Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

An API for MoQ: provision your own isolated relays

Last year, we enabled Media over QUIC (MoQ) on every Cloudflare server and opened the network for anyone to test. It provided a global MoQ endpoint, but not the isolation and access controls needed to run an application. Today, we’re adding those isolation and access controls. The new MoQ provisioning API lets you create an isolated relay for your application and issue separate credentials for publishers and subscribers.

Why is MFA Needed for Your Atlassian Cloud Instance?

In 2026, cyberattacks are constant and highly coordinated. Every day, there are 300 million fraudulent sign-in attempts targeting cloud services. That number reflects the scale of automated attacks happening right now across the cloud. If your organization uses Atlassian Cloud apps like Jira, Confluence, or Jira Service Management, you rely on the cloud. Your critical data, like customer info, source code, sprint data, or documentation, is stored there.

Protecting data in the cloud: Risks, responsibilities, and best practices

Cloud storage feels like an ocean—vast, endless, and deeper than Everest is tall. While it feels like there is limitless space for your data, the reality is not so harmonious. It's truly a case of survival of the fittest. With the right policies and data protection practices in place, your data remains safe. If not, it could either be lost in the abyss as dark data or end up as the next meal of a great white.

Post-quantum authentication to origins is now supported

Cloudflare's Authenticated Origin Pulls and Custom Origin Trust Store now support post-quantum authentication. Here we’ll explain how you can configure fully post-quantum secure mutually authenticated TLS connections to your origin server, dive into the engineering details of how we built it, make a shameful confession, and finally explain how this work fits into our overall post-quantum migration roadmap.

Best Atlassian Apps to Reduce Cloud Costs

Are you trying to reduce Atlassian Cloud costs? Runaway software expenses are usually driven by three specific factors: dormant user licenses, slow manual provisioning, and paying for full access seats for temporary external collaborators. To optimize Atlassian Cloud costs, you need to address these root cost drivers directly rather than paying for seats nobody uses.

Falcon Cloud Security July 2026 Release: Helping Security Teams Move Faster in the Cloud

Every change in a cloud environment creates new security decisions. A new infrastructure as code (IaC) template needs to be validated. Cloud permissions need to be reviewed. An application release introduces new cloud interactions. A Kubernetes cluster needs protection before it goes into production. Individually, these are routine tasks. Together, they create growing operational friction that makes cloud security harder to scale.

Natural disasters and government interference: examining Q2 2026's major Internet disruption events

Like most infrastructure, the Internet's fragility is easy to overlook — as long as it's working. When it fails, its complexity comes into full view. Cloudflare is in a unique position to detect and document the moments when one of the interrelated systems the Internet depends on breaks down and connectivity suffers as a result. Each quarter, we summarize the disruptions we detect and annotate on Cloudflare Radar.

LimaCharlie Cloud Security: CNAPP Walkthrough

A walkthrough of Cloud Security in LimaCharlie — CNAPP capability built into the SecOps Cloud Platform. Connect your cloud and SaaS providers (AWS, GCP, Azure, Okta, Google Workspace, GitHub, Cloudflare, Anthropic, and even other LimaCharlie orgs) and everything is normalized into a single security graph: identities, permissions, workloads, and data. The engine reasons over that graph to surface attack paths — evidence-backed chains an attacker could actually walk — instead of isolated checkbox findings.

We're open-sourcing our privacy proxy CLI

Debugging privacy-preserving protocols is hard. Oblivious HTTP has several different steps across four different parties, not to mention binary HTTP encoding and details spread across many draft RFCs. We've taken what we've learned operating protocols like Oblivious HTTP at the scale of millions of requests per second, and wrapped it up in a nice, clean CLI tool — that we are open-sourcing today. We call it our privacy-client, or pvcli.

BGP ORIGIN attribute manipulation and its impact on the Internet

Border Gateway Protocol (BGP) is the de facto routing protocol of the Internet. It offers built-in mechanisms to allow entities, represented by Autonomous Systems (ASes), to express how they want to send and receive traffic on the Internet. One such mechanism is path attributes, which carry essential routing information and metadata for their associated route.

Best Cloud Penetration Testing Providers in 2026

Most cloud breaches begin with a configuration error the customer made. Gartner projected that through 2025, 99% of cloud security failures would be the customer’s responsibility, caused by misconfigured identity and access management, exposed storage, and over-permissioned services. Cloud penetration testing is the simulation of real-world attacks against cloud infrastructure on AWS, Azure, and GCP to find those exploitable gaps before an attacker does.

Secure every identity. Human or not.

