Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

A broken DNSSEC rollover took down .AL. Now 1.1.1.1 tells you when validation is bypassed

On July 3, 2026, the Albanian communications authority (AKEP), the operator of the.AL country-code top-level domain (TLD) of Albania, attempted a DNSSEC key rollover. Something went wrong, resulting in DNSSEC validation failures. Any validating DNS resolver receiving these signatures was required by the DNSSEC specification to reject them and return errors to clients. That includes 1.1.1.1, the public DNS resolver operated by Cloudflare.

Demo Discover Enterprise AI Workloads Running on AWS

AI workloads are appearing across AWS environments faster than most teams can inventory them. New APIs, EKS clusters, model integrations, and AI services are showing up across accounts and regions without a clear ownership trail or centralized visibility. By the time security catches up, the environment has already changed again.

Introducing Precursor: detecting agentic behavior with continuous client-side signals

Bot mitigation is an adversarial game: attackers adapt, defenders respond, and the cycle continues. At Cloudflare, we stay ahead by combining visibility across our global network with signals from the client-side environment. At the network level, we analyze over 1 trillion requests per day to understand reputation, patterns, and anomalies across more than 20% of the web.

Cloud Transition Challenges: From On-Prem to Multi-Cloud Security #shorts

Organizations are fully onboarded in multi-cloud environments (AWS, Azure, GCP), but transitioning from traditional on-prem security to the cloud poses a significant challenge. Cloud security teams now need to collaborate with traditional network engineering teams, each with different objectives, to bridge the gap.

Warehouse Security That Keeps Operations Moving

Warehouses are built for motion. Trucks arrive, products move, employees shift between zones, and valuable inventory often sits in multiple areas at once. That constant activity creates opportunities, but it also creates risk. For operators who need better visibility, safer access, and stronger protection, it can make sense to hire ADR Security when planning a system that supports daily warehouse operations without slowing them down.

Defence in Depth Changed Forever with Cloud Security

Defence in depth changed forever with cloud security because the old perimeter gave way to platforms, suppliers and connected services outside direct control. That means modern attackers often reach the target through weaker vendors, cloud services or supply chain links instead of attacking the business head on.

Why we cannot wait for better post-quantum signature algorithms

RSA and ECC, cryptographic algorithms that we’ve all relied on for decades, are vulnerable to the attack of sufficiently advanced quantum computers. Such quantum computers do not exist yet, but they seem to be coming sooner than expected. Luckily, the solution is already available: migrate to ML-KEM encryption and ML-DSA signatures, which are designed to be resistant to quantum attack. They were standardized in 2024 by the U.S.

Hybrid Cloud Security: A CISO's Guide for 2026

A hybrid breach now costs an average of $5.05 million per incident, and that's 26% more expensive than breaches in traditional on-premises-only environments according to AppSecure's 2025 cloud security statistics. That number changes the conversation. Hybrid cloud security isn't a side project for infrastructure teams. It's a board-level risk issue with direct impact on resilience, audit readiness, and operating cost.

When AI Agents Call AWS, Who Does AWS Think They Are?

In Part 1, Your AI Agent Needs to Know Who You Are, we showed how Teleport JWTs give MCP tools a verified identity for every request. This post extends that pattern to AWS, specifically to Amazon Bedrock AgentCore, where the same identity gap exists but requires a different solution stack. You ask an AI agent to list your S3 buckets. The agent calls an MCP tool. The tool reaches out to AWS. However, CloudTrail records the action under something like agentcore-bot, but not your identity.