The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 14hblog.cloudflare.comCloudflare Impact reaches $100 million in donationsThis week, Cloudflare's Impact programs will reach $100 million in donated services. This milestone means that thousands of entities including journalists, civil society, state and local governments, election management bodies, and public schools are being protected from cyberattacks. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 14hblog.cloudflare.comIdentify AI model overuse with User InsightsAI Gateway User Insights now adds task, model, turn, and user categories to help teams understand AI adoption and make better model decisions. This is available free to AI Gateway users. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 14hblog.cloudflare.comThe Internet has a second audienceMore than half the traffic reaching sites on Cloudflare is now automated, and AI agents are the fastest-growing part of it. We're giving site owners the tools to see who's visiting, decide who gets in, and charge for access. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 29/09/2026blog.cloudflare.comPreventing quantum downgrade attacks against IPsecA sophisticated attacker with a quantum computer can exploit a protocol design flaw to downgrade post-quantum IPsec tunnels to classical crypto. We helped the IETF develop a transcript authentication extension to prevent these attacks. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 28/09/2026blog.cloudflare.comNext.js applications, powered by Vite: introducing Vinext 1.0Vinext 1.0 graduates from an AI experiment to a production-ready framework, letting developers run Next.js apps on Vite. This release brings advanced cache warming, broader compatibility, and an automated testing pipeline. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 28/09/2026blog.cloudflare.comIntroducing cf: the agentic CLI for the entire Cloudflare APIWe are releasing cf, our new command-line tool that mirrors the entire Cloudflare API and supports programmatic TypeScript configuration. We are also open-sourcing Forge, our internal SDK generator. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 28/09/2026blog.cloudflare.comHow fast is the web? Explore billions of real-user measurements with BEACONCloudflare is open-sourcing the BEACON dataset, making billions of anonymized Real User Monitoring (RUM) performance records publicly available on Google BigQuery. Explore real-world Core Web Vitals, soft navigation metrics, and performance breakdowns across browsers and regions. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 28/09/2026blog.cloudflare.comSupporting native Rust in Workers with the new Emscripten target for wasm-bindgenWith the new experimental support for the Emscripten target in Rust Workers, many previously unsupported Rust libraries and applications can now be built and deployed directly to Cloudflare’s global Workers platform, including upcoming support for Tokio async. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 27/09/2026blog.cloudflare.comCloudflare’s 2026 Annual Founders’ LetterThe Internet is changing more today than at any point since Cloudflare launched back on September 27, 2010. As automated traffic surpasses human activity, we reflect on the rise of AI agents, new creators, and how we can help build a fair, sustainable future for the web. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 25/09/2026blog.cloudflare.comAgents can now set up your website’s security with Turnstile SpinMisconfiguring Turnstile by skipping backend validation leaves sites exposed to bots. Turnstile Spin fixes incomplete setups by using your preferred AI coding agent to wire up server-side verification. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 24/09/2026blog.cloudflare.comHow Cloudflare addressed a cross-tenant data exposure vulnerability in ContainersExternal security researchers at Accomplish identified a vulnerability in Cloudflare Containers that could expose residual disk data from previous workloads. We explain how the issue worked, how we investigated it, and the steps we took to remediate it. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 22/09/2026blog.cloudflare.comWe just shipped support for the ugliest part of HTTP: VaryVary support is now available in Cache Rules on every plan. You can normalize known negotiation headers, pass exact values through to the origin when those small differences matter, or bypass cache when the variation is too unpredictable. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 22/09/2026blog.cloudflare.comIntroducing Worker Previews: Isolated preview environments for every change your agent makesWorker Previews gives every branch its own URL, configuration, state, and observability, so you and your agents can test changes in parallel without affecting production. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 18/09/2026blog.cloudflare.comSaving another 100TB of RAM with math (and Rust)Cloudflare's global network is immense but not limitless. As we look for small ways to trim our resource usage, we sometimes get lucky and we can cut significantly more. Here’s how we reduced one of our Pingora-based service's RAM usage with statistics. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 16/09/2026blog.cloudflare.comWhen scanners miss the attack: how Cloudflare Client-Side Security protects storefrontsA modern storefront can look healthy while malicious JavaScript quietly siphons revenue, hijacks clicks, or rewrites analytics. See how Cloudflare's machine learning models surface evasive client-side attacks for analyst investigation. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 15/09/2026blog.cloudflare.comGive every teammate and agent the right level of access to your WorkersYou can now scope access to individual Workers and assign narrower Developer Platform roles, so teammates, CI tokens, and agents get only the access they need to debug, deploy, or monitor safely. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 11/09/2026blog.cloudflare.comIntroducing automatic remediation policies with Cloudflare CASBCloudflare CASB policies introduce a native automation engine built directly on the Cloudflare developer platform to remediate SaaS risks automatically. Security teams can now design event-driven logic to revoke risky file shares and send webhooks without manual intervention. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 10/09/2026blog.cloudflare.com1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44 algorithm. Here is how we manage 2,420-byte signatures and downgrade risks at scale. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 09/09/2026blog.cloudflare.comHow we rebuilt Cloudflare Workers’ module registry for Node.js compatibilityWorkers now enables Node.js compatibility by default, supports applications up to 64 mebibytes, and adds a URL-based module registry with import.meta, lazy compilation, shared code caches, and clearer errors. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 08/09/2026blog.cloudflare.comAutomatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting)Automatic Key Exchange probes TLS 1.3-capable customer origins to learn which key agreement algorithms they support. We then lead with the most secure algorithm when connecting to the origin, preferring post-quantum connections wherever the origin supports it. 001
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 03/09/2026blog.cloudflare.comIntroducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak modelsUse production traffic and security signals to prioritize findings, prepare edge mitigations when safe, and propose code patches. By combining WAF data with OpenAI Daybreak models, Vulnerability Discovery and Remediation helps teams identify and patch the most critical threats first. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 01/09/2026blog.cloudflare.comHow we could save petabytes of cache storage with Zstandard and PingoraCould we get more cache space with the same hardware? We prototyped compression inside Cloudflare's cache to find out. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 31/08/2026blog.cloudflare.comIntroducing Adaptive Intelligence: Undermining the economics of every bot attackBot operators have historically had the economic advantage, bypassing static, deterministic detection rules with cheap proxies and retooling. Cloudflare's new Adaptive Intelligence engine flips this dynamic by autonomously learning from the meta-signals of live traffic and deploying disposable rules, making automated attacks too expensive to sustain. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 28/08/2026blog.cloudflare.comBotBase for Operators: A clearer path to joining Cloudflare's directory of bots and agentsBot operators now have a home in the Cloudflare dashboard to manage submissions. This update adds submission status tracking, submission editing, and a behavior model so operators can accurately declare how their bots use content. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 24/08/2026blog.cloudflare.comThe Cloudflare Blog – Brought to you by EmDashWe migrated the Cloudflare Blog to EmDash to prove our stack at massive scale. Here is how we stress-tested performance, safely routed production traffic, and redesigned the frontend experience. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 22/08/2026blog.cloudflare.comSay it once: introducing Bot Preference SyncCloudflare's new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training. Easily manage which bots access your content without maintaining static files. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 20/08/2026blog.cloudflare.comFrom all-or-nothing to task-based OAuth consentCloudflare OAuth now supports optional scopes, giving users more control over what an app can access and helping developers build secure consent flows around the task at hand. 010
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 19/08/2026blog.cloudflare.comA revisit of remote Spectre attacks on Cloudflare WorkersIn 2024 and 2025, we reassessed remote Spectre attacks on our Workers infrastructure. We share details about the new attack primitives like Spectre gadgets, remote timers, achieving co-location and how new defenses further harden Cloudflare Workers. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 18/08/2026blog.cloudflare.comBGP Role model: tracking the adoption of RFC 9234RFC 9234 lets routers reject route leaks on their own, using BGP Roles and the Only to Customer attribute. We measured who has deployed it, and found two Tier 1 networks unexpectedly stripping OTC. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 14/08/2026blog.cloudflare.comHow Cloudflare detects MCP traffic and helps secure itCloudflare Gateway identifies MCP requests using protocol-level heuristics. Security teams can use that signal to find shadow MCP traffic, enforce Portal-only access for approved servers, and block direct connections on managed network paths. 010
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 14/08/2026blog.cloudflare.comSecure all your internal vibe-coded applications — in one clickIntroducing Cloudflare Access for Workers. Attach an Access policy directly to a Worker and it applies everywhere that Worker runs — routes, custom domains, workers.dev, and previews — automatically. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 13/08/2026blog.cloudflare.comTotal eclipse of the Internet: traffic impacts in Iceland, Spain, and PortugalCloudflare's data shows a clear impact on Internet traffic from Iceland to Spain and Portugal, following the path of totality of the total solar eclipse that occurred on August 12, 2026. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 13/08/2026blog.cloudflare.comCertificate Transparency Monitoring is now generally availableCloudflare's Certificate Transparency Monitoring is now generally available. The biggest change: we no longer email you about certificates Cloudflare issued for your domain, so when an alert lands in your inbox, it's worth a look. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 11/08/2026blog.cloudflare.comCloudflare DDoS Threat Report H1 2026: 1 Tbps attacks soar as DNS floods and geopolitical tensions drive a new waveIn the first half of 2026, Cloudflare detected a 519% surge in hyper-volumetric DDos attacks across its network. These attacks were driven heavily by DNS and CLDAP reflection vectors. This report breaks down how major geopolitical conflicts reshaped the global cyber threat landscape. 010
