Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Azure Monitor Agent Metrics Extension Vulnerability: From Engagement to CVE

This article was authored by Cristhian Parrot from the Kroll Offensive Security Team. Kroll’s Offensive Security Team recently discovered a new vulnerability within Microsoft’s Azure Monitor Agent Metrics Extension, which demonstrates how subtle configuration issues can introduce significant security risks in widely deployed infrastructure components.

Why Every MSP Should Be Offering a 30-Minute Cloud Risk Assessment

As businesses continue moving critical workloads to the cloud, attackers are increasingly targeting identities, SaaS applications, and cloud configurations. While many organizations believe their cloud environments are secure, hidden risks often go unnoticed until it's too late. For MSPs, this presents an opportunity to deliver greater value while growing recurring security revenue.

Falcon Cloud Security June 2026 Release: Updates for Azure and Google Cloud

Identities, permissions, exposed resources, and sensitive data can all contribute to risk regardless of whether they reside in AWS, Microsoft Azure, or Google Cloud. However, security teams often encounter uneven visibility and coverage across disparate cloud environments, and face difficulty in consistently understanding risk across a multi-cloud estate.

Falcon Cloud Security: Attack Path Analysis Across Multi-Cloud Environments

Falcon Cloud Security correlates cloud exposures into prioritized attack paths and enriches them with CrowdStrike adversary intelligence, helping teams focus on the risks most likely to be exploited across AWS, Azure, and Google Cloud. Subscribe and stay updated!

The post-quantum EO is an important milestone. Now it's time to get to work

On June 22, 2026, President Trump signed Executive Order 14409, "Securing the Nation Against Advanced Cryptographic Attacks." The order sets a December 31, 2030, deadline for federal agencies to transition their most sensitive systems to post-quantum encryption, and a December 31, 2031, deadline for post-quantum authentication. The EO also directs federal contractors to comply with post-quantum Federal Information Processing Standards (FIPS) by the end of 2030.

Better Together: How Wiz and Cloudflare Are Democratizing Cloud Security

Oron Noah, VP of Product Extensibility & Partnership at Wiz, shares how the Cloudflare and Wiz partnership began and how their integration delivers better security outcomes — from code to production — by giving every team full visibility into their cloud environment.

The Vanta Trust Center is now on AWS Marketplace

Accelerating security solutions for small businesses‍ Tagore offers strategic services to small businesses. A partnership that can scale‍ Tagore prioritized finding a managed compliance partner with an established product, dedicated support team, and rapid release rate. Standing out from competitors‍ Tagore's partnership with Vanta enhances its strategic focus and deepens client value, creating differentiation in a competitive market.

94% of Organizations Report Cloud Breaches: CrowdStrike State of CDR Survey

Organizations are struggling to detect, investigate, and contain cloud threats before adversaries achieve their goals. The new CrowdStrike State of Cloud Detection and Response (CDR) Survey highlights the primary challenges they face: Together, these challenges are creating opportunities for threat actors to successfully breach cloud environments.

Dedicated Server Hosting: Benefits, Use Cases and Pricing in 2026

Despite the rapid growth of cloud platforms, the dedicated server market continues to expand. Many companies still choose dedicated server hosting for hosting corporate applications, databases, SaaS platforms, high-traffic web services, and artificial intelligence infrastructure. The reason is simple. Not every workload can be efficiently handled in a virtualized environment. Many projects require guaranteed computing resources, consistent performance, full server control, and the ability to customize hardware according to specific business requirements.

Introducing the Cloudflare One stack: agent-powered deployment

Adopting or migrating to a Zero Trust network architecture can be a daunting task. Before a single policy changes, teams have to recall how their network is actually built: which applications exist, their authentication and authorization constructs, how traffic flows between them, and any assumptions the current architecture makes. This hands-on process requires practitioners to decode the intent behind every security and routing policy in place.

Bringing more agent harnesses and frameworks to Cloudflare, starting with Flue

2026 is the year agent harnesses go to production. The software that controls the model’s access to the outside world — harnesses like Codex, Claude Code, OpenCode, Pi, and Project Think — has matured to the point where teams are deploying agents as real, load-bearing infrastructure, not just prototypes. But building agents that survive production is hard.

Protecting Applications Through Secure Development Practices

Modern software rarely gets built from scratch. Instead, it's put together using a complex mix of proprietary code, open-source libraries, third-party APIs, and various development tools. This network of dependencies and components makes up the software supply chain. While this approach speeds up development, it also brings significant security risks that attackers can exploit, making it more crucial than ever to protect this chain.

Cloud Security Threats: How Prevention Cloud Protects Data

It is more important than ever to keep your data secure. Malware, ransomware, and attacks on cloud-based assets pose a constant threat to businesses as more sensitive data moves to the cloud. A report by Cybersecurity Ventures projected global cybercrime costs to reach $10.5 trillion annually by 2025. Data breaches, ransomware, fraud, and operational disruption are major contributors to cybercrime losses.

Cloudflare DMARC Management is now generally available

When we first launched DMARC Management, it was driven by a simple belief: every domain on the Internet deserves strong email authentication, and cost should never be the reason it doesn't happen. As part of our mission to help build a better Internet, we made DMARC Management available for free to every Cloudflare customer. We wanted to give everyone the tools to understand and improve their DMARC posture without needing to hire an email security consultant or parse XML report files by hand.

Growing the Cloudflare AI team with talent from Ensemble AI

Today, we’re excited to share that key members of the team at Ensemble AI are joining Cloudflare to help accelerate our work in AI infrastructure and make it easier for developers to run powerful AI models efficiently at scale. Ensemble AI, founded in 2023 in San Francisco, has spent the last few years focused on one of the most important challenges in AI: making large models faster, smaller, and more cost-effective to serve, without sacrificing quality.

What is Cloud Security?

Many people assume that cloud storage is automatically private, but in reality, security levels vary widely between providers. Understanding the differences between cloud security, privacy, and what kind of cloud storage meets your needs is essential if you want to protect personal or business information from unauthorized access, data leaks, or misuse.

Scaling Security Insights: how we achieved a 10x increase in global scanning capacity

Security Insights provides actionable security recommendations for every Cloudflare account. To find these insights, we perform regular scans for all accounts, zones, and DNS records, looking for potential security risks and misconfigurations. However, two key issues emerged. First, our scans were too infrequent. Scans were only being performed every week or two, and therefore newly introduced security risks could remain undetected for up to two weeks.

Cloud Security Monitoring: A Complete Guide for 2026

Your cloud footprint probably grew faster than your monitoring program did. That's the normal path. A team starts with one cloud account, one logging service, and a few dashboards. Then come managed databases, containers, serverless functions, SaaS integrations, new identities, and temporary workloads that appear and disappear before anyone documents them. Security ends up with a pile of logs, a backlog of alerts, and a nagging suspicion that the dangerous activity isn't the stuff already visible.

Why Technology Companies Are Investing in Drone App Development

The global drone market is expanding at an impressive pace, driven by advances in automation, artificial intelligence, cloud computing, and connectivity. While drone hardware continues to evolve, software has become the primary factor that determines how effectively organizations can leverage these technologies. Companies working with companies, such as Wezom, on custom drone app development projects are discovering new ways to automate operations, improve data visibility, and create scalable digital ecosystems that support long-term growth.

SIEM on Cloud: Modernizing Threat Detection for 2026

Your team already knows the pattern. The on-prem SIEM is still running, but it's become a bottleneck instead of a force multiplier. Cloud logs arrive late or in partial form. SaaS activity sits in separate consoles. Endpoint and identity events don't line up cleanly. Analysts burn time pivoting across tools, then still end up asking whether the alert is real. That's why the conversation around SIEM on cloud has changed. It's no longer about chasing a newer deployment model.

Cloud Security Report Finds Fragmented Tools Widening the Cloud Complexity Gap

The 2026 Cloud Security Report from Cybersecurity Insiders, produced in collaboration with Fortinet, finds that 69% of organizations cite tool sprawl and visibility gaps as the top factor limiting cloud security effectiveness. Based on a survey of 1,163 IT and cybersecurity professionals, the report shows the strain: 66% lack strong confidence in their ability to detect and respond to cloud threats in real time, up from 64% last year.