AI agents are now managing critical tasks across your workforce. And they need access to your enterprise IT systems to do it. JumpCloud manages the entire lifecycle for human, non-human, and agentic identities from a single platform. Every identity, verified. Every action, governed. Learn more on how to secure every identity. Human or not.

Enabling Massive-File Collaboration in the Cloud With Adaptive Block Caching

When it comes to massive files, many organizations still rely on old-fashioned, on-premises file servers and filers. They’re hesitant to work on these projects in the cloud because the inherent network latency makes working with massive files difficult. So they stick to an on-premises approach—even though it typically requires wired access and stable VPN connections, which makes sharing and collaborating especially challenging for people working from home, in the field, or on the road.

How to Secure Cloud Communication Systems Against Modern Cyber Threats

As businesses increasingly rely on cloud-based communication systems like Voice over IP (VoIP) for daily operations, securing these platforms has become a top concern. The convenience and flexibility of cloud communications come with unique vulnerabilities that cybercriminals are eager to exploit. Protecting these vital channels isn't just an IT issue; it's fundamental to business continuity and data protection.
Featured Post

Organisations Don't Need a Cloud-Native Network to Adopt SASE

In a perfect world, every business would design its network from day one with the need for scalability, connectivity from anywhere and zero-trust security in mind. In the real world, of course, few organisations have this luxury. Most have entrenched technology investments in place, and overhauling them to conform with modern network access and security paradigms isn't always feasible.

Cloudflare WAF protects WordPress applications from two high-severity vulnerabilities

Cloudflare has deployed new Web Application Firewall (WAF) protections for two critical vulnerabilities affecting WordPress. The protections address an Unauthenticated Remote Code Execution (RCE) vulnerability in WordPress's REST API and a related SQL Injection vulnerability. The WordPress security team disclosed the vulnerabilities to Cloudflare before public release so that we could prepare protections for customers.

The 30-Minute Cloud Risk Assessment Every MSP Should Be Offering

Every time a client gets breached through a cloud app, it's the MSP who gets the call. Compromised Microsoft 365 accounts, unauthorized AI tools, and misconfigured sharing settings. Attackers aren't breaking in anymore. They're logging in through gaps that your endpoint, firewall, and MDR tools were never designed to see.

GitProtect 2.4.0: Complete QA Protection in Azure DevOps, FIPS-Compliant Encryption, and More

The new 2.4.0 release delivers complete protection for your entire Quality Assurance (QA) workloads in Azure DevOps. Teams on platforms hosted locally in Windows can now secure them with the AES encryption compliant with the federal, enterprise-grade FIPS standards. This release also packs other notable upgrades, including seamless Active Directory integration, a smarter repository exclusion mechanism, and full German language support. Dive into the full breakdown below.

Backup Azure DevOps Test Plans w GitProtect.io | Ochrona QA i Test Suites

Zabezpiecz pełny cykl zapewnienia jakości w swoich projektach programistycznych! W wersji 2.4 GitProtect wprowadza wyczekiwaną funkcję: pełną kopię zapasową oraz odzyskiwanie planów testowych Azure DevOps Test Plans (w tym powiązanych zestawów testów — Test Suites). W tym wideo pokazujemy, jak łatwo dodać i skonfigurować plan ochrony dla Azure DevOps, zachowując przy tym pełną strukturę powiązań między przypadkami testowymi, konfiguracjami i historią ich wykonania.

Building a More Secure Workplace Technology Environment

One weak password. One rushed click. One laptop left in a rideshare. That's all it can take to create a very real problem for your business. Strong workplace technology security is no longer just about locking down computers. It protects payroll, customer records, employee privacy, contracts, financial data, and the trust you've worked hard to earn.

A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed

On July 3, 2026, the Albanian communications authority (AKEP), the operator of the.AL country-code top-level domain (TLD) of Albania, attempted a DNSSEC key rollover. Something went wrong, resulting in DNSSEC validation failures. Any validating DNS resolver receiving these signatures was required by the DNSSEC specification to reject them and return errors to clients. That includes 1.1.1.1, the public DNS resolver operated by Cloudflare.

Demo Discover Enterprise AI Workloads Running on AWS

AI workloads are appearing across AWS environments faster than most teams can inventory them. New APIs, EKS clusters, model integrations, and AI services are showing up across accounts and regions without a clear ownership trail or centralized visibility. By the time security catches up, the environment has already changed again.

Introducing Precursor: detecting agentic behavior with continuous client-side signals

Bot mitigation is an adversarial game: attackers adapt, defenders respond, and the cycle continues. At Cloudflare, we stay ahead by combining visibility across our global network with signals from the client-side environment. At the network level, we analyze over 1 trillion requests per day to understand reputation, patterns, and anomalies across more than 20% of the web.