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 10/08/2026blog.cloudflare.comEverything we launched during Agents WeekOur latest Agents Week has come to a close. Here’s a recap of all the announcements we made, from Wallets to Radar. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 10/08/2026blog.cloudflare.comServing the most critical missions: Cloudflare for Government achieves FedRAMP Class D (High) Certified statusCloudflare for Government achieves FedRAMP Class D (High) Certified status. We also announce our commitment to pursue DoD IL4 authorization. Cloudflare brings world-class security, performance, and developer products to the public sector. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 07/08/2026blog.cloudflare.comUnveiling good and bad behaviors on the Agentic InternetCloudflare is shifting bot mitigation from point-in-time Risk assessment to continuous Trust evaluation. Learn how new good and bad behaviors from bots and agents are assessed by our systems, including BotBase and Precursor — and try out our Precursor Trace simulation to see how your own cursor movements would be assessed as human or bot. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 07/08/2026blog.cloudflare.comUnifying Workers AI and AI Gateway into a single AI control planeCloudflare is unifying AI Gateway and Workers AI into a single control plane, giving developers observability, billing, and dynamic routing across both managed GPUs and external providers. Learn how unified bindings and model-first routing simplify building resilient AI applications. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 06/08/2026blog.cloudflare.comGive any website a WebMCP interfaceToday we're launching a developer preview of WebMCP on Cloudflare. With one switch, any site becomes usable by browser AI agents — no new APIs, no origin changes — while the human stays in control and creators keep their traffic. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 06/08/2026blog.cloudflare.comCloudflare is the only vendor named a Visionary in 2026 SASE and SSE reportsWe're honored to announce that Cloudflare is the only vendor that has been recognized as a Visionary in both the 2026 Gartner® Magic Quadrant™ for SASE Platforms and the 2026 Gartner® Magic Quadrant™ for Security Service Edge reports. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 05/08/2026The Agent Access Model proposes a new architecture to secure task-scoped agents using strict identity brokering, continuous mediation, and stateful trust. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 05/08/2026blog.cloudflare.comHow we’re rethinking work at Cloudflare with Cloudflare OSWe built Cloudflare OS to equip our teams to safely rethink how they get work done with AI. The platform brings together the best of our technologies, from our Compute primitives to our Zero Trust suite. This post walks through our journey to give our users the best AI tools available. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 05/08/2026blog.cloudflare.comCloudflare OS: an open platform for agents, apps, and workCloudflare OS is an open-source platform that lets everyone in your company build apps, automate work, and safely access internal systems, shaped around what your organization knows and how it operates 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 04/08/2026blog.cloudflare.comHow we built a software factory to drive Astro’s GitHub issue count to zeroBy replacing manual issue verification with isolated AI subagents running in GitHub Actions, the Astro maintainers reduced open issue count by 85%. This post explores the architecture behind automated bug reproduction, patch verification, and preview releases. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 03/08/2026blog.cloudflare.comYour agent needs a computer, not a container — introducing @cloudflare/computerAgents need more than just a container to scale. We're introducing @cloudflare/computer, an agent runtime that dynamically orchestrates between fast, efficient isolates and full Linux containers to give every agent a computer of its own. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 03/08/2026blog.cloudflare.comWorkers RPC now works across Python and JavaScriptOne coding agent can write a Python Worker and another can write a JavaScript Worker. At runtime, those Workers can exchange references to live objects and call their methods without defining APIs, schemas, or serialization code 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 02/08/2026blog.cloudflare.comWelcome to Agents WeekAgents Week explores how cloud infrastructure must evolve to serve autonomous agents rather than human browsers. Join us as we unpack the storage, execution, and security primitives needed for an agent-native web. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 31/07/2026blog.cloudflare.comAn API for MoQ: provision your own isolated relaysLast year we made every Cloudflare server a Media over QUIC (MoQ) relay. Now the new provisioning API lets you create your own isolated relay and control who can publish and who can only watch. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 30/07/2026blog.cloudflare.comDogfooding at scale: migrating cdnjs to Cloudflare’s Developer PlatformWe moved cdnjs, serving 9 billion requests a day, entirely onto Cloudflare's Developer Platform. That means we’re running one of the Internet's busiest open-source CDNs on our own building blocks, and we pushed Workflows and Workers limits higher for everyone. 000
The Cloudflare Blog [Unofficial] @blog.cloudflare.com.web.brid.gy · 29/07/2026blog.cloudflare.comPost-quantum authentication to origins is now supportedCloudflare now supports post-quantum (PQ) authentication when connecting to customer origin servers via Authenticated Origin Pulls and Custom Origin Trust Store. This is the first step towards providing PQ authentication for all Cloudflare products. 000