuses on closing the gap between vulnerability discovery and mitigation through real-time threat intelligence and rapid rule deployment.

NetworkingSecurity
1 min
Cloudflare8d ago

Turning Cloudflare’s threat indicators into real-time WAF rules

Cloudflare has integrated its threat indicators into real-time WAF rules, allowing security teams to automate blocking of high-risk IPs before they attempt to access their infrastructure. This is done by populating specialized fields in the WAF engine with live intelligence data, enabling rules to screen traffic based on threat actor names, target industries, attack types, and more. The always-on detection model eliminates the "log vs. block" trade-off, providing visibility and protection without compromising performance.

NetworkingSecurity
1 min
Cloudflare11d ago

Your AI bill is out of control. Cloudflare can fix it now.

Cloudflare's AI Gateway now offers spend controls to help companies manage their AI expenses. These controls include budgets set in dollars, rather than tokens, that track cumulative spend across all requests and can be scoped to specific dimensions such as model, provider, or user. This allows companies to see where their AI spend is going and set limits to prevent overages. The new features also include identity-driven budgets and policies, which use Cloudflare Access to automatically attribute AI usage to specific users or teams. This enables per-user budgets, team model policies, and cost attribution, making it easier for companies to manage their AI expenses and optimize their costs. With these features, companies can now track their AI spend in real-time, set budgets and limits, and make data-driven decisions to optimize their AI expenses and usage.

NetworkingSecurity
1 min
Cloudflare12d ago

VoidZero is joining Cloudflare

Cloudflare is acquiring VoidZero, the company behind popular frameworks Vite, Vitest, and others. Vite remains open source and vendor-agnostic, with its roadmap driven by the community and VoidZero team. Cloudflare is committing engineering resources and $1 million to a Vite ecosystem fund to support maintainers and contributors.

NetworkingSecurity
1 min
Cloudflare13d ago

Enforcing the First AS in BGP AS_PATHs

Cloudflare researchers detected recent BGP hijacking attempts using fake AS_PATHs, where attackers created fake networks and used unused ASNs to misdirect traffic. To prevent these attacks, the researchers recommend enforcing the First AS in BGP AS_PATHs, which prevents attackers from stripping their own ASN from the path. This simple safeguard can be implemented by major networks and prevents hijackers from forging AS_PATHs and intercepting traffic.

NetworkingSecurity
1 min
Cloudflare15d ago

How we reduced core unit boot time from hours to minutes

Cloudflare engineers tackled a critical issue of prolonged core unit boot times, which affected nearly 2,000 Gen12 units, after a routine firmware update caused some servers to take four hours to reboot instead of minutes. They identified the problem as a firmware quirk that led to a linear search through every network boot interface, wasting minutes due to timeout responses. To resolve this, they restructured the boot automation workflow to declare the correct network boot interface upfront, eliminating the guesswork and reducing total boot time from four hours to minutes.

NetworkingSecurity
1 min
Cloudflare19d ago

How we built Cloudflare's data platform and an AI agent on top of it

Cloudflare built a unified data analytics platform called Town Lake to streamline access to its vast amounts of data, spanning over 100+ countries. This platform provides a single SQL interface to all of Cloudflare's data, ensuring consistency and accuracy in querying. Town Lake is built on R2 storage, Workers for compute, and Cloudflare Access for authentication, with a focus on security, governance, and scalability. Town Lake's architecture is a data lakehouse, combining query engines, metadata layers, and data cataloging to deliver fast and secure data access. Its components include a query engine powered by Apache Trino, a managed Apache Iceberg service for storage, a metadata catalog for data lineage and ownership, and an access control service for secure authentication. Built on top of Town Lake is Skipper, an AI data agent that runs on plain English queries to provide correct, auditable answers in seconds. Skipper aims to empower anyone at Cloudflare to access and analyze the stream of data flowing through their network

NetworkingSecurity
1 min
Cloudflare20d ago

Iran's Internet is partially restored, Cloudflare Radar data shows

Cloudflare's Radar data shows a significant increase in internet activity and DNS queries in Iran, indicating a partial restoration of internet services in the country. The data, however, also suggests that the restoration is incomplete, with traffic levels still below pre-shutdown levels. IPv6 traffic remains affected, with a near-complete loss of announced IPv6 address space.

NetworkingSecurity
1 min
Cloudflare26d ago

Announcing Claude Compliance API support with Cloudflare CASB

Cloudflare has extended its Cloud Access Security Broker (CASB) to support the Claude Compliance API, allowing security teams to monitor Claude usage directly in the Cloudflare dashboard without requiring endpoint agents. This integration builds on Cloudflare's existing AI governance support, delivering visibility and control over sanctioned and unsanctioned applications, including AI tools. By consuming Claude's security-relevant data, Cloudflare CASB surfaces actionable security findings, enabling organizations to regain visibility and control over their investments in SaaS applications, including Claude Enterprise activity.