Cloud Transition Challenges: From On-Prem to Multi-Cloud Security #shorts

Organizations are fully onboarded in multi-cloud environments (AWS, Azure, GCP), but transitioning from traditional on-prem security to the cloud poses a significant challenge. Cloud security teams now need to collaborate with traditional network engineering teams, each with different objectives, to bridge the gap.

Warehouse Security That Keeps Operations Moving

Warehouses are built for motion. Trucks arrive, products move, employees shift between zones, and valuable inventory often sits in multiple areas at once. That constant activity creates opportunities, but it also creates risk. For operators who need better visibility, safer access, and stronger protection, it can make sense to hire ADR Security when planning a system that supports daily warehouse operations without slowing them down.

Why we cannot wait for better post-quantum signature algorithms

RSA and ECC, cryptographic algorithms that we’ve all relied on for decades, are vulnerable to the attack of sufficiently advanced quantum computers. Such quantum computers do not exist yet, but they seem to be coming sooner than expected. Luckily, the solution is already available: migrate to ML-KEM encryption and ML-DSA signatures, which are designed to be resistant to quantum attack. They were standardized in 2024 by the U.S.

Defence in Depth Changed Forever with Cloud Security

Defence in depth changed forever with cloud security because the old perimeter gave way to platforms, suppliers and connected services outside direct control. That means modern attackers often reach the target through weaker vendors, cloud services or supply chain links instead of attacking the business head on.

Hybrid Cloud Security: A CISO's Guide for 2026

A hybrid breach now costs an average of $5.05 million per incident, and that's 26% more expensive than breaches in traditional on-premises-only environments according to AppSecure's 2025 cloud security statistics. That number changes the conversation. Hybrid cloud security isn't a side project for infrastructure teams. It's a board-level risk issue with direct impact on resilience, audit readiness, and operating cost.

When AI Agents Call AWS, Who Does AWS Think They Are?

In Part 1, Your AI Agent Needs to Know Who You Are, we showed how Teleport JWTs give MCP tools a verified identity for every request. This post extends that pattern to AWS, specifically to Amazon Bedrock AgentCore, where the same identity gap exists but requires a different solution stack. You ask an AI agent to list your S3 buckets. The agent calls an MCP tool. The tool reaches out to AWS. However, CloudTrail records the action under something like agentcore-bot, but not your identity.

AWS egress fees and data transfer costs explained for MSPs and cloud providers

AWS has become a default infrastructure platform for many organizations. It offers scale, flexibility and a broad service portfolio. However, for managed service providers (MSPs) and cloud providers, AWS pricing can be difficult to explain, forecast and package profitably. One of the most important cost factors is AWS data transfer cost. Internet egress, or data leaving AWS for the public internet, is the most familiar example.

Protect AWS Strands Agents with Datadog AI Guard

AI agents can reason through tasks, call tools, and adapt their next steps based on intermediate results. That flexibility is useful for building agentic applications, but it also creates security risk at runtime: A prompt injection attempt can change the agent’s instructions, a malicious request can try to exfiltrate sensitive data, and an unsafe tool call can lead to an action that the application owner did not intend.

Protecting Sensitive Documents from Digital Threats

In our increasingly digital lives, we handle a vast number of documents, from personal financial statements and contracts to sensitive business reports. We often focus on securing our networks and devices, but the security of the documents themselves is frequently overlooked. Protecting these files from digital threats isn't just an IT department's problem; it's a personal responsibility for anyone creating, sharing, or storing information.

How I Chose a CIEM Tool: My Practical Review of Cloud Access Governance Platforms

Choosing a CIEM tool sounds simple until you actually start doing it. At first, I thought I only needed another security dashboard - something that could show me which users, roles, service accounts, and workloads had access to cloud resources. But after looking deeper into our environment, I realized the real problem was not visibility alone. The real problem was cloud access risk.

5 Essential Cybersecurity Defenses for Cloud Email Security

Cloud email has become the center of modern business. Regardless of your organization's industry or size, email connects employees, customers, vendors, executives, financial systems and critical business processes. Unfortunately, attackers know this too. For cybercriminals, compromising an email account is often like finding the master key to a building. Once inside, they may be able to steal information, impersonate employees, redirect payments, spread malware or gain access to other systems.

IaaS for MSPs: A practical guide to building profitable cloud services

Infrastructure as a service (IaaS) is becoming a bigger opportunity for managed service providers (MSPs), cloud service providers (CSPs), hosters and telecommunications providers. Clients still need compute, storage and networking. But many are rethinking where those workloads should run.