Route public traffic to private applications with Cloudflare

For most of the Internet’s history, public and private infrastructure operated as separate worlds. Public applications lived behind content delivery networks (CDNs) and web application firewalls (WAFs). Private applications lived behind virtual private networks (VPNs), firewalls, and separate operational stacks. We think that distinction is becoming obsolete.

Defend against frontier cyber models: Cloudflare's architecture as customer zero

A few weeks ago, we wrote about Project Glasswing and what we observed when we pointed cyber frontier models at our own code. Since then, we’ve seen that the part of the post that has resonated most deeply is the argument that the architecture around the vulnerability matters more than the speed of the patch.

Top 7 CDN Services That Improve Speed While Protecting Your Website

Website speed and website security used to feel like two separate projects. In 2026 they're basically the same conversation. When your pages load slowly, users bounce and ad costs creep up. When scrapers, probes, or traffic spikes hit your site, a "speed issue" turns into downtime (or at least a costly performance day).

Turning Cloudflare's threat indicators into real-time WAF rules

Cloudflare’s Threat Events provides security analysts with a window into the global threat landscape. The platform offers a peek into the immense traffic that Cloudflare processes every day, so you can see in real time which IPs are attacking specific industries or which threat actors are trending globally. However, translating that visibility into active mitigation has often been a manual, reactive process.

The Deep Dive | The Future of IT Management: Meet JumpCloud AI Assistant 06.05.2026

Stop navigating endless pages and start managing through conversation. See how AI Assistant translates your intent into secure, confirmable actions across users, devices, groups, and more, helping your IT team work faster and with greater confidence.

Your AI bill is out of control. Cloudflare can fix it now.

There isn't a CIO on the planet not worried about AI spend right now. CFOs are increasingly nervous, too. For fear of falling behind, many companies have pushed their employees to use AI as aggressively as possible. The edict was clear: "Move fast, we'll figure out the bill later." And for the most part, it worked: AI has been genuinely transformational for the teams that leaned in. But the costs are real: we’ve heard countless horror stories of huge bills and painful overages on token spend.

10 cloud data security solutions mid-market teams should consider in 2026

Cloud data security solutions protect sensitive data across SaaS, IaaS, and hybrid environments, covering discovery, classification, access governance, DLP, and evidence for compliance. No single tool covers everything. The right stack depends on where regulated data actually lives, who has access to it, and what evidence your compliance team needs to satisfy auditors. Regulated data doesn't stay in one place, and cloud data security solutions need to account for that reality.

Beyond the VPN: Modernizing Access with Netskope ZTNA

BDO escaped from a legacy, "connect-on-logon" VPN infrastructure to a modern Netskope-driven architecture to overcome scalability and performance limitations. By implementing zero trust network access (ZTNA), the organization replaced full-scale system access with granular controls that reduce the potential damage across their infrastructure. Netskope’s global data centers provided a backbone that prevents overutilization and ensures high service level agreements (SLAs), and offered faster routing for critical tools like Microsoft 365 and private applications.

What Santa Clarita Businesses Should Look for in a Managed IT Services Provider

Technology has become a core part of how modern businesses operate. From cloud apps and remote work tools to cybersecurity, data backup, and helpdesk support, companies rely on their IT systems every day. For businesses in Santa Clarita, the right managed services provider can make a major difference. A strong provider does more than fix computers when something breaks. They help protect your network, support your employees, improve uptime, and plan for future growth.

Balancing Protection and Performance in Retail: AI Guardrails for the Modern Enterprise

The video emphasizes the critical need for due diligence when deploying AI, focusing on establishing ethical parameters and safety guardrails. The speaker highlights that for a retailer, security is paramount to protect customer data and credit/insurance services while ensuring a seamless, high-performance user experience. Netskope provides the necessary ethical guardrails and safety parameters required to deploy AI technologies without compromising security.