NetworkingSecurity
1 min
Cloudflare28d ago

Announcing Claude Managed Agents on Cloudflare

Cloudflare has integrated Claude Managed Agents, enabling developers to run agent loops on the Claude Platform while utilizing Cloudflare's infrastructure for secure code execution and customizable sandboxes. This integration offers enhanced security, observability, and scalability, allowing developers to run multiple agents at scale and minimize infrastructure costs. Developers can choose between traditional microVMs and lightweight isolates for sandboxing, depending on their performance and security requirements.

NetworkingSecurity
1 min
CloudflareMay 18, 2026

Project Glasswing: what Mythos showed us

Cloudflare's Project Glasswing tested a cutting-edge security-focused LLM, Mythos Preview, on its infrastructure to identify vulnerabilities and gauge potential threats. Mythos Preview excelled in constructing complex exploit chains and generating proofs of concept, demonstrating its potential as a valuable tool in vulnerability research. However, the model occasionally pushed back on certain requests, and its organic refusals weren't consistent, highlighting the need for additional safeguards in a broader research context. Mythos Preview performed well in triaging security vulnerabilities, with higher-quality output and fewer hedged findings compared to previous models. Its ability to chain primitives and generate clear reproduction steps also made it a valuable addition to Cloudflare's security processes. To address the "signal-to-noise" problem in vulnerability research, Mythos Preview's harnesses were deliberately tuned to over-report, resulting in more findings, but also more noise.

NetworkingSecurity
1 min
CloudflareMay 14, 2026

Our billing pipeline was suddenly slow. The culprit was a hidden bottleneck in ClickHouse

Cloudflare encountered a bottleneck in ClickHouse due to lock contention in query planning after redesigning a table to support per-tenant retention. The redesign, which added a namespace to the partitioning key, created thousands of data parts and led to massive lock contention, resulting in slower query times. To mitigate this issue, ClickHouse engineers implemented a trio of patches aimed at reducing lock contention and query planning time. The patches improved the order of pruning parts in query planning, which led to a 5% improvement, and modified the locking mechanism to reduce contention and waiting times.

NetworkingSecurity
1 min
CloudflareMay 13, 2026

Browser Run: now running on Cloudflare Containers, it’s faster and more scalable

Cloudflare rebuilt its Browser Run platform on top of Cloudflare Containers, boosting performance, scalability, and reliability. This change increased usage limits to 60 browsers per minute and 120 concurrent browsers, and decreased Quick Action response times by over 50%. As a result of the migration, Cloudflare was able to ship fixes and new features faster, leveraging the flexibility of Cloudflare Containers. The team overcame initial technical hurdles, including latency issues and scaling bottlenecks, by implementing regional pools of pre-warmed browser containers and optimizing their architecture. To enhance scalability and meet the demanding requirements of the platform, Cloudflare migrated from Workers KV to D1 instances and Queues, which significantly improved write throughput and reduced lag times to below 2 seconds. This new approach enabled the team to handle large volumes of requests and efficiently manage browser state, making it a more robust and reliable platform.

NetworkingSecurity
1 min
CloudflareMay 12, 2026

When "idle" isn't idle: how a Linux kernel optimization became a QUIC bug

Engineers at Cloudflare discovered a bug in the Linux kernel's CUBIC congestion control algorithm that prevents it from recovering from a congestion collapse event. The issue arises when the congestion window (cwnd) gets permanently pinned at its minimum after a loss event, causing the algorithm to oscillate between recovery and congestion avoidance states. This bug was found in the context of QUIC, where it fails 61% of the time in a test scenario involving heavy loss in the early connection phase.

NetworkingSecurity
1 min
CloudflareMay 7, 2026

Building for the future

Cloudflare's leadership, including Matthew Prince and Michelle Zatlyn, announced a significant workforce reduction of over 1,100 employees due to the increased adoption of AI within the company, requiring a reimagining of internal processes and roles. This change is part of Cloudflare's pivot to a high-growth, AI-driven organization, aiming to create value in the "agentic AI era." Cloudflare is providing generous severance packages to departing employees, including full base pay through the end of 2026 and vested equity.

NetworkingSecurity
1 min
CloudflareMay 7, 2026

How Cloudflare responded to the “Copy Fail” Linux vulnerability

Cloudflare's Security and Engineering teams quickly assessed the Linux kernel "Copy Fail" vulnerability upon public disclosure on April 29, 2026. They evaluated the exploit technique, checked exposure across their infrastructure, and validated that their existing behavioral detections could identify the exploit pattern within minutes. As a result, there was no impact to the Cloudflare environment, no customer data was at risk, and no services were disrupted at any point. Cloudflare's established procedures ensure that they have already deployed patches for critical vulnerabilities, in this case, allowing them to respond proactively to the issue.

NetworkingSecurity
1